Make client_secret optional in token revocation requests - #3512
HARSHAVARDHAN-RAJU5 wants to merge 1 commit into
Conversation
|
This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3508. If a maintainer assigns you to #3508, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take. You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
Fixes #3508
Public OAuth clients can now revoke tokens without sending
client_secret.Motivation and Context
RevocationRequest.client_secretwas declared asstr | Nonewith no default. Pydantic v2 treats that as required: the value can beNone, but the key has to be present. Public clients (token_endpoint_auth_method: "none") don't have a secret, so they leave the parameter out, as RFC 6749 §2.3 and RFC 7009 §5 allow./revokethen rejected them with:ClientAuthenticatoralready lets public clients through, so the only problem was the request model. The fix defaults the field toNone, which matches how the token endpoint handles it.How Has This Been Tested?
test_revoke_public_client_without_client_secret. It registers a client withtoken_endpoint_auth_method: "none", gives it an access token, and revokes that token withoutclient_secret. It checks for a 200 and that the token is gone.tests/server/mcpserver/auth/test_auth_integration.pypass.ruff format,ruff checkandpyrightare clean.Breaking Changes
None. Requests that already sent
client_secretbehave the same way.Types of changes
Checklist
help wanted, or I'm a maintainer)Additional context
This is a one-line change to the model plus a regression test. Nothing in the docs needed updating, because nothing there says
client_secretis required for revocation.