返回 CodeWhale
auth_bearer_never_recorded.case.json
根目录 / crates / tui / tests / fixtures / conformance / mcp / auth_bearer_never_recorded.case.json
1 {
2 "description": "A bearer-token server (token from bearer_token_env_var, secret supplied by the harness and required by the server). Pins Rust McpHttpAuth::resolved_headers / StreamableHttpTransport::send / bounded_body_excerpt: the token authenticates every request (the call succeeds only because the server saw it), a server that echoes the credential back in an error body has it redacted, and a 401 mid-session surfaces the needs-auth transition (success=false, mcp_catalog_changed) with the bearer-token recovery hint. The harness fails if the secret appears in any recorded byte; requests record only the Authorization header's shape.",
3 "server_name": "conformance",
4 "bearer_secret": "conformance-secret-token-7f3a91c4e2",
5 "server_options": {
6 "require_bearer": true
7 },
8 "record_requests": "summary",
9 "server": {
10 "initialize": {
11 "result": {
12 "protocolVersion": "2025-06-18",
13 "serverInfo": {
14 "name": "bearer-fixture",
15 "version": "1.0.0"
16 },
17 "capabilities": {
18 "tools": {}
19 }
20 }
21 },
22 "tools/list": {
23 "result": {
24 "tools": [
25 {
26 "name": "echo",
27 "inputSchema": {
28 "type": "object"
29 }
30 },
31 {
32 "name": "echo_credential",
33 "description": "A buggy server: answers 500 and repeats the Authorization header.",
34 "inputSchema": {
35 "type": "object"
36 }
37 },
38 {
39 "name": "revoked",
40 "description": "The token stops being accepted mid-session.",
41 "inputSchema": {
42 "type": "object"
43 }
44 }
45 ]
46 }
47 },
48 "tools/call": [
49 {
50 "match": {
51 "name": "echo"
52 },
53 "result": {
54 "content": [
55 {
56 "type": "text",
57 "text": "authenticated"
58 }
59 ]
60 }
61 },
62 {
63 "match": {
64 "name": "echo_credential"
65 },
66 "http": {
67 "status": 500,
68 "body": "upstream failure while handling Authorization: {{authorization}}"
69 }
70 },
71 {
72 "match": {
73 "name": "revoked"
74 },
75 "http": {
76 "status": 401,
77 "headers": {
78 "WWW-Authenticate": "Bearer error=\"invalid_token\""
79 },
80 "body": "{\"error\":\"invalid_token\"}"
81 }
82 }
83 ]
84 },
85 "steps": [
86 {
87 "op": "catalog"
88 },
89 {
90 "op": "call",
91 "tool": "mcp_conformance_echo",
92 "input": {}
93 },
94 {
95 "op": "call",
96 "tool": "mcp_conformance_echo_credential",
97 "input": {}
98 },
99 {
100 "op": "call",
101 "tool": "mcp_conformance_revoked",
102 "input": {}
103 },
104 {
105 "op": "catalog"
106 }
107 ]
108 }
109
109 lines JSON