Skip to content

oauthex: accept token68 challenges in WWW-Authenticate - #1357

Open
akshita317 wants to merge 1 commit into
modelcontextprotocol:mainfrom
akshita317:oauthex-token68
Open

akshita317 wants to merge 1 commit into
modelcontextprotocol:mainfrom
akshita317:oauthex-token68

Conversation

@akshita317

@akshita317 akshita317 commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

A challenge carries either auth-params or a token68 (RFC 9110, section 11.6.1); the grammar is quoted in the doc comment of parseSingleChallenge, but only auth-params were handled. With

WWW-Authenticate: Negotiate oYH1MIHyoAMKAQ, Bearer resource_metadata="https://example.com/.well-known/oauth-protected-resource"

the Negotiate challenge failed with expected key=value, ParseWWWAuthenticate failed the whole header, and the auth handlers never saw the Bearer challenge. A token68 with padding, such as Basic dGVzdA==, did not fail but was misread as a parameter named dgvzda with value =.

This recognizes a token68 and returns the challenge with no Params; Challenge has nowhere to store the token and the SDK only needs Bearer parameters, so it is not kept. The Params doc notes this.

Test changes:

  • New cases in TestParseSingleChallenge (token68, token68 with padding, malformed token68) and TestParseWWWAuthenticateToken68 (Negotiate next to Bearer). Both fail without the change.
  • Removed the Bearer realm= "no value" case: realm= is a valid token68. A parameter with no value is still covered by "malformed param - no value before comma".

This touches the same file as #1351; whichever lands second will need a trivial rebase.

AI assistance: prepared with Claude Code.

A challenge carries either auth-params or a token68 (RFC 9110, section
11.6.1), as in

	WWW-Authenticate: Negotiate oYH1MIHyoAMKAQ, Bearer resource_metadata="..."

parseSingleChallenge only understood auth-params. A token68 without
padding failed with "expected key=value", which made
ParseWWWAuthenticate fail the whole header, so the auth handlers never
saw the Bearer challenge next to it. A token68 with padding, such as
dGVzdA==, was misread as a parameter named "dgvzda".

Recognize a token68 and return the challenge without parameters.

The "Bearer realm=" test case is removed: "realm=" is a valid token68,
and a parameter with no value is still covered by the case
"malformed param - no value before comma".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant