Module: MCPClient::Auth::OAuthProvider::ClientAuthentication
- Included in:
- MCPClient::Auth::OAuthProvider
- Defined in:
- lib/mcp_client/auth/oauth_provider/client_authentication.rb
Overview
How this client authenticates at the token endpoint.
A confidential client — one the authorization server issued a
client_secret to — must present that secret with every token
request, and RFC 7591 Section 2 says how: "if unspecified or omitted,
the default is client_secret_basic". This client used to send the
secret only for client_secret_post and to record an omitted method
as none, which is the one combination that never authenticates: a
registration that issued a secret and named no method produced a
record whose secret was never sent, and every token request went out
as an unauthenticated client for an authorization server that expects
HTTP Basic.
So the method the authorization server registered decides, defaulting as the RFC does:
client_secret_basic— the credentials go in anAuthorization: Basicheader, form-urlencoded before they are base64'd (RFC 6749 Section 2.3.1), never in the body;client_secret_post— in the request body, as before;none(a public client, or no secret at all) — nothing is sent;- anything else (
private_key_jwt,client_secret_jwt, a method a future RFC adds) — this client cannot produce that assertion, so it sends no credentials and says so, rather than guessing with the secret in a header the server did not ask for.
Mixed into OAuthProvider.
Constant Summary collapse
- DEFAULT_TOKEN_ENDPOINT_AUTH_METHOD =
RFC 7591 Section 2: the
token_endpoint_auth_methoda registration response that names none is read as. 'client_secret_basic'- NO_CLIENT_AUTHENTICATION =
The method a public client declares: no credentials are sent.
'none'