Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions packages/client/src/client/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -184,50 +184,6 @@ export interface OAuthClientProvider {
*/
prepareTokenRequest?(scope?: string): URLSearchParams | Promise<URLSearchParams | undefined> | undefined;

/**
* Saves the authorization server URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* authorization server via protected resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered authorization server URL should implement this method.
*
* @param authorizationServerUrl - The authorization server URL discovered via RFC 9728
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void | Promise<void>;

/**
* Returns the previously saved authorization server URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* authorization server URL discovered during the OAuth flow.
*
* @returns The authorization server URL, or `undefined` if not available
*/
authorizationServerUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the resource URL after RFC 9728 discovery.
* This method is called by {@linkcode auth} after successful discovery of the
* resource metadata.
*
* Providers implementing Cross-App Access or other flows that need access to
* the discovered resource URL should implement this method.
*
* @param resourceUrl - The resource URL discovered via RFC 9728
*/
saveResourceUrl?(resourceUrl: string): void | Promise<void>;

/**
* Returns the previously saved resource URL, if available.
*
* Providers implementing Cross-App Access can use this to access the
* resource URL discovered during the OAuth flow.
*
* @returns The resource URL, or `undefined` if not available
*/
resourceUrl?(): string | undefined | Promise<string | undefined>;

/**
* Saves the OAuth discovery state after RFC 9728 and authorization server metadata
* discovery. Providers can persist this state to avoid redundant discovery requests
Expand DownExpand Up@@ -545,16 +501,8 @@ async function authInternal(
});
}

// Save authorization server URL for providers that need it (e.g., CrossAppAccessProvider)
await provider.saveAuthorizationServerUrl?.(String(authorizationServerUrl));

const resource: URL | undefined = await selectResourceURL(serverUrl, provider, resourceMetadata);

// Save resource URL for providers that need it (e.g., CrossAppAccessProvider)
if (resource) {
await provider.saveResourceUrl?.(String(resource));
}

// Apply scope selection strategy (SEP-835):
// 1. WWW-Authenticate scope (passed via `scope` param)
// 2. PRM scopes_supported
Expand Down
40 changes: 8 additions & 32 deletions packages/client/src/client/authExtensions.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,7 +8,7 @@
import type { FetchLike, OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '@modelcontextprotocol/core';
import type { CryptoKey, JWK } from 'jose';

import type { AddClientAuthentication, OAuthClientProvider } from './auth.js';
import type { AddClientAuthentication, OAuthClientProvider, OAuthDiscoveryState } from './auth.js';

/**
* Helper to produce a `private_key_jwt` client authentication function.
Expand DownExpand Up@@ -545,8 +545,7 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
private _clientMetadata: OAuthClientMetadata;
private _assertionCallback: AssertionCallback;
private _fetchFn: FetchLike;
private _authorizationServerUrl?: string;
private _resourceUrl?: string;
private _discoveryState?: OAuthDiscoveryState;
private _scope?: string;

constructor(options: CrossAppAccessProviderOptions) {
Expand DownExpand Up@@ -600,40 +599,17 @@ export class CrossAppAccessProvider implements OAuthClientProvider {
throw new Error('codeVerifier is not used for jwt-bearer flow');
}

/**
* Saves the authorization server URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveAuthorizationServerUrl?(authorizationServerUrl: string): void {
this._authorizationServerUrl = authorizationServerUrl;
}

/**
* Returns the cached authorization server URL if available.
*/
authorizationServerUrl?(): string | undefined {
return this._authorizationServerUrl;
saveDiscoveryState(state: OAuthDiscoveryState): void {
this._discoveryState = state;
}

/**
* Saves the resource URL discovered during OAuth flow.
* This is called by the auth() function after RFC 9728 discovery.
*/
saveResourceUrl?(resourceUrl: string): void {
this._resourceUrl = resourceUrl;
}

/**
* Returns the cached resource URL if available.
*/
resourceUrl?(): string | undefined {
return this._resourceUrl;
discoveryState(): OAuthDiscoveryState | undefined {
return this._discoveryState;
}

async prepareTokenRequest(scope?: string): Promise<URLSearchParams> {
// Get the authorization server URL and resource URL from cached state
const authServerUrl = this._authorizationServerUrl;
const resourceUrl = this._resourceUrl;
const authServerUrl = this._discoveryState?.authorizationServerUrl;
const resourceUrl = this._discoveryState?.resourceMetadata?.resource;

if (!authServerUrl) {
throw new Error('Authorization server URL not available. Ensure auth() has been called first.');
Expand Down
36 changes: 9 additions & 27 deletions packages/client/src/client/crossAppAccess.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,11 +8,11 @@
* @module
*/

import type { FetchLike } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthErrorResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';
import type { FetchLike, OAuthTokens } from '@modelcontextprotocol/core';
import { IdJagTokenExchangeResponseSchema, OAuthTokensSchema } from '@modelcontextprotocol/core';

import type { ClientAuthMethod } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata } from './auth.js';
import { applyClientAuthentication, discoverAuthorizationServerMetadata, parseErrorResponse } from './auth.js';

/**
* Options for requesting a JWT Authorization Grant via RFC 8693 Token Exchange.
Expand DownExpand Up@@ -104,7 +104,7 @@ export interface JwtAuthGrantResult {
*
* @param options - Configuration for the token exchange request
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If the token exchange fails or returns an error response
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -154,16 +154,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`Token exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`Token exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const parseResult = IdJagTokenExchangeResponseSchema.safeParse(await response.json());
Expand All@@ -186,7 +177,7 @@ export async function requestJwtAuthorizationGrant(options: RequestJwtAuthGrantO
*
* @param options - Configuration including IdP URL for discovery
* @returns The JWT Authorization Grant and related metadata
* @throws {Error} If discovery fails or the token exchange fails
* @throws {OAuthError} If the token exchange fails or returns an error response
*
* @example
* ```ts
Expand DownExpand Up@@ -226,7 +217,7 @@ export async function discoverAndRequestJwtAuthGrant(options: DiscoverAndRequest
*
* @param options - Configuration for the JWT grant exchange
* @returns OAuth tokens (access token, token type, etc.)
* @throws {Error} If the exchange fails or returns an error response
* @throws {OAuthError} If the exchange fails or returns an error response
*
* Defaults to `client_secret_basic` (HTTP Basic Authorization header), matching
* `CrossAppAccessProvider`'s declared `token_endpoint_auth_method` and the
Expand DownExpand Up@@ -257,7 +248,7 @@ export async function exchangeJwtAuthGrant(options: {
*/
authMethod?: ClientAuthMethod;
fetchFn?: FetchLike;
}): Promise<{ access_token: string; token_type: string; expires_in?: number; scope?: string }> {
}): Promise<OAuthTokens> {
const { tokenEndpoint, jwtAuthGrant, clientId, clientSecret, authMethod = 'client_secret_basic', fetchFn = fetch } = options;

// Prepare JWT bearer grant request per RFC 7523
Expand All@@ -279,16 +270,7 @@ export async function exchangeJwtAuthGrant(options: {
});

if (!response.ok) {
const errorBody = await response.json().catch(() => ({}));

// Try to parse as OAuth error response
const parseResult = OAuthErrorResponseSchema.safeParse(errorBody);
if (parseResult.success) {
const { error, error_description } = parseResult.data;
throw new Error(`JWT grant exchange failed: ${error}${error_description ? ` - ${error_description}` : ''}`);
}

throw new Error(`JWT grant exchange failed with status ${response.status}: ${JSON.stringify(errorBody)}`);
throw await parseErrorResponse(response);
}

const responseBody = await response.json();
Expand Down
29 changes: 12 additions & 17 deletions packages/client/test/client/authExtensions.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -467,38 +467,33 @@ describe('CrossAppAccessProvider', () => {
clientSecret: 'secret'
});

// Manually set authorization server URL but not resource URL
provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
// Save discovery state without resourceMetadata
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL
});

await expect(provider.prepareTokenRequest()).rejects.toThrow(
'Resource URL not available — server may not implement RFC 9728 Protected Resource Metadata'
);
});

it('stores and retrieves authorization server URL', () => {
it('stores and retrieves discovery state', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
});

expect(provider.authorizationServerUrl?.()).toBeUndefined();

provider.saveAuthorizationServerUrl?.(AUTH_SERVER_URL);
expect(provider.authorizationServerUrl?.()).toBe(AUTH_SERVER_URL);
});
expect(provider.discoveryState()).toBeUndefined();

it('stores and retrieves resource URL', () => {
const provider = new CrossAppAccessProvider({
assertion: async () => 'jwt-grant',
clientId: 'client',
clientSecret: 'secret'
provider.saveDiscoveryState({
authorizationServerUrl: AUTH_SERVER_URL,
resourceMetadata: { resource: RESOURCE_SERVER_URL }
});

expect(provider.resourceUrl?.()).toBeUndefined();

provider.saveResourceUrl?.(RESOURCE_SERVER_URL);
expect(provider.resourceUrl?.()).toBe(RESOURCE_SERVER_URL);
const state = provider.discoveryState();
expect(state?.authorizationServerUrl).toBe(AUTH_SERVER_URL);
expect(state?.resourceMetadata?.resource).toBe(RESOURCE_SERVER_URL);
});

it('has correct client metadata', () => {
Expand Down
49 changes: 25 additions & 24 deletions packages/client/test/client/crossAppAccess.test.ts
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
import type { FetchLike } from '@modelcontextprotocol/core';
import { OAuthError } from '@modelcontextprotocol/core';
import { describe, expect, it, vi } from 'vitest';

import { discoverAndRequestJwtAuthGrant, exchangeJwtAuthGrant, requestJwtAuthorizationGrant } from '../../src/client/crossAppAccess.js';
Expand DownExpand Up@@ -174,14 +175,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'Audience validation failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'Audience validation failed'
}),
{ status: 400 }
)
);

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -193,15 +195,13 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed: invalid_grant - Audience validation failed');
).rejects.toThrow(OAuthError);
});

it('handles non-OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 500,
json: async () => ({ message: 'Internal server error' })
} as Response);
const mockFetch = vi
.fn<FetchLike>()
.mockResolvedValue(new Response(JSON.stringify({ message: 'Internal server error' }), { status: 500 }));

await expect(
requestJwtAuthorizationGrant({
Expand All@@ -213,7 +213,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('Token exchange failed with status 500');
).rejects.toThrow(OAuthError);
});
});

Expand DownExpand Up@@ -385,14 +385,15 @@ describe('crossAppAccess', () => {
});

it('handles OAuth error responses', async () => {
const mockFetch = vi.fn<FetchLike>().mockResolvedValue({
ok: false,
status: 400,
json: async () => ({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
})
} as Response);
const mockFetch = vi.fn<FetchLike>().mockResolvedValue(
new Response(
JSON.stringify({
error: 'invalid_grant',
error_description: 'JWT signature verification failed'
}),
{ status: 400 }
)
);

await expect(
exchangeJwtAuthGrant({
Expand All@@ -402,7 +403,7 @@ describe('crossAppAccess', () => {
clientSecret: 'secret',
fetchFn: mockFetch
})
).rejects.toThrow('JWT grant exchange failed: invalid_grant - JWT signature verification failed');
).rejects.toThrow(OAuthError);
});

it('validates token response with schema', async () => {
Expand Down
2 changes: 1 addition & 1 deletion packages/core/src/shared/auth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -151,7 +151,7 @@ export const IdJagTokenExchangeResponseSchema = z
issued_token_type: z.literal('urn:ietf:params:oauth:token-type:id-jag'),
access_token: z.string(),
token_type: z.string().optional(),
expires_in: z.number().optional(),
expires_in: z.coerce.number().optional(),
scope: z.string().optional()
})
.strip();
Expand Down
Loading