feat: accept OAuth 2.1 access tokens and sync with the hosted server - #2
Merged
Merged
Conversation
Port the hosted server's changes since this mirror was published. - OAuth 2.1 (backend ENG-882): the server accepts an access token from the Clerk issuer as well as a cloro API key. initialize and tools/list answer without a credential. A tools/call without one returns 401 with a WWW-Authenticate challenge. The protected resource metadata is served at both well-known paths. The token verifier is vendored in src/oauth-tokens/ and adds the jose dependency. OAuth is off unless CLERK_ISSUER is set. - Schemas: re-vendor from the backend. The Google tools take gl and hl (country is a deprecated alias), ChatGPT takes legacy, and include.rawHtml no longer exists. - Version 0.2.0 in package.json, src/server.ts, server.json and the Cursor plugin manifest. server.json gets the repository field and makes the Authorization header optional. - tsconfig: add the DOM lib for the CryptoKey and RequestInfo types in the vendored tests. The hosted deployment's Prometheus metrics stay out of this repo, as before. Claude-Session: https://claude.ai/code/session_01DBpCib1v2KCNjNijH5ersL
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Port the hosted server's changes (
cloro-dev/backendapps/mcp) since this mirror was published.initializeandtools/listanswer without a credential. Atools/callwithout one returns 401 with aWWW-Authenticatechallenge. The protected resource metadata is served at both well-known paths. The token verifier is vendored insrc/oauth-tokens/and adds thejosedependency. OAuth is off unlessCLERK_ISSUERis set.@repo/api-schemas. The Google tools takeglandhl(countryis a deprecated alias), ChatGPT takeslegacy, andinclude.rawHtmlno longer exists.package.json,src/server.ts,server.jsonand.cursor-plugin/plugin.json.server.jsonmatches cloro-dev/backend#388:repositoryfield,Authorizationheader optional.gl/hl.DOMlib for theCryptoKeyandRequestInfotypes in the vendored tests.The hosted deployment's Prometheus metrics stay out of this repo, as before. Two backend tests that assert on those metrics are left out.
Test
tsc --noEmit: passes.vitest run: 91 passed.npm run build: passes.https://claude.ai/code/session_01DBpCib1v2KCNjNijH5ersL