@modelcontextprotocol/server-legacy@2.3.1
@modelcontextprotocol/server-legacy 2.3.1 adds an optional expectedResource parameter to requireBearerAuth to validate audience URLs against AuthInfo.resource.
Why this signal matters
The patch release for @modelcontextprotocol/server-legacy updates requireBearerAuth to accept an optional expectedResource configuration, aligning it with the 1.x middleware it mimics as well as recent updates in @modelcontextprotocol/server (2.3.0) and @modelcontextprotocol/sdk (1.32.0). If configured, incoming bearer tokens are validated by comparing expectedResource against AuthInfo.resource as strings (ignoring URL fragments and a single trailing slash). Failure or omission of this resource check returns a 401 invalid token error with a WWW-Authenticate header. If unset, existing behavior is preserved. The package remains otherwise frozen, and dependency @modelcontextprotocol/core is updated to 2.3.1.
Actionable summary
In @modelcontextprotocol/server-legacy@2.3.1, requireBearerAuth receives an optional expectedResource parameter matching behavior from @modelcontextprotocol/server 2.3.0 and @modelcontextprotocol/sdk 1.32.0. When set, AuthInfo.resource must match expectedResource (ignoring fragments and a trailing slash), otherwise returning a 401 invalid token with WWW-Authenticate.
- Agent usefulness
- 77/100
- Confidence
- 96%
- Canonical data
- JSON + Markdown
What builders should check
- Optionally configure expectedResource in requireBearerAuth with the expected audience (typically the server URL) if token audience verification is needed.
- Update @modelcontextprotocol/server-legacy to version 2.3.1.