| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
…en's resource v1.x backport. BearerAuthBackend takes an optional resource_server_url; when it is set, only a token the verifier reports as issued for that URL (AccessToken.resource, the RFC 8707 resource indicator, compared as a URL with a trailing slash tolerated) is accepted, and anything else is answered 401 like an unrecognized token. AuthSettings.validate_token_resource turns this on for FastMCP's SSE and Streamable HTTP apps; leaving it unset while resource_server_url is set emits a DeprecationWarning and behaves as False, and 3.0 makes True the default there. RefreshToken gains an optional resource so a provider can carry the binding through the refresh grant. TokenVerifier.verify_token's docstring and docs/authorization.md say where the token's audience goes and when to enable the option versus checking the audience in the verifier. The oauth_server snippet and the simple-auth example set it.
📚 Documentation preview
|
Sorry, something went wrong.
There was a problem hiding this comment.
All reported issues were addressed across 10 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
v1.x backport of #3447.
Adds AuthSettings.validate_token_resource. When set, the bearer gate only accepts a token that the TokenVerifier reports as issued for resource_server_url (via AccessToken.resource); a token reporting another resource, or none, gets the same 401 as an unrecognized token. Leaving it unset on a resource server emits a DeprecationWarning and behaves as off; 3.0 makes it the default there. RefreshToken gains an optional resource so providers can carry the binding through the refresh grant.
Differences from #3447
How Has This Been Tested?
Unit tests as above; driven end to end under uvicorn on FastMCP with an introspection-backed verifier over Streamable HTTP (option on: a token for another resource gets 401 and one for this server 200; unset: behaviour unchanged apart from the warning); full suite with coverage, ruff, pyright.
Breaking Changes
None. Unset behaves as off (with the deprecation warning); BearerAuthBackend(verifier) and existing verifiers behave as before. Setting it to True without a resource_server_url raises at construction.
Types of changes
Checklist
AI Disclaimer