Files
Arcrun/mcp/src/oauth/metadata.ts
T
Claude 7d9d478baa feat(mcp): OAuth 2.1 server for claude.ai remote connector; close plaintext-namespace bearer hole
在 arcrun-mcp worker 實作 MCP Authorization 規範(OAuth 2.1 + PKCE S256),
讓 claude.ai 遠端 connector 安全登入;並修掉「Bearer 明碼 namespace 直接放行」漏洞。

安全模型
- /authorize 同意頁以 owner secret(CF Secrets MCP_OWNER_SECRET)把關,只有 owner 知道 →
  只知 URL 的人走不完 OAuth、拿不到 token。
- access_token 是 /mcp 唯一接受的 bearer(預設);明碼 namespace 舊路徑移除(步驟 5 直接 401)。

實作 endpoint(掛 worker 根路徑)
- RFC 9728 /.well-known/oauth-protected-resource(+/mcp 變體)+ 401 帶
  WWW-Authenticate: Bearer resource_metadata=...
- RFC 8414 /.well-known/oauth-authorization-server(response_types=code, S256, none)
- RFC 7591 /register(public client,無 secret,無狀態不落地)
- GET/POST /authorize(PKCE S256 + owner-secret 閘 + redirect_uri 白名單)
- POST /token(authorization_code + PKCE 驗證 → access_token 綁定 owner namespace)

儲存鐵律
- authorization code / access token → 短效 KV OAUTH_KV(key 用 SHA-256 hash、帶 TTL、code 一次性)
- owner secret / static token → CF Secrets(非 KV、非明碼 var)
- DCR client / refresh token → 不落地(無狀態 / 不實作,避免長效機密進 KV)

相容決策
- 本機 CLI/GUI/Claude Code → 用真祕密 MCP_STATIC_TOKEN(CF Secret)取代舊明碼 namespace
- 官方 SaaS partner-key 路徑行為不變
- ALLOW_PLAINTEXT_NAMESPACE 逃生門預設關(僅遷移期)

驗證:tsc exit 0;vitest 42/42(oauth 22 + partner-auth 10 改測真實 middleware + 既有 10);
wrangler deploy --dry-run 打包過、OAUTH_KV binding 正確識別。設計文件 mcp/OAUTH.md。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015d5jDbuqT5Htwv3Q88XXKk
2026-07-07 03:59:00 +00:00

50 lines
1.9 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
// OAuth 探索文件(RFC 9728 Protected Resource Metadata、RFC 8414 Authorization Server Metadata
// 以「當前請求的 origin」動態組出——同一份碼在 mcp.arcrun.dev 與 arcrun-mcp.<sub>.workers.dev 都正確。
/** 從請求 URL 取 originscheme://host),canonical 用小寫 scheme/host。 */
export function originOf(reqUrl: string): string {
const u = new URL(reqUrl);
return `${u.protocol.toLowerCase()}//${u.host.toLowerCase()}`;
}
/** 本 MCP server 的 canonical resource URIRFC 8707 audience)——MCP 端點在 /mcp。 */
export function resourceUri(origin: string): string {
return `${origin}/mcp`;
}
/** RFC 9728 Protected Resource Metadata。 */
export function protectedResourceMetadata(origin: string) {
return {
resource: resourceUri(origin),
authorization_servers: [origin],
scopes_supported: ["mcp"],
bearer_methods_supported: ["header"],
};
}
/** RFC 8414 Authorization Server Metadata(本 worker 同時是 AS)。 */
export function authorizationServerMetadata(origin: string) {
return {
issuer: origin,
authorization_endpoint: `${origin}/authorize`,
token_endpoint: `${origin}/token`,
registration_endpoint: `${origin}/register`,
response_types_supported: ["code"],
grant_types_supported: ["authorization_code"],
code_challenge_methods_supported: ["S256"],
token_endpoint_auth_methods_supported: ["none"], // public client + PKCE
scopes_supported: ["mcp"],
};
}
/**
* RFC 9728 §5.1 WWW-Authenticate 回應標頭——401 時指向 protected-resource metadata
* claude.ai 靠這個發現 OAuth authorization server。
*/
export function wwwAuthenticateHeader(origin: string, error?: string): string {
const metaUrl = `${origin}/.well-known/oauth-protected-resource`;
let h = `Bearer resource_metadata="${metaUrl}"`;
if (error) h += `, error="${error}"`;
return h;
}