fix(client): don't send client_id in token body under client_secret_b…#3175
Draft
manjunathbhaskar wants to merge 2 commits into
Draft
fix(client): don't send client_id in token body under client_secret_b…#3175manjunathbhaskar wants to merge 2 commits into
manjunathbhaskar wants to merge 2 commits into
Conversation
…asic RFC 6749 section 2.3 requires that with HTTP Basic auth, client credentials must not also appear in the request body. prepare_token_auth stripped client_secret from the body for the client_secret_basic branch but left client_id in, so strict token endpoints (Keycloak, Okta in strict mode, and the RFC 6749 compliance test suite) reject the request as presenting two authentication methods at once. Fixes modelcontextprotocol#3138 Two existing tests asserted the old behavior explicitly, updated both to assert the corrected one, and added the same check to the refresh token test for symmetry. Signed-off-by: manjunathbhaskar <manjunathbhaskar854@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…asic
RFC 6749 section 2.3 requires that with HTTP Basic auth, client credentials must not also appear in the request body. prepare_token_auth stripped client_secret from the body for the client_secret_basic branch but left client_id in, so strict token endpoints (Keycloak, Okta in strict mode, and the RFC 6749 compliance test suite) reject the request as presenting two authentication methods at once.
Fixes #3138
Two existing tests asserted the old behavior explicitly, updated both to assert the corrected one, and added the same check to the refresh token test for symmetry.
Motivation and Context
How Has This Been Tested?
Breaking Changes
Types of changes
Checklist
Additional context