Skip to content

feat(nitro): add an oauth 2.1 resource server - #330

Open
HugoRCD wants to merge 2 commits into
mainfrom
feat/nitro-oauth-resource-server
Open

feat(nitro): add an oauth 2.1 resource server#330
HugoRCD wants to merge 2 commits into
mainfrom
feat/nitro-oauth-resource-server

Conversation

@HugoRCD

@HugoRCD HugoRCD commented Sep 3, 2026

Copy link
Copy Markdown
Member

📚 Description

Stacked on #329. Second of six; the OAuth feature arrives over this PR and the two above it.

createMcpOAuth verifies JWT access tokens against the issuer's JWKS and puts the claims on event.context.oauth. iss defaults to authorizationServers and aud to resource, so a token minted for another service does not pass — that check is the confused-deputy attack the spec's security considerations call out. verify replaces JWKS verification for opaque tokens.

It also returns metadataHandler and metadataPath for the RFC 9728 protected-resource document, which is what a 401's WWW-Authenticate header points a client at. That supersedes the README's old "Protected resource metadata" section, which told you to serve the document from your own app — removed here.

This is the resource server only: nothing in this package mints a token. mcp({ oauth }) and the provider connectors are the next two PRs.

jose becomes a dependency.

📝 Checklist

  • I have linked an issue or discussion.
  • I have updated the documentation accordingly.

`module.test.ts` drove the `types:extend` hook against the shared discovery
fixture, then removed `node_modules/.nitro` from it in `afterAll`. The e2e
suite builds that same fixture out of the same directory, so the cleanup
could land mid-build and fail it — roughly one run in four once the module
suite grew long enough to overlap.

The hook test now runs against its own temporary app, which leaves nothing
for the fixture to share.
`createMcpOAuth` verifies JWT access tokens against the issuer's JWKS and
puts the claims on `event.context.oauth`. `iss` defaults to
`authorizationServers` and `aud` to `resource`, so a token minted for
another service does not pass. It returns `metadataHandler` and
`metadataPath` for the RFC 9728 protected-resource document, which is
what the `401`'s `WWW-Authenticate` header points a client at.

`verify` replaces JWKS verification for opaque tokens. This is the
resource server only — nothing here mints a token.
@vercel

vercel Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nuxt-mcp-toolkit-docs Ready Ready Preview Sep 3, 2026 3:40pm UTC

Request Review

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

Base automatically changed from test/nitro-shared-build-state to main September 3, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant