Skip to content

oauth-approved-client session token needs a strict check at callback #513

@geoffg-sentry

Description

@geoffg-sentry

Current implementation allows for refresh token theft. We use a static client ID but don't enforce consent for dynamically registered clients

https://modelcontextprotocol.io/specification/draft/basic/authorization#confused-deputy-problem

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions