You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 1e86bfa
Browse filesBrowse the repository at this point in the historyBrowse files
fix(dpop,mcp,fastmcp): keep the ;params segment in the htu binding, make the PRM hook public
`urlparse` peels an RFC 3986 `;params` segment off the last path segment, so a
request to `/orders;v=2` bound an `htu` of `/orders` — a proof computed over a
different resource than the one being accessed, and RFC 3986 §3.3 puts `;params`
squarely in the path. The htu construction uses `urlsplit`, which does not split
it off, and the round-trip no longer has to fill `urlunparse`'s params slot.
`VerbatimPRMRemoteAuthProvider` is now public (was `_VerbatimPRMRemoteAuthProvider`)
and `rewrite_prm_routes_verbatim` is exported: building a `RemoteAuthProvider` by
hand is a documented FastMCP pattern, and doing so silently lost the verbatim PRM.
`install_request_context(mcp)` now detects a verifier carrying no verbatim
identifiers and warns instead of skipping the rewrite in silence — a verifier
built through the public `AuthplaneTokenVerifier(verifier)` constructor has none,
so the previous `is None` check never fired for it and the served document kept
advertising slash-normalized identifiers that this SDK's own byte-for-byte
comparison rejects. `AuthplaneTokenVerifier.verbatim_identifiers()` exposes the
pair without cross-module private attribute reads.
`install_request_context` also stops touching `mcp.sse_app` unguarded: SSE is not
on the streamable-HTTP path, so a future `mcp` 1.x that drops the attribute would
have taken down servers that never touch SSE.
Copy file name to clipboardExpand all lines: authplane-fastmcp/docs/user-guide.md
+28-2Lines changed: 28 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -244,7 +244,7 @@ Trade-offs to understand before enabling `fail_closed=True`:
244
244
245
245
-**Availability**: an authorization server or introspection outage makes every request fail with 401 until the outage resolves. Once the client's circuit breaker opens, checks fail fast and all tokens are rejected until the cooldown elapses.
246
246
-**Credentials**: authorization servers commonly require authenticated introspection; without valid `as_credentials` the introspection call fails, which under `fail_closed=True` means every token is rejected. Verify credentials as part of deployment, not just at rollout.
247
-
-**Metadata**: an AS whose metadata document does not advertise `introspection_endpoint` fails every introspection attempt. Under the default that check is silently skipped; under `fail_closed=True` every token is rejected — and unlike an outage this never self-recovers, because the missing endpoint is a permanent property of the AS configuration. Confirm the endpoint is present in AS metadata before enabling.
247
+
-**Metadata**: an AS whose metadata document does not advertise `introspection_endpoint` fails every introspection attempt. Under the default that check is skipped and every request logs a `Revocation check failed (fail-open)` warning — for a missing endpoint that is every request, permanently, since the condition never clears; under `fail_closed=True` every token is rejected — and unlike an outage this never self-recovers, because the missing endpoint is a permanent property of the AS configuration. Confirm the endpoint is present in AS metadata before enabling.
248
248
-`fail_closed` has no effect when `revocation_checker` is `None` — the flag is only consulted when a revocation check actually runs. The SDK logs a warning at resource construction when it detects this misconfiguration.
249
249
250
250
### Custom Revocation Checker
@@ -529,10 +529,36 @@ Returned by `authplane_auth()`. Supports `**` unpacking into `FastMCP()` — the
529
529
530
530
| Attribute | Type | Description |
531
531
|-----------|------|-------------|
532
-
|`auth`|`RemoteAuthProvider`| Auth provider for FastMCP |
532
+
|`auth`|`RemoteAuthProvider`(a `VerbatimPRMRemoteAuthProvider`in practice) | Auth provider for FastMCP. `authplane_auth()` always constructs the subclass — see below — but the attribute is typed as the base class, so a checker will not offer subclass members without a narrowing check|
0 commit comments