Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

M7. MCP authorization (OAuth code flow)

未关闭
#159 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 2 天内回复

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
35/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
活跃
技术栈
azure, csharp

调研方向

从 docs/mcp.md 和 docs/agentic-roadmap.md 开始,重点查看路线图项目 M7,然后跟踪 HTTP 传输和现有的 Entra/RBAC 凭据路径。完成的标准是:拒绝未经身份验证的远程请求,bearer-token 授权正常工作,身份信息能够传递到 Cosmos/ARM 凭据,localhost 的 no-auth 仍由 flag 控制,并更新威胁模型和文档。

由索引模型根据 Issue 内容生成。

描述

agentic enhancement P1

Why

Today the MCP server relies solely on origin-header validation and localhost binding — safe for a single-user local machine, but there is no authorization layer. Any remote, hosted, or shared agent deployment (team agent, CI runner, cloud-hosted assistant) currently has no supported way to authenticate a caller. The MCP spec defines an OAuth 2.1 authorization-code flow for exactly this; adopting it unlocks hosted/agentic scenarios without falling back to master keys.

This is the natural companion to confirmation/elicitation (item M3): authorization answers "who is allowed to call," M3 answers "what may they do."

Proposed behavior

  • Implement the MCP authorization-code flow for the HTTP transport: advertise the authorization server, validate bearer tokens on each request, and map the authenticated identity onto the shell's existing Entra/RBAC connection so tool calls run with least-privilege, per-caller credentials rather than a shared session.
  • Keep localhost/no-auth as an explicit opt-in for the current single-user experience.

Acceptance criteria

  • Unauthenticated remote requests are rejected.
  • A client can complete the authorization-code flow and call tools with a bearer token.
  • Identity flows to the Cosmos/ARM credential.
  • Localhost no-auth mode preserved behind a flag.
  • Threat model + docs/mcp.md updated.

Filed from the Agentic & Automation Roadmap (docs/agentic-roadmap.md), item M7, Wave 2. Priority P1.

主要语言
C#
星标
4
派生
7
平均合并
3 天 12 小时
30 天内合并 PR
23

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

Azure/CosmosDBShell 的其他 Issue

查看 Azure/CosmosDBShell 的全部 Issue

相似的 Issue

更多 C# Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。