@modelcontextprotocol/server-legacy@2.3.1
@modelcontextprotocol/server-legacy 2.3.1 adds an optional expectedResource parameter to requireBearerAuth to validate audience URLs against AuthInfo.resource.
原始内容为英文;当前页面提供中文导航与来源说明,具体事实请以原文为准。
为什么值得关注
The patch release for @modelcontextprotocol/server-legacy updates requireBearerAuth to accept an optional expectedResource configuration, aligning it with the 1.x middleware it mimics as well as recent updates in @modelcontextprotocol/server (2.3.0) and @modelcontextprotocol/sdk (1.32.0). If configured, incoming bearer tokens are validated by comparing expectedResource against AuthInfo.resource as strings (ignoring URL fragments and a single trailing slash). Failure or omission of this resource check returns a 401 invalid token error with a WWW-Authenticate header. If unset, existing behavior is preserved. The package remains otherwise frozen, and dependency @modelcontextprotocol/core is updated to 2.3.1.
可执行摘要
In @modelcontextprotocol/server-legacy@2.3.1, requireBearerAuth receives an optional expectedResource parameter matching behavior from @modelcontextprotocol/server 2.3.0 and @modelcontextprotocol/sdk 1.32.0. When set, AuthInfo.resource must match expectedResource (ignoring fragments and a trailing slash), otherwise returning a 401 invalid token with WWW-Authenticate.
- Agent 实用度
- 77/100
- 可信度
- 96%
- 机器格式
- JSON + Markdown
开发者应核对什么
- Optionally configure expectedResource in requireBearerAuth with the expected audience (typically the server URL) if token audience verification is needed.
- Update @modelcontextprotocol/server-legacy to version 2.3.1.