28 lines
1.2 KiB
Python
28 lines
1.2 KiB
Python
|
|
"""Single-principal stdio credentials; never use this for a shared MCP listener."""
|
||
|
|
from pathlib import Path
|
||
|
|
|
||
|
|
|
||
|
|
class StdioTokenFile:
|
||
|
|
"""Reread an operator-projected Hub-audience credential for every request.
|
||
|
|
|
||
|
|
This does not mint credentials or authenticate multiple callers. The process
|
||
|
|
and its private stdio transport must belong to the one admitted principal.
|
||
|
|
The Hub API validates issuer/audience/expiry and current authority.
|
||
|
|
"""
|
||
|
|
def __init__(self, path: Path):
|
||
|
|
if not path.is_absolute():
|
||
|
|
raise ValueError("absolute MCP credential path required")
|
||
|
|
self.path = path
|
||
|
|
|
||
|
|
def __call__(self) -> str:
|
||
|
|
# A bounded read prevents an accidentally mounted large file from being
|
||
|
|
# loaded. Errors are sanitized by the MCP HTTP adapter.
|
||
|
|
with self.path.open("r", encoding="ascii") as stream:
|
||
|
|
raw = stream.read(16386)
|
||
|
|
if len(raw) > 16385:
|
||
|
|
raise ValueError("current stdio credential unavailable")
|
||
|
|
value = raw.strip()
|
||
|
|
if not value or len(value) > 16384 or any(c.isspace() for c in value):
|
||
|
|
raise ValueError("current stdio credential unavailable")
|
||
|
|
return value
|