mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-10-03 18:23:47 +10:00
fix: restore MCP OAuth registration and authorization (#3421)
* fix: align MCP OAuth provider schema and authorization flow * test: isolate OpenAPI generation from OAuth initialization * fix: accept auth routes without a callback query * fix: require explicit OAuth consent and preserve signed requests * test: verify OAuth audiences through real MCP initialization * test(e2e): isolate OAuth token audience validation
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
CREATE TABLE "oauth_client_assertion" (
|
||||
"id" text PRIMARY KEY,
|
||||
"expires_at" timestamp with time zone NOT NULL
|
||||
);
|
||||
--> statement-breakpoint
|
||||
CREATE TABLE "oauth_client_resource" (
|
||||
"id" text PRIMARY KEY,
|
||||
"client_id" text NOT NULL,
|
||||
"resource_id" text NOT NULL,
|
||||
"metadata" jsonb,
|
||||
"created_at" timestamp with time zone
|
||||
);
|
||||
--> statement-breakpoint
|
||||
CREATE TABLE "oauth_resource" (
|
||||
"id" text PRIMARY KEY,
|
||||
"identifier" text NOT NULL UNIQUE,
|
||||
"name" text NOT NULL,
|
||||
"access_token_ttl" integer,
|
||||
"refresh_token_ttl" integer,
|
||||
"signing_algorithm" text,
|
||||
"signing_key_id" text,
|
||||
"allowed_scopes" text[],
|
||||
"custom_claims" jsonb,
|
||||
"dpop_bound_access_tokens_required" boolean DEFAULT false,
|
||||
"disabled" boolean DEFAULT false,
|
||||
"created_at" timestamp with time zone,
|
||||
"updated_at" timestamp with time zone,
|
||||
"policy_version" integer DEFAULT 1,
|
||||
"metadata" jsonb
|
||||
);
|
||||
--> statement-breakpoint
|
||||
ALTER TABLE "oauth_access_token" ADD COLUMN "authorization_code_id" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_access_token" ADD COLUMN "resources" text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_access_token" ADD COLUMN "requested_user_info_claims" text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_access_token" ADD COLUMN "revoked" timestamp with time zone;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_access_token" ADD COLUMN "confirmation" jsonb;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "client_discovery_id" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "client_credentials_scopes" text[] DEFAULT '{}'::text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "backchannel_logout_uri" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "backchannel_logout_session_required" boolean;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "application_type" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "jwks" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "jwks_uri" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client" ADD COLUMN "dpop_bound_access_tokens" boolean DEFAULT false;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_consent" ADD COLUMN "resources" text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_consent" ADD COLUMN "requested_user_info_claims" text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "authorization_code_id" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "resources" text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "requested_user_info_claims" text[];--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "rotated_at" timestamp with time zone;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "rotation_replay_response" text;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "rotation_replay_expires_at" timestamp with time zone;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_refresh_token" ADD COLUMN "confirmation" jsonb;--> statement-breakpoint
|
||||
CREATE INDEX "oauth_client_resource_client_id_index" ON "oauth_client_resource" ("client_id");--> statement-breakpoint
|
||||
CREATE INDEX "oauth_client_resource_resource_id_index" ON "oauth_client_resource" ("resource_id");--> statement-breakpoint
|
||||
CREATE UNIQUE INDEX "oauth_client_resource_client_id_resource_id_index" ON "oauth_client_resource" ("client_id","resource_id");--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client_resource" ADD CONSTRAINT "oauth_client_resource_client_id_oauth_client_client_id_fkey" FOREIGN KEY ("client_id") REFERENCES "oauth_client"("client_id") ON DELETE CASCADE;--> statement-breakpoint
|
||||
ALTER TABLE "oauth_client_resource" ADD CONSTRAINT "oauth_client_resource_dn2L1gs9Dolm_fkey" FOREIGN KEY ("resource_id") REFERENCES "oauth_resource"("identifier") ON DELETE CASCADE;
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user