Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Robustly parse quoted WWW-Authenticate parameters

未关闭
#1,088 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 9 天内回复

@DanielC000 已经在做这个了。

开始于 2026年7月28日。

  • #1764 来自 @DanielC000 —— 未关闭

评估

难度
3/5
预计耗时
1-2 天
新手友好度
55/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
csharp

调研方向

定位 ClientOAuthProvider 中 WWW-Authenticate 参数的解析逻辑,并先阅读 RFC 9110 的第 11.6.1 节和参数处理部分。验证引号字符串中的逗号以及 \" 之类的转义引号的行为;当这些值能够被解析且不会破坏响应处理,并且边界情况有测试覆盖时,即视为完成。

由索引模型根据 Issue 内容生成。

描述

bug P2

Something like param="," can break our naive WWW-Authenticate parameter parsing logic in ClientOAuthProvider. While I don't expect many servers will be sending parameters like that in their responses, and it'd be very unusual for an attacker to have only partial control over a WWW-Authenticate response header value, it'd be best to properly account for things like commas inside of quoted strings or escaped quotes. \".

It's a bit like CSV with its quote handling trickiness.

See https://github.com/modelcontextprotocol/csharp-sdk/pull/1084#discussion_r2612746896 for more context.

https://gist.github.com/halter73/aca998c8855b4260b7ae2e705d85ec98 Includes a copilot conversation I had investigating if there was a built-in API we could leverage, and it appears not.

RFC 9110 contains the relevant specs for the WWW-Authenticate header and how to read a parameter.

https://www.rfc-editor.org/rfc/rfc9110#section-11.6.1
https://www.rfc-editor.org/rfc/rfc9110#parameter

主要语言
C#
星标
4.6k
派生
819
平均合并
4 天 23 小时
30 天内合并 PR
2

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

modelcontextprotocol/csharp-sdk 的其他 Issue

查看 modelcontextprotocol/csharp-sdk 的全部 Issue

相似的 Issue

更多 C# Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。