Module: MCPClient::RequestAuthorization

Included in:
HttpTransportBase::CacheSupport, ServerSSE
Defined in:
lib/mcp_client/request_authorization.rb

Overview

The Authorization one request went out with, kept per thread and per transport (MCP 2026-07-28 caching, cacheScope "private"): a result is bound to the credentials of its own request rather than to whatever the transport is configured with at the moment it is recorded.

Every transport that can send an Authorization header keeps it the same way, in a slot named after the transport's object_id so that MCPClient::ResultCaching#forget_transport_thread_state finds it: a worker thread that builds and discards transports must not keep one entry per transport for its whole life.

Constant Summary collapse

UNRECORDED_AUTHORIZATION =

Thread-local marker meaning "this attempt has not applied its headers yet": a failure before that point leaves the credentials of the attempt unknown, so no private stale copy may be served for it.

:unrecorded
ANONYMOUS_AUTHORIZATION =

Thread-local marker for "this attempt went out with no Authorization at all". The anonymous context is nil everywhere else, and an empty thread-local slot is nil too: a request that really was anonymous is noted with this marker so that a slot a cleanup dropped reads as unrecorded rather than as an anonymous request that never happened.

:anonymous