[Client] Implement OAuth 2.0 Authorization Code flow with PKCE (RFC 6749 + RFC 7636)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- php
调研方向
先查看依赖项 #315、#316、#317 和 #318,然后检查 Mcp\Client\Auth\Grant\AuthorizationCodeGrant 和 TokenStorageInterface。在定义 user-agent 和 redirect-handler 的集成之前,跟踪授权端点和令牌端点。PKCE 和 state 验证单元测试通过,且 auth/basic-cimd 一致性场景通过,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Context
Primary user-facing flow. Required for any interactive MCP client to obtain tokens after PRM/AS discovery.
Scope
Mcp\Client\Auth\Grant\AuthorizationCodeGrant:- Generate PKCE
code_verifier+code_challenge(S256). - Build authorize URL with
client_id,redirect_uri,response_type=code,code_challenge,code_challenge_method,scope,state,resource(audience-binding RFC 8707). - Pluggable user-agent dispatcher: callback hook so library users can open a browser / present URL in CLI.
- Local loopback redirect listener (default) or custom redirect handler.
- Exchange code → tokens at
token_endpoint; persist viaTokenStorageInterface.
- Generate PKCE
- Verify
stateround-trip; reject mismatched.
Conformance scenarios unblocked
auth/basic-cimd and prerequisite for all scope/refresh/cross-app scenarios.
Dependencies
Blocked by: #315, #316, #317, #318. Pairs with #319 (token endpoint auth methods).
Acceptance
- Unit tests for PKCE generation + state validation.
- Conformance:
auth/basic-cimdpasses.
cc @soyuka
- 主要语言
- PHP
- 星标
- 1.6k
- 派生
- 173
- 平均合并
- 19 小时 19 分钟
- 30 天内合并 PR
- 8
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/php-sdk 的其他 Issue
-
[Server] Connections to Github Copilot CLI time out on subscriptions/listen可能已有人在做 @SammyTourani 于 5 天前认领。 未关闭bug
难度 2/5 1-3 小时 新手友好度 78/100
modelcontextprotocol/php-sdk#516 ·
维护者通常 1 天内回复
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStan未关闭Server
难度 1/5 1 小时以内 新手友好度 78/100
modelcontextprotocol/php-sdk#468 · 2 条评论 ·
维护者通常 1 天内回复
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudly可能已有人在做 @ousamabenyounes 于 47 天前认领。 未关闭needs confirmation needs maintainer action Server
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/php-sdk#398 · 1 个 reaction ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/php-sdk#370 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 74/100
modelcontextprotocol/php-sdk#524 ·
维护者通常 1 天内回复
查看 modelcontextprotocol/php-sdk 的全部 Issue
相似的 Issue
-
Security SecurityBundle
难度 2/5 1-3 小时 新手友好度 68/100
symfony/symfony-docs#23173 ·
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
fossology/fossology#3893 · 1 条评论 ·
维护者通常 2 天内回复
-
Documentation Feature: Self-Register / Verify UI
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
i18n
难度 2/5 1-3 小时 新手友好度 74/100
WordPress/wordpress.org#1002 ·
维护者通常 4 天内回复
-
Bug
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复