Skip to content

Handle valid authentication challenge parameters and tokens - #12

Merged
quinnj merged 3 commits into
mainfrom
fix/auth-param-whitespace
Sep 21, 2026
Merged

quinnj merged 3 commits into
mainfrom
fix/auth-param-whitespace

Conversation

@quinnj

@quinnj quinnj commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Authentication challenges could lose resource metadata and scopes with whitespace before = or mixed-case parameter names. The parser also treated a padded token such as Negotiate abc== as a parameter instead of a token.

Handle parameter whitespace, token68 padding, and case-insensitive parameter names. Preserve parameter value case. Keep the local parser so MCP's existing HTTP/OAuth dependency choices remain supported. The grammar is defined in RFC 9110 section 11.3.

Validation: 84 added parser/challenge assertions, including whitespace, quoted/unquoted metadata, scopes, multiple schemes, padded tokens, and mixed-case names and values. Full Julia 1.10.11 and 1.12.6 suites passed, including real HTTP discovery and the Julia 1.12 trimmed executable (7 trim assertions). The required documentation build and doctests also passed.

Co-authored by Codex

@quinnj quinnj changed the title Preserve authentication parameters with whitespace Handle whitespace and padded authentication tokens Sep 19, 2026
@quinnj quinnj changed the title Handle whitespace and padded authentication tokens Handle valid authentication challenge parameters and tokens Sep 19, 2026
@quinnj
quinnj merged commit d231bfd into main Sep 21, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant