Repository navigation
MCP handlers on an auth: true mount receive the caller's verified principal - #1151
Merged
Merged
Conversation
…1139) A tool, resource or prompt handler on a mount whose route names a principal-providing policy now receives the request's frozen {id, provider} principal (RIM-EXT-PRINCIPAL-001) as context.principal. Unprotected mounts, and requests whose provider set none, get no key. Admission and the cross-origin gate are unchanged (#1138). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013oBXtj4wmB5VHq2cNMWNeU
The handler-principal docs pushed core's unpacked size 792 bytes over its budget and auth's README past its unpacked budget. Per the policy in scripts/package-audit.ts, every package is re-measured on Node 26 and each limit reset to measurement plus the fixed margin, not raised by the overshoot. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013oBXtj4wmB5VHq2cNMWNeU
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Jimmy · project thread
Closes #1139.
Problem and change
Before: an
auth: trueMCP mount admitted only a signed-in caller, but its tool, resource and prompt handlers got justenv,kind,progress,requestId,server,signalandtool. They couldn't tell who called, so a per-user tool had nothing to scope its work by.After: on a mount whose route names a principal-providing policy (
auth: true), every handler getscontext.principal. This is the same frozen{id, provider}that core carries on the request (RIM-EXT-PRINCIPAL-001). With the bundled auth extension,idis the signed-in user id, the same value a function route reads ascontext.capabilities.auth.identity.userId. A mount without such a policy, or a request whose provider set no principal, gets noprincipalkey.How:
createMcpExtensionrecords each server's mount against the activation'sprincipalMounts, andinvocation()addsrequest.principalto the handler context only for those mounts.Verification
test/account-composition.test.tsis the [Request]: per-user remote MCP for non-browser clients: protected mcp mounts refuse headless callers and handlers get no caller identity #1139 repro. It now checks that Alice and Bob each get their own frozen principal, matching what/api/mereturns, and that a second mount withoutauth: truegets no principal even when a valid session cookie is sent.test/feature-plan.test.tsis updated for the newmountauthoring text.npm run lint,typecheck,typecheck:tooling,check(docs included) andbuildpass. The mcp and auth workspace tests pass (47 and 33).npm run audit:packagesandnpm run test:package:builtpass.npm test: 1435 pass and 2 fail. The 2 failures aredisk-full.test.tsandhermetic-accounts.test.ts, and both fail only because this container's Node 22 ships SQLite 3.50.4, below the store's patched-SQLite floor. They don't touch this change.Package budgets
The new docs pushed core's unpacked size 792 bytes over its budget, and auth's unpacked size over its budget too. Following the policy in
scripts/package-audit.ts, every package was re-measured on Node 26 (npm pack --dry-run --json --ignore-scriptsafter the build) and each limit reset to measurement plus the fixed margin, rather than raised by the overshoot. Measured sizes (packed / unpacked / entries):Compatibility and security
This adds a key to the handler context and changes no YAML. Unprotected mounts behave exactly as before, which
packages/mcp/test/context.test.tsalready pins.The principal is never taken from a header, cookie or tool argument. It comes only from core's principal slot, and only on a
principalMountsmount.Remaining for Make URLCode auth and MCP easier to adopt in existing apps #1138: admission is unchanged. With the bundled auth, a non-browser MCP client (no
Origin, or a bearer token) is still refused403 cross_origin_refusedby the session gate. There is still no bearer, OAuth or headless principal provider, so remote MCP clients can't reach these per-user tools yet.Docs: the mcp README ("Protecting a mount", the context list and the generated reference), the auth README cross-link, the mcp
CHANGELOG.mdandllms.txt, and the RIM-EXT-PRINCIPAL-001 card indocs/RUNTIME-IMPLEMENTATION.md.Changes match the documented portable contract; docs/examples are updated where needed.
Relevant tests and package checks pass, or limitations are explained above.
No credentials, customer data or private project material are included.
Runtime/starter changes remain aligned where applicable.
🤖 Generated with Claude Code
https://claude.ai/code/session_013oBXtj4wmB5VHq2cNMWNeU