Patch Changes
-
#2952
5a18673Thanks @claude! -requireBearerAuthin@modelcontextprotocol/server-legacytakes the optionalexpectedResourcethat@modelcontextprotocol/server2.3.0 and@modelcontextprotocol/sdk1.32.0 added: the resource the token must be issued for (its audience), usually the server's URL. When it is set, a token is accepted only if the verifier reports that value inAuthInfo.resource; the two are compared as strings, ignoring a fragment and one trailing slash. A token reported for another value, or for none, is answered401 invalid_tokenwith the usualWWW-Authenticatechallenge. When it is not set, nothing changes. The package stays frozen otherwise; this option is added so that itsrequireBearerAuthmatches the 1.x middleware it is a copy of. -
Updated dependencies []:
- @modelcontextprotocol/core@2.3.1