feat(auth): CLI tokens minted at /connect for containerized MCP clients
Adds a second token kind alongside Authentik OIDC access tokens for MCP authentication. When the user visits /connect after signing into the Web UI, the server mints an HMAC-signed JWT (kid="cli-v1") carrying their Authentik identity in oidc_iss / oidc_sub claims. The token is shown once in React state — never put in the URL or persisted on the client. The MCP endpoint's bearer-token verifier dispatches by JWT `kid` header: CLI tokens are verified locally via HS256(CLI_TOKEN_SECRET); everything else goes through Authentik JWKS. Both paths resolve to the same AuthenticatedClaims shape so userContextFromClaims handles them identically. This unblocks MCP clients running in containers where the OAuth loopback callback isn't reachable — paste the token into Claude Code as a static Authorization header and skip the OAuth flow entirely. Revocation in v1 is "rotate CLI_TOKEN_SECRET to invalidate every issued CLI token at once." Per-token revocation can come later if needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,13 +1,21 @@
|
||||
import { createRemoteJWKSet, jwtVerify, errors as joseErrors } from "jose";
|
||||
import type { JWTPayload } from "jose";
|
||||
import { env } from "@/lib/env";
|
||||
import { CLI_TOKEN_KID, tokenKid, verifyCliToken } from "./cli-token";
|
||||
|
||||
/**
|
||||
* Authenticates a bearer token issued by Authentik against the configured
|
||||
* OIDC issuer. Verifies signature (via JWKS), issuer, audience, and expiry.
|
||||
* Authenticates a bearer token presented to the MCP endpoint. Two token
|
||||
* kinds are accepted, dispatched by the JWT `kid` header:
|
||||
*
|
||||
* Used by the MCP endpoint to authenticate incoming Claude Code requests.
|
||||
* Distinct from the NextAuth session cookie path used by the Web UI.
|
||||
* - Authentik-issued OIDC access tokens (any kid) — verified against
|
||||
* Authentik's JWKS over the network.
|
||||
* - CLI tokens minted at /connect (kid="cli-v1") — verified locally
|
||||
* with the HMAC CLI_TOKEN_SECRET.
|
||||
*
|
||||
* Both resolve to the same `AuthenticatedClaims` shape so downstream code
|
||||
* (`userContextFromClaims`) doesn't care which path produced them.
|
||||
*
|
||||
* This is distinct from the NextAuth session cookie path used by the Web UI.
|
||||
*/
|
||||
|
||||
type GlobalWithJwks = typeof globalThis & {
|
||||
@@ -64,7 +72,24 @@ export async function authenticateBearer(authHeader: string | null): Promise<Aut
|
||||
throw new UnauthorizedError("empty bearer token", buildWwwAuthenticate("invalid_token"));
|
||||
}
|
||||
|
||||
// Dispatch by kid: CLI tokens are verified locally, everything else goes
|
||||
// through Authentik JWKS. We never attempt JWKS verification for CLI
|
||||
// tokens (or vice versa) so a kid mismatch fails fast.
|
||||
const isCliToken = tokenKid(token) === CLI_TOKEN_KID;
|
||||
|
||||
try {
|
||||
if (isCliToken) {
|
||||
const claims = await verifyCliToken(token);
|
||||
// CLI tokens carry the user's real Authentik identity in oidc_iss /
|
||||
// oidc_sub. Surface those on the standard claims shape so user
|
||||
// context resolution is identical to the Authentik path.
|
||||
return {
|
||||
...claims,
|
||||
iss: claims.oidc_iss,
|
||||
sub: claims.oidc_sub,
|
||||
} as AuthenticatedClaims;
|
||||
}
|
||||
|
||||
const { payload } = await jwtVerify(token, jwks(), {
|
||||
issuer: env().OIDC_ISSUER,
|
||||
audience: env().OIDC_AUDIENCE,
|
||||
|
||||
Reference in New Issue
Block a user