Scopes not forwarded to DCR endpoint and duplication of RedirectUris
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 45/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- csharp
调研方向
从 HttpClientTransport 及其对 OAuth 和 DynamicClientRegistrationOptions 的处理开始,然后跟踪 ResourceMetadata.ScopesSupported 如何传递到 DCR 请求中。验证请求的 scopes 是否被转发,并确定应如何协调 OAuth 和 DCR 的 RedirectUri 值;在无需重复配置的情况下覆盖这两种行为即表示完成。
由索引模型根据 Issue 内容生成。
描述
I have implemented an MCP server and added DCR support to my Duende Identity Server, and it all kind of works with the MCP Server and MCP Client in the SDK. However, one issue seems to be with scopes. The server declares it's supported scopes:
.AddMcp(options =>
{
options.ResourceMetadata = new()
{
Resource = new Uri(serverUrl),
AuthorizationServers = { new Uri(chronosIdp) },
ScopesSupported = ["mcp:tools"]
};
});
However, in the request that my DCR endpoint receives, Scopes is null. Shouldn't the HttpClientTransport take the scopes from the MCP Server and add these to the DCR request?
Right now I can add them manually here, but a normal MCP tool user wouldn't know what scopes to request - that's why the MCP server declares them:
var transport = new HttpClientTransport(new()
{
Endpoint = new Uri(serverUrl),
Name = "Secure Chronos Client",
OAuth = new()
{
Scopes = [ "mcp:tools", "chronosapi"], // shouldn't need to do this!
RedirectUri = new Uri("http://localhost:1179/callback"),
AuthorizationRedirectDelegate = HandleAuthorizationUrlAsync,
DynamicClientRegistration = new DynamicClientRegistrationOptions
{
ClientName = "Chronos MCP Client",
ClientUri = new Uri("http://localhost:1179/callback")
},
}
}, httpClient, consoleLoggerFactory);
var client = await McpClient.CreateAsync(transport, loggerFactory: consoleLoggerFactory);
Also it seems a bit redundant to specify the same RedirectUri in the OAuth object AND the DCR object - they are necessarily the same so maybe if the DCR property is present the OAuth object can use the info there - or vice versa. Just to make it easier to set up correctly.
- 主要语言
- C#
- 星标
- 4.5k
- 派生
- 814
- 平均合并
- 9 天 19 小时
- 30 天内合并 PR
- 4
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/csharp-sdk 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
modelcontextprotocol/csharp-sdk#1867 ·
-
难度 1/5 1 小时以内 新手友好度 88/100
modelcontextprotocol/csharp-sdk#1840 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
modelcontextprotocol/csharp-sdk#1836 ·
-
enhancement needs confirmation
难度 2/5 1-3 小时 新手友好度 64/100
modelcontextprotocol/csharp-sdk#678 · 1 条评论 ·
-
enhancement needs confirmation P3 ready for work
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/csharp-sdk#515 · 6 条评论 · 3 个 reaction ·
查看 modelcontextprotocol/csharp-sdk 的全部 Issue
相似的 Issue
-
bug
难度 1/5 1 小时以内 新手友好度 90/100
-
Type: enhancement
难度 2/5 1-3 小时 新手友好度 65/100
apache/arrow-adbc#4809 ·
-
type/automation type/tech-debt
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 65/100
microsoft/vscode-azurefunctions#5197 · 1 条评论 ·
-
难度 1/5 1 小时以内 新手友好度 85/100
microsoft/microsoft-ui-reactor#1274 ·