fastmcp/tests/server/auth
Jeremiah Lowin 3bc2805b67
fix: normalize Google scope shorthands and surface valid_scopes
Google accepts shorthand scopes like "email" in authorization requests but
returns full URIs like "https://www.googleapis.com/auth/userinfo.email" in
token responses. The verifier now normalizes shorthands at initialization so
the subset check works regardless of which form was used. GoogleProvider also
now exposes valid_scopes for controlling which scopes clients can request
beyond the required minimum.

Co-authored-by: Claude <noreply@anthropic.com>
2026-03-13 18:29:52 -04:00
..
oauth_proxy Escape client_id in OAuth consent details (#3418) 2026-03-06 17:33:12 -05:00
providers fix: normalize Google scope shorthands and surface valid_scopes 2026-03-13 18:29:52 -04:00
__init__.py Add WorkOS and Azure OAuth providers (#1550) 2025-08-20 16:22:03 -04:00
test_auth_provider.py Upgrade to MCP 1.17+ with RFC 9728 compliance (#2122) 2025-10-17 09:29:23 -04:00
test_authorization.py Handle AuthorizationError as exclusion in AuthMiddleware list hooks 2026-03-01 13:23:02 -05:00
test_cimd.py Split large test files to comply with loq line limit (#3328) 2026-02-28 11:21:11 -05:00
test_cimd_validators.py Split large test files to comply with loq line limit (#3328) 2026-02-28 11:21:11 -05:00
test_debug_verifier.py Add DebugTokenVerifier with custom sync/async validation (#2296) 2025-10-31 10:38:01 -04:00
test_enhanced_error_responses.py Use MemoryStore for OAuth proxy tests 2026-02-01 02:30:05 +00:00
test_jwt_issuer.py feat: option to add upstream claims to the FastMCP proxy JWT (#2997) 2026-01-28 15:57:24 -05:00
test_jwt_provider.py Block insecure HS* JWT verification with JWKS/public keys (#3430) 2026-03-07 12:20:48 -05:00
test_jwt_provider_bearer.py Split large test files to comply with loq line limit (#3328) 2026-02-28 11:21:11 -05:00
test_multi_auth.py Add MultiAuth for composing multiple token verification sources (#3335) 2026-03-02 12:09:22 -05:00
test_oauth_consent_flow.py Split large test files to comply with loq line limit (#3328) 2026-02-28 11:21:11 -05:00
test_oauth_consent_page.py Remove form-action from default consent CSP, forward consent_csp_policy in all providers 2026-03-03 14:55:00 -05:00
test_oauth_mounting.py Use MemoryStore for OAuth proxy tests 2026-02-01 02:30:05 +00:00
test_oauth_proxy_redirect_validation.py Fix CIMD redirect allowlist bypass and cache revalidation (#3098) 2026-02-06 20:08:23 -05:00
test_oauth_proxy_storage.py Drop diskcache dependency (CVE-2025-69872) (#3185) 2026-02-16 16:43:15 -05:00
test_oidc_proxy.py Split large test files to comply with loq line limit (#3328) 2026-02-28 11:21:11 -05:00
test_oidc_proxy_token.py fix: use intent-based flag for OIDC scope patch in load_access_token (#3465) 2026-03-13 17:59:03 -04:00
test_redirect_validation.py Add CIMD (Client ID Metadata Document) support for OAuth (#2871) 2026-02-06 13:44:52 -05:00
test_remote_auth_provider.py Add AzureJWTVerifier for Managed Identity token verification (#3058) 2026-02-02 19:59:13 -05:00
test_ssrf_protection.py Add CIMD (Client ID Metadata Document) support for OAuth (#2871) 2026-02-06 13:44:52 -05:00
test_static_token_verifier.py Add documentation for get_access_token() dependency function (#1446) 2025-08-11 13:01:44 -04:00