fastmcp/tests/server/auth
Jeremiah Lowin 9c21754a45
Fix Azure provider OIDC scope handling (#2506)
* Fix Azure provider to handle OIDC scopes correctly

OIDC scopes (openid, profile, email, offline_access) were being
incorrectly prefixed with identifier_uri, causing Azure to reject
authorization requests. This fix:

- Detects OIDC scopes and sends them unprefixed to Azure
- Filters OIDC scopes from token validation (Azure doesn't include
  them in access token scp claims)
- Still advertises OIDC scopes to clients via valid_scopes
- Also handles dot-notation scopes (e.g., User.Read) correctly

Fixes #2451, #2420

* Fix dot-notation scopes to be prefixed (custom scopes can have dots)

* Improve Azure scope handling docs with clear examples
2025-12-01 13:42:36 -05:00
..
providers Fix Azure provider OIDC scope handling (#2506) 2025-12-01 13:42:36 -05:00
__init__.py Add WorkOS and Azure OAuth providers (#1550) 2025-08-20 16:22:03 -04:00
test_auth_provider.py Upgrade to MCP 1.17+ with RFC 9728 compliance (#2122) 2025-10-17 09:29:23 -04:00
test_debug_verifier.py Add DebugTokenVerifier with custom sync/async validation (#2296) 2025-10-31 10:38:01 -04:00
test_enhanced_error_responses.py Derive jwt_signing_key from Client Secret, default to Encrypted Disk Store (#2223) 2025-10-24 19:08:58 -04:00
test_jwt_issuer.py Derive jwt_signing_key from Client Secret, default to Encrypted Disk Store (#2223) 2025-10-24 19:08:58 -04:00
test_jwt_provider.py Supporting Multiple Issuers For JWTVerifier Oauth Workflow (#2233) 2025-10-27 18:13:40 -04:00
test_oauth_consent_flow.py Add consent_csp_policy parameter for CSP customization (#2484) 2025-11-26 16:53:40 -05:00
test_oauth_mounting.py Fix OAuth metadata endpoint URLs when base_url differs from issuer_url (#2353) 2025-11-04 10:38:41 -05:00
test_oauth_proxy.py Cleanly render oauth errors from proxy (#2268) 2025-10-26 21:08:05 -04:00
test_oauth_proxy_redirect_validation.py Derive jwt_signing_key from Client Secret, default to Encrypted Disk Store (#2223) 2025-10-24 19:08:58 -04:00
test_oauth_proxy_storage.py Derive jwt_signing_key from Client Secret, default to Encrypted Disk Store (#2223) 2025-10-24 19:08:58 -04:00
test_oidc_proxy.py Add extra_authorize_params and extra_token_params to OIDCProxy 2025-11-17 11:57:58 -05:00
test_redirect_validation.py Fix OAuth redirect URI validation for DCR compatibility (#1661) 2025-08-28 15:19:56 -04:00
test_remote_auth_provider.py Support mounting OAuth-protected servers under path prefixes (#2119) 2025-10-17 11:44:49 -04:00
test_static_token_verifier.py Add documentation for get_access_token() dependency function (#1446) 2025-08-11 13:01:44 -04:00