fastmcp/tests/server/auth
mika 9af97ee0aa
fix(auth): preserve verifier-defined challenge scopes through wrappers (#5478)
RemoteAuthProvider and single-verifier MultiAuth now pass the raw required_scopes value to the verifier's get_challenge_scopes hook, so a verifier-defined default challenge is preserved.

Co-authored-by: mikamikasuki <211269698+mikamikasuki@users.noreply.github.com>
2026-10-08 14:37:30 -04:00
..
oauth_proxy fix(auth): omit scopes from generic authorization code exchange (#5183) 2026-10-08 14:34:56 -04:00
providers fix(azure): send prompt=select_account to Entra instead of the consent URL (#5162) 2026-10-04 21:23:09 -04:00
__init__.py Add WorkOS and Azure OAuth providers (#1550) 2025-08-20 16:22:03 -04:00
conftest.py fix(auth): cache OIDC discovery configuration (#4861) 2026-09-22 10:56:31 -05:00
test_auth_provider.py fix(auth): preserve verifier-defined challenge scopes through wrappers (#5478) 2026-10-08 14:37:30 -04:00
test_auth_source_identities.py fix!: Qualify MultiAuth client identities (#5455) 2026-10-04 16:43:15 -04:00
test_authorization.py Add require_roles auth check (#4656) 2026-07-27 12:36:58 -04:00
test_cimd.py Bound CIMD cache growth (#4852) 2026-08-26 18:11:13 -04:00
test_cimd_validators.py Bound CIMD cache growth (#4852) 2026-08-26 18:11:13 -04:00
test_debug_verifier.py Add DebugTokenVerifier with custom sync/async validation (#2296) 2025-10-31 10:38:01 -04:00
test_enhanced_error_responses.py Treat non-Bearer Authorization schemes as missing authentication (#5503) 2026-10-08 12:25:55 -04:00
test_issuer_url_identity.py Bind ID-JAG audience to the issuer identifier 2026-07-27 09:37:38 -04:00
test_jwks_refresh.py fix: Share JWKS refreshes across key lookups (#5456) 2026-10-04 16:43:38 -04:00
test_jwt_issuer.py Make the unit suite fast: in-process HTTP tests, no real sleeps, parallel Windows CI (#4554) 2026-07-20 10:51:14 -04:00
test_jwt_provider.py Support EdDSA verification in JWTVerifier (#4752) 2026-08-06 14:09:37 -04:00
test_jwt_provider_bearer.py Speed up the unit test suite, and fix the task-notification race it surfaced (#4550) 2026-07-19 18:52:04 -04:00
test_multi_auth.py Preserve provider challenge defaults through MultiAuth (#5454) 2026-10-04 20:43:59 -04:00
test_oauth_consent_flow.py Keep earlier consent CSRF tokens valid within a transaction (#4818) 2026-08-13 15:24:02 -04:00
test_oauth_consent_page.py Migrate to MCP Python SDK v2 (#4437) 2026-07-06 17:36:45 -04:00
test_oauth_mounting.py Use issuer_url for OAuth issuer identity, not base_url 2026-07-26 15:10:15 -04:00
test_oauth_proxy_redirect_validation.py Honor OAuth application_type in DCR (SEP-837) (#4621) 2026-07-26 14:24:50 -04:00
test_oauth_proxy_storage.py Migrate to MCP Python SDK v2 (#4437) 2026-07-06 17:36:45 -04:00
test_oidc_discovery_cache.py fix(auth): cache OIDC discovery configuration (#4861) 2026-09-22 10:56:31 -05:00
test_oidc_proxy.py Add valid_scopes parameter to OIDC proxy valid scopes (#4660) 2026-07-27 15:12:15 -04:00
test_oidc_proxy_token.py fix: use intent-based flag for OIDC scope patch in load_access_token (#3465) 2026-03-13 17:59:03 -04:00
test_redirect_validation.py [codex] Add OAuthProxy RFC 9207 issuer responses (#4438) 2026-07-19 09:52:43 -04:00
test_remote_auth_provider.py Include scopes in auth challenges (#4527) 2026-07-18 20:53:52 -04:00
test_ssrf_protection.py fix(auth): preserve DNS resolver order when deduplicating resolved IP addresses (#5151) (#5157) 2026-09-21 18:10:47 -05:00
test_static_token_verifier.py Make InMemoryOAuthProvider keyword-only like its parent 2026-07-26 15:34:06 -04:00