Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
27 lines
1.2 KiB
Python
27 lines
1.2 KiB
Python
"""Single-principal stdio credentials; never use this for a shared MCP listener."""
|
|
from pathlib import Path
|
|
|
|
|
|
class StdioTokenFile:
|
|
"""Reread an operator-projected Hub-audience credential for every request.
|
|
|
|
This does not mint credentials or authenticate multiple callers. The process
|
|
and its private stdio transport must belong to the one admitted principal.
|
|
The Hub API validates issuer/audience/expiry and current authority.
|
|
"""
|
|
def __init__(self, path: Path):
|
|
if not path.is_absolute():
|
|
raise ValueError("absolute MCP credential path required")
|
|
self.path = path
|
|
|
|
def __call__(self) -> str:
|
|
# A bounded read prevents an accidentally mounted large file from being
|
|
# loaded. Errors are sanitized by the MCP HTTP adapter.
|
|
with self.path.open("r", encoding="ascii") as stream:
|
|
raw = stream.read(16386)
|
|
if len(raw) > 16385:
|
|
raise ValueError("current stdio credential unavailable")
|
|
value = raw.strip()
|
|
if not value or len(value) > 16384 or any(c.isspace() for c in value):
|
|
raise ValueError("current stdio credential unavailable")
|
|
return value
|