Repository navigation
docs: separate tool discovery and execution authorization - #3647
Closed
starsstreaming wants to merge 1 commit into
Closed
starsstreaming wants to merge 1 commit into
starsstreaming wants to merge 1 commit into
Conversation
Contributor
|
This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and this PR doesn't link an open issue yet.
You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Authenticated callers need permission for both the operation and the target data.
Add an authorization-guide example that separates token verification, tool
discovery, operation scopes, and tenant ownership without changing SDK APIs.
Motivation and Context
The existing guide explains token verification and caller identity, but does not
show a complete per-tool and per-resource policy. The new example has two tools:
notes_read(note_id)andnotes_update(note_id, text).A read-only caller sees only
notes_read; guessingnotes_updatestill results indenial before its handler runs. A writer can update its own tenant's note but
cannot access another tenant's note. Scope rules are shared between discovery and
execution, and handlers enforce scopes independently of provisional middleware.
Tenant identity comes from trusted token claims, never tool arguments.
The guide explains generic RPC denials, demo-only tokens, caller-specific
discovery, and atomic ownership checks for persistent data. Missing and foreign
notes receive the same error without resource details.
Issue linkage: no assigned issue is currently linked to this documentation
contribution. The assignment checklist below is intentionally unchecked.
How Has This Been Tested?
in-process HTTP transport, including authentication rejection, guessed and
unconfigured tools, shared-server discovery across callers, tenant isolation,
denied-write preservation, and handler enforcement without middleware.
branch coverage;
strict-no-coverpasses.inventory failures allowed because downloads were restricted in the environment.
Breaking Changes
None. This adds documentation, an example, and tests only.
Types of changes
Checklist
help wanted, or I'm a maintainer)Additional context
AI assistance disclosure: This contribution was prepared with Codex assistance
and reviewed by the contributor before submission.