| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
(cherry picked from commit b7a5bff)
The 1.x line still allows pydantic 2.11 (Python < 3.14), where the url_preserve_empty_path config from #2925 is silently ignored and a path-less PRM resource still renders with a trailing slash. Record the wire string on ProtectedResourceMetadata (resource_str) and use it for the resource parameter, so the client echoes the server's identifier verbatim on every supported pydantic version. Also spell the config as a cast dict so the 2.11 type stubs accept it, and make the cherry-picked issuer assertion version-tolerant. Co-Authored-By: Claude <noreply@anthropic.com>
| Back | FazBrowse Home | New Git URL |
Backport of #2925 to the 1.x line, plus a small compat shim so the fix holds on pydantic < 2.12 (which 1.x still supports).
Motivation and Context
RFC 8707's resource parameter must be the protected resource's identifier byte-for-byte. On 1.x a path-less resource from the server's Protected Resource Metadata (http://host:port) is parsed into AnyHttpUrl and re-serialised as http://host:port/, so the client sends a different identifier in the authorization and token requests (#2578). main fixed this in #2925 via url_preserve_empty_path=True on the OAuth metadata models; that was never backported.
This now matters for conformance: modelcontextprotocol/conformance#488 adds a resource-parameter-matches-prm check (FAILURE, RFC 8707 MUST) to the scored auth/metadata-var2 client scenario, and the 1.x line fails it without this change while main, go, rust, csharp and the TS SDK pass.
What's in here
How Has This Been Tested?
Breaking Changes
None intended. str(prm.resource) is unchanged on pydantic < 2.12 (still normalised); code that needs the exact identifier should use the new ProtectedResourceMetadata.resource_str.
Types of changes
Checklist
AI Disclaimer
Prepared with Claude Code; reviewed the diff and the test/conformance output.