fastmcp/tests/server/auth/test_jwt_issuer.py
Jeremiah Lowin 3a9717e6be
Publish docs for v3.2.0 (#3713)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
Co-authored-by: Marvin Context Protocol <41898282+Marvin Context Protocol@users.noreply.github.com>
Co-authored-by: voidborne-d <voidborne-d@users.noreply.github.com>
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: d 🔹 <258577966+voidborne-d@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Bill Easton <strawgate@users.noreply.github.com>
Co-authored-by: Sumanshu Nankana <sumanshunankana@gmail.com>
Co-authored-by: Eric Robinson <ericrobinson@indeed.com>
Co-authored-by: Martim Santos <martimfasantos@gmail.com>
Co-authored-by: d 🔹 <liusway405@gmail.com>
Co-authored-by: Matthieu B <66959271+mtthidoteu@users.noreply.github.com>
Co-authored-by: Sascha Buehrle <47737812+saschabuehrle@users.noreply.github.com>
Co-authored-by: Hakancan <142545736+hkc5@users.noreply.github.com>
Co-authored-by: nightcityblade <jackchen@haloailabs.com>
Co-authored-by: Matt Hallowell <17804673+mhallo@users.noreply.github.com>
Co-authored-by: nate nowack <thrast36@gmail.com>
Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Marcus Shu <46469249+shulkx@users.noreply.github.com>
Co-authored-by: Rushabh Doshi <radoshi@gmail.com>
Co-authored-by: AIKAWA Shigechika <shige@aikawa.jp>
Co-authored-by: Jeremy Simon <simonjer805@gmail.com>
Co-authored-by: Miguel Miranda Dias <7780875+pandego@users.noreply.github.com>
Co-authored-by: Anthony James Padavano <padavano.anthony@gmail.com>
Co-authored-by: Mostafa Kamal <hiremostafa@gmail.com>
Fix auto-close MRE script posting comment without closing (#3386)
Fix WorkOS token scope verification bypass 🤖 Generated with Codex (#3407)
Fix initialize McpError fallthrough 🤖 Generated with Codex (#3413)
Fix transform arg collisions with passthrough params (#3431)
Fix get_* returning None when latest version is disabled (#3439)
Fix get_* returning None when latest version is disabled (#3421)
Fix server lifespan overlap teardown (#3415)
Fix $ref output schema object detection regression (#3420)
resolved annotations (#3429)
Fix async partial callables rejected by iscoroutinefunction (#3438)
Fix async partial callables rejected by iscoroutinefunction (#3423)
fix: add version to components (#3458)
fix: use intent-based flag for OIDC scope patch in load_access_token (#3465)
Fixes #3461
fix: normalize Google scope shorthands and surface valid_scopes (#3477)
fix: resolve ty 0.0.23 type-checking errors and bump pin (#3481)
fix: shield lifespan teardown from cancellation (#3480)
fix: forward custom_route endpoints from mounted servers (#3462)
fix updates _get_additional_http_routes() to traverse providers,
Fixes #3457
fix: remove hardcoded version from CLI help text (#3456)
fix: monty 0.0.8 compatibility, drop external_functions from constructor (#3468)
fix: task test teardown hanging 5s per test (#3499)
Closes #3498
fix: validate workspace path is a directory before cursor install (#3440)
Fixes #3426
fix: handle re.error from malformed URI templates in build_regex (#3501)
fix: reject empty/OIDC-only required_scopes in AzureProvider (#3503)
fix: restrict $ref resolution to local refs only (SSRF/LFI) (#3502)
fix warnings and timeouts (#3504)
close upgrade check issue when build passes (#3505)
Closes #3484
fix: URL-encode path params to prevent SSRF/path traversal (GHSA-vv7q-7jx5-f767) (#3507)
fix: prevent path traversal in skill download (#3493)
fix: prefer IdP-granted scopes over client-requested scopes in OAuthProxy (#3492)
fix: remove unrelated transform and http.py changes from PR scope
fix: remove forced follow_redirects from httpx_client_factory calls (#3496)
fix: stop passing follow_redirects to httpx_client_factory
fix: restore follow_redirects=True for custom httpx client factories
Closes #3509
fix: CSRF double-submit cookie check in consent flow (#3519)
fix: validate server names in install commands (#3522)
fix: use raw strings for regex in pytest.raises match (#3523)
fix: reject refresh tokens used as Bearer access tokens (#3524)
fix: route ResourcesAsTools/PromptsAsTools through server middleware (#3495)
fix: resolve Pyright "Module is not callable" on @tool, @resource, @prompt decorators (#3540)
fix: filter warnings by message in KEY_PREFIX test (#3549)
fix: suppress output schema for ToolResult subclass annotations (#3548)
fix: increase sleep duration in proxy cache tests (#3567)
fix: store absolute token expiry to prevent stale expires_in on reload (#3572)
fix: preserve tool properties named 'title' during schema compression (#3582)
Fix loopback redirect URI port matching per RFC 8252 §7.3 (#3589)
Fix app tool routing: visibility check and middleware propagation (#3591)
Fix query parameter serialization to respect OpenAPI explode/style settings (#3595)
Fix dev apps form: union types, textarea support, JSON parsing (#3597)
fix(google): replace deprecated /oauth2/v1/tokeninfo with /oauth2/v3/userinfo (#3603)
fix: resolve EntraOBOToken dependency injection through MultiAuth (#3609)
fix(docs): correct misleading stateless_http header (#3622)
fix: filesystem provider import machinery (#3626)
Closes #3625 (issues 2, 3, 6)
fix: recover StdioTransport after subprocess exits (#3630)
fix(server): preserve mounted tool task metadata (#3632)
fix: scope deprecation warning filter to FastMCPDeprecationWarning (#3649)
fix imports, add PrefabAppConfig (#3650)
fix: resolve CurrentFastMCP/ctx.fastmcp to child server in mounted background tasks (#3651)
Fix blocking docs issues: chart imports, Select API, Rx consistency (#3652)
closed by default (#3657)
Fix prompt caching middleware missing wrap/unwrap round-trip (#3666)
fix: serialize object query params per OpenAPI style/explode rules (#3662)
Fixes #2857
fix: HTTP request headers not accessible in background task workers (#3631)
fix: restore HTTP headers in worker execution path for background tasks (#3681)
fix: strip discriminator after dereferencing schemas (#3682)
fix: remove stale ty:ignore directives for ty 0.0.26 (#3684)
Fix docs gaps in app provider pages (#3690)
fix: dev apps log panel UX improvements (#3698)
fix dev server empty string args (#3700)
2026-03-30 16:48:30 -04:00

310 lines
11 KiB
Python

"""Unit tests for JWT issuer and token encryption."""
import base64
import time
import pytest
from authlib.jose.errors import JoseError
from fastmcp.server.auth.jwt_issuer import (
JWTIssuer,
derive_jwt_key,
)
class TestKeyDerivation:
"""Tests for HKDF key derivation functions."""
def test_derive_jwt_key_produces_32_bytes(self):
"""Test that JWT key derivation produces 32-byte key."""
key = derive_jwt_key(high_entropy_material="test-secret", salt="test-salt")
assert len(key) == 44
assert isinstance(key, bytes)
# base64 decode and make sure its 32 bytes
key_bytes = base64.urlsafe_b64decode(key)
assert len(key_bytes) == 32
key = derive_jwt_key(low_entropy_material="test-secret", salt="test-salt")
assert len(key) == 44
assert isinstance(key, bytes)
# base64 decode and make sure its 32 bytes
key_bytes = base64.urlsafe_b64decode(key)
assert len(key_bytes) == 32
def test_derive_jwt_key_with_different_secrets_produces_different_keys(self):
"""Test that different secrets produce different keys."""
key1 = derive_jwt_key(high_entropy_material="secret1", salt="salt")
key2 = derive_jwt_key(high_entropy_material="secret2", salt="salt")
assert key1 != key2
key1 = derive_jwt_key(low_entropy_material="secret1", salt="salt")
key2 = derive_jwt_key(low_entropy_material="secret2", salt="salt")
assert key1 != key2
def test_derive_jwt_key_with_different_salts_produces_different_keys(self):
"""Test that different salts produce different keys."""
key1 = derive_jwt_key(high_entropy_material="secret", salt="salt1")
key2 = derive_jwt_key(high_entropy_material="secret", salt="salt2")
assert key1 != key2
key1 = derive_jwt_key(low_entropy_material="secret", salt="salt1")
key2 = derive_jwt_key(low_entropy_material="secret", salt="salt2")
assert key1 != key2
def test_derive_jwt_key_is_deterministic(self):
"""Test that same inputs always produce same key."""
key1 = derive_jwt_key(high_entropy_material="secret", salt="salt")
key2 = derive_jwt_key(high_entropy_material="secret", salt="salt")
assert key1 == key2
key1 = derive_jwt_key(low_entropy_material="secret", salt="salt")
key2 = derive_jwt_key(low_entropy_material="secret", salt="salt")
assert key1 == key2
class TestJWTIssuer:
"""Tests for JWT token issuance and verification."""
@pytest.fixture
def issuer(self):
"""Create a JWT issuer for testing."""
signing_key = derive_jwt_key(
low_entropy_material="test-secret", salt="test-salt"
)
return JWTIssuer(
issuer="https://test-server.com",
audience="https://test-server.com/mcp",
signing_key=signing_key,
)
def test_issue_access_token_creates_valid_jwt(self, issuer):
"""Test that access token is a minimal JWT with correct structure."""
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read", "write"],
jti="token-id-123",
expires_in=3600,
)
# Should be a JWT with 3 segments
assert len(token.split(".")) == 3
# Should be verifiable
payload = issuer.verify_token(token)
# Minimal token should only have required claims
assert payload["client_id"] == "client-abc"
assert payload["scope"] == "read write"
assert payload["jti"] == "token-id-123"
assert payload["iss"] == "https://test-server.com"
assert payload["aud"] == "https://test-server.com/mcp"
# Should NOT have user identity claims
assert "sub" not in payload
assert "azp" not in payload
def test_minimal_token_has_no_user_identity(self, issuer):
"""Test that minimal tokens contain no user identity or custom claims."""
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id",
expires_in=3600,
)
payload = issuer.verify_token(token)
# Should only have minimal required claims
assert "sub" not in payload
assert "azp" not in payload
assert "groups" not in payload
assert "roles" not in payload
assert "email" not in payload
# Should have exactly these claims
expected_keys = {"iss", "aud", "client_id", "scope", "exp", "iat", "jti"}
assert set(payload.keys()) == expected_keys
def test_issue_refresh_token_creates_valid_jwt(self, issuer):
"""Test that refresh token is a minimal JWT with token_use claim."""
token = issuer.issue_refresh_token(
client_id="client-abc",
scopes=["read"],
jti="refresh-token-id",
expires_in=60 * 60 * 24 * 30, # 30 days
)
payload = issuer.verify_token(token, expected_token_use="refresh")
assert payload["client_id"] == "client-abc"
assert payload["token_use"] == "refresh"
assert payload["jti"] == "refresh-token-id"
# Should NOT have user identity
assert "sub" not in payload
def test_verify_token_validates_signature(self, issuer):
"""Test that token verification fails with wrong signing key."""
# Create token with one issuer
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id",
)
# Try to verify with different issuer (different key)
other_key = derive_jwt_key(
low_entropy_material="different-secret", salt="different-salt"
)
other_issuer = JWTIssuer(
issuer="https://test-server.com",
audience="https://test-server.com/mcp",
signing_key=other_key,
)
with pytest.raises(JoseError):
other_issuer.verify_token(token)
def test_verify_token_validates_expiration(self, issuer):
"""Test that expired tokens are rejected."""
# Create token that expires in 1 second
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id",
expires_in=1,
)
# Should be valid immediately
payload = issuer.verify_token(token)
assert payload["client_id"] == "client-abc"
# Wait for token to expire
time.sleep(1.1)
# Should be rejected
with pytest.raises(JoseError, match="expired"):
issuer.verify_token(token)
def test_verify_token_validates_issuer(self, issuer):
"""Test that tokens from different issuers are rejected."""
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id",
)
# Create issuer with different issuer URL but same key
other_issuer = JWTIssuer(
issuer="https://other-server.com", # Different issuer
audience="https://test-server.com/mcp",
signing_key=issuer._signing_key, # Same key
)
with pytest.raises(JoseError, match="issuer"):
other_issuer.verify_token(token)
def test_verify_token_validates_audience(self, issuer):
"""Test that tokens for different audiences are rejected."""
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id",
)
# Create issuer with different audience but same key
other_issuer = JWTIssuer(
issuer="https://test-server.com",
audience="https://other-server.com/mcp", # Different audience
signing_key=issuer._signing_key, # Same key
)
with pytest.raises(JoseError, match="audience"):
other_issuer.verify_token(token)
def test_verify_token_rejects_malformed_tokens(self, issuer):
"""Test that malformed tokens are rejected."""
with pytest.raises(JoseError):
issuer.verify_token("not-a-jwt")
with pytest.raises(JoseError):
issuer.verify_token("too.few.segments")
with pytest.raises(JoseError):
issuer.verify_token("header.payload") # Missing signature
def test_issue_access_token_with_upstream_claims(self, issuer):
"""Test that upstream claims are included when provided."""
upstream_claims = {
"sub": "user-123",
"oid": "object-id-456",
"name": "Test User",
"email": "test@example.com",
"roles": ["Admin", "Reader"],
}
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read", "write"],
jti="token-id-123",
expires_in=3600,
upstream_claims=upstream_claims,
)
payload = issuer.verify_token(token)
assert "upstream_claims" in payload
assert payload["upstream_claims"]["sub"] == "user-123"
assert payload["upstream_claims"]["oid"] == "object-id-456"
assert payload["upstream_claims"]["name"] == "Test User"
assert payload["upstream_claims"]["email"] == "test@example.com"
assert payload["upstream_claims"]["roles"] == ["Admin", "Reader"]
def test_issue_access_token_without_upstream_claims(self, issuer):
"""Test that upstream_claims is not present when not provided."""
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id-123",
expires_in=3600,
)
payload = issuer.verify_token(token)
assert "upstream_claims" not in payload
def test_issue_refresh_token_with_upstream_claims(self, issuer):
"""Test that refresh tokens also include upstream claims when provided."""
upstream_claims = {
"sub": "user-123",
"name": "Test User",
}
token = issuer.issue_refresh_token(
client_id="client-abc",
scopes=["read"],
jti="refresh-token-id",
expires_in=60 * 60 * 24 * 30,
upstream_claims=upstream_claims,
)
payload = issuer.verify_token(token, expected_token_use="refresh")
assert "upstream_claims" in payload
assert payload["upstream_claims"]["sub"] == "user-123"
assert payload["upstream_claims"]["name"] == "Test User"
assert payload["token_use"] == "refresh"
def test_verify_token_rejects_refresh_token_as_access(self, issuer):
"""Refresh tokens must not be accepted when expecting access tokens."""
token = issuer.issue_refresh_token(
client_id="client-abc",
scopes=["read"],
jti="refresh-token-id",
expires_in=60 * 60 * 24 * 30,
)
with pytest.raises(JoseError, match="Token type mismatch"):
issuer.verify_token(token)
def test_verify_token_rejects_access_token_as_refresh(self, issuer):
"""Access tokens must not be accepted when expecting refresh tokens."""
token = issuer.issue_access_token(
client_id="client-abc",
scopes=["read"],
jti="token-id",
)
with pytest.raises(JoseError, match="Token type mismatch"):
issuer.verify_token(token, expected_token_use="refresh")