Skip to main content

prism_mcp_rs/auth/
mod.rs

1//! OAuth 2.1 Authorization Support for MCP Protocol
2//!
3//! Module implements the authorization flow for HTTP-based MCP transports
4//! as specified in the MCP Authorization specification (draft).
5//!
6//! The implementation follows OAuth 2.1, OAuth 2.0 Authorization Server Metadata,
7//! Dynamic Client Registration, and Protected Resource Metadata specifications.
8
9pub mod client;
10pub mod discovery;
11pub mod errors;
12pub mod pkce;
13pub mod token;
14pub mod types;
15
16pub use client::*;
17pub use discovery::*;
18pub use errors::*;
19pub use pkce::*;
20pub use token::*;
21pub use types::*;
22
23// Error types are re-exported from submodules
24
25/// Authorization configuration for MCP
26#[derive(Clone)]
27pub struct AuthConfig {
28    /// Enable authorization for this client/server
29    pub enabled: bool,
30
31    /// Client ID for OAuth (if pre-registered)
32    pub client_id: Option<String>,
33
34    /// Client secret (for confidential clients)
35    pub client_secret: Option<String>,
36
37    /// Redirect URI for authorization code flow
38    pub redirect_uri: String,
39
40    /// Scopes to request
41    pub scopes: Vec<String>,
42
43    /// Enable dynamic client registration
44    pub enable_dynamic_registration: bool,
45}
46
47impl Default for AuthConfig {
48    fn default() -> Self {
49        Self {
50            enabled: false,
51            client_id: None,
52            client_secret: None,
53            redirect_uri: "http://localhost:8080/callback".to_string(),
54            scopes: vec![],
55            enable_dynamic_registration: true,
56        }
57    }
58}
59
60impl AuthConfig {
61    /// Create a new authorization configuration
62    pub fn new() -> Self {
63        Self::default()
64    }
65
66    /// Enable authorization
67    pub fn with_auth(mut self, enabled: bool) -> Self {
68        self.enabled = enabled;
69        self
70    }
71
72    /// Set client credentials
73    pub fn with_client_credentials(
74        mut self,
75        client_id: String,
76        client_secret: Option<String>,
77    ) -> Self {
78        self.client_id = Some(client_id);
79        self.client_secret = client_secret;
80        self
81    }
82
83    /// Set redirect URI
84    pub fn with_redirect_uri(mut self, uri: String) -> Self {
85        self.redirect_uri = uri;
86        self
87    }
88
89    /// Set scopes
90    pub fn with_scopes(mut self, scopes: Vec<String>) -> Self {
91        self.scopes = scopes;
92        self
93    }
94
95    /// Generate a state parameter
96    pub fn generate_state(&self) -> String {
97        // Default: generate random state
98        use rand::RngExt;
99        let mut rng = rand::rng();
100        let state: String = (0..32)
101            .map(|_| {
102                let idx = rng.random_range(0..62);
103                let chars = b"abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
104                chars[idx] as char
105            })
106            .collect();
107        state
108    }
109}