feat: compose authenticated stdio MCP with explicit runtime tool mapping
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
1ece969f59
commit
3c5cbfbafe
14 changed files with 465 additions and 81 deletions
|
|
@ -120,10 +120,13 @@ MCP hosts may supply `token_provider`, a callable resolving a **Hub-audience**
|
|||
credential from the current invocation, with `require_credentials=True`. Credentials
|
||||
are never retained on the server; requests do not follow redirects when carrying
|
||||
one. `trailing_slash=False` targets the standalone runtime's native paths. The
|
||||
standalone production MCP has no human flow/provider yet and fails closed.
|
||||
standalone production MCP supports only explicit single-principal stdio credentials;
|
||||
network transports require an authenticated host composition. The standalone
|
||||
profile advertises four mapped runtime tools; legacy operations remain embedded-only.
|
||||
Many legacy tools target APIs the standalone Hub does not implement. They remain
|
||||
unsupported, not silently translated or authorized. Cross-audience delegation,
|
||||
browser PKCE sessions/logout and real MCP root login remain open.
|
||||
unsupported, not silently translated or authorized. Cross-audience delegation
|
||||
remains open. Browser PKCE sessions/logout are implemented locally; live browser/MCP caller
|
||||
admission remains open. See the [MCP composition contract](owner-access-integration.md#mcp-caller-composition-and-backend-mapping).
|
||||
|
||||
## Remaining release gates
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue