diff --git a/package-lock.json b/package-lock.json index 668d2bb..9b11d63 100644 --- a/package-lock.json +++ b/package-lock.json @@ -3643,7 +3643,6 @@ "version": "0.1.8", "resolved": "https://registry.npmjs.org/errno/-/errno-0.1.8.tgz", "integrity": "sha512-dJ6oBr5SQ1VSd9qkk7ByRgb/1SH4JZjCHSW/mr63/QcXO9zLVxvJ6Oy13nio03rxpSnVDDjFor75SjVeZWPW/A==", - "dev": true, "license": "MIT", "optional": true, "dependencies": { @@ -3944,7 +3943,6 @@ "version": "4.2.11", "resolved": "https://registry.npmjs.org/graceful-fs/-/graceful-fs-4.2.11.tgz", "integrity": "sha512-RbJ5/jmFcNNCcDV5o9eTnBLJ/HszWV0P73bc+Ff4nS/rJj+YaS6IGyiOL0VoBYX+l1Wrl3k63h/KrH+nhJ0XvQ==", - "dev": true, "license": "ISC", "optional": true }, @@ -4033,7 +4031,7 @@ "version": "0.6.3", "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.6.3.tgz", "integrity": "sha512-4fCk79wshMdzMp2rH06qWrJE4iolqLhCUH+OiuIgU++RB0+94NlDL81atO7GX55uUKueo0txHNtvEyI6D7WdMw==", - "dev": true, + "devOptional": true, "license": "MIT", "dependencies": { "safer-buffer": ">= 2.1.2 < 3.0.0" @@ -4056,7 +4054,6 @@ "version": "0.5.5", "resolved": "https://registry.npmjs.org/image-size/-/image-size-0.5.5.tgz", "integrity": "sha512-6TDAlDPZxUFCv+fuOkIoXT/V/f3Qbq8e37p+YOiYrUv3v9cc3/6x78VdfPgFVaB9dZYeLUfKgHRebpkm/oP2VQ==", - "dev": true, "license": "MIT", "optional": true, "bin": { @@ -4417,7 +4414,6 @@ "version": "2.1.0", "resolved": "https://registry.npmjs.org/make-dir/-/make-dir-2.1.0.tgz", "integrity": "sha512-LS9X+dc8KLxXCb8dni79fLIIUA5VyZoyjSMCwTluaXA0o27cCK0bhXkpgw+sTXVpPy/lSO57ilRixqk0vDmtRA==", - "dev": true, "license": "MIT", "optional": true, "dependencies": { @@ -4665,7 +4661,6 @@ "version": "1.6.0", "resolved": "https://registry.npmjs.org/mime/-/mime-1.6.0.tgz", "integrity": "sha512-x0Vn8spI+wuJ1O6S7gnbaQg8Pxh4NNHb7KSINmEWKiPE4RKOplvijn+NkmYmmRgP68mc70j2EbeTFRsrswaQeg==", - "dev": true, "license": "MIT", "optional": true, "bin": { @@ -4758,7 +4753,6 @@ "version": "3.3.1", "resolved": "https://registry.npmjs.org/needle/-/needle-3.3.1.tgz", "integrity": "sha512-6k0YULvhpw+RoLNiQCRKOl09Rv1dPLr8hHnVjHqdolKwDrdNyk+Hmrthi4lIGPPz3r39dLx0hsF5s40sZ3Us4Q==", - "dev": true, "license": "MIT", "optional": true, "dependencies": { @@ -4970,7 +4964,6 @@ "version": "4.0.1", "resolved": "https://registry.npmjs.org/pify/-/pify-4.0.1.tgz", "integrity": "sha512-uB80kBFb/tfd68bVleG9T5GGsGPjJrLAUpR5PZIrhBnIaRTQRjqdJSsIKkOP6OAIFbj7GOrcudc5pNjZ+geV2g==", - "dev": true, "license": "MIT", "optional": true, "engines": { @@ -5072,7 +5065,6 @@ "version": "1.0.1", "resolved": "https://registry.npmjs.org/prr/-/prr-1.0.1.tgz", "integrity": "sha512-yPw4Sng1gWghHQWj0B3ZggWUm4qVbPwPFcRG8KyxiU7J2OHFSoEHKS+EZ3fv5l1t9CyCiop6l/ZYeWbrgoQejw==", - "dev": true, "license": "MIT", "optional": true }, @@ -5271,14 +5263,13 @@ "version": "2.1.2", "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz", "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==", - "dev": true, + "devOptional": true, "license": "MIT" }, "node_modules/sax": { "version": "1.4.1", "resolved": "https://registry.npmjs.org/sax/-/sax-1.4.1.tgz", "integrity": "sha512-+aWOz7yVScEGoKNd4PA10LZ8sk0A/z5+nXQG5giUO5rprX9jgYsTdov9qCchZiPIZezbZH+jRut8nPodFAX4Jg==", - "dev": true, "license": "ISC", "optional": true }, @@ -5306,7 +5297,6 @@ "version": "5.7.2", "resolved": "https://registry.npmjs.org/semver/-/semver-5.7.2.tgz", "integrity": "sha512-cBznnQ9KjJqU67B52RMC65CMarK2600WFnbkcaiwWq3xy/5haFJlshgnpjovMVJ+Hff49d8GEn0b87C5pDQ10g==", - "dev": true, "license": "ISC", "optional": true, "bin": { @@ -5381,7 +5371,6 @@ "version": "0.6.1", "resolved": "https://registry.npmjs.org/source-map/-/source-map-0.6.1.tgz", "integrity": "sha512-UjgapumWlbMhkBgzT7Ykc5YXUT46F0iKu8SGXq0bcwP5dz/h0Plj6enJqjz1Zbq2l5WaqYnrVbwWOWMyF3F47g==", - "dev": true, "license": "BSD-3-Clause", "optional": true, "engines": { diff --git a/plugin-tutorial/usage/images/oauth-github-ak.png b/plugin-tutorial/usage/images/oauth-github-ak.png new file mode 100644 index 0000000..c2b9813 Binary files /dev/null and b/plugin-tutorial/usage/images/oauth-github-ak.png differ diff --git a/plugin-tutorial/usage/images/oauth-github-new-application.png b/plugin-tutorial/usage/images/oauth-github-new-application.png new file mode 100644 index 0000000..dc26ccd Binary files /dev/null and b/plugin-tutorial/usage/images/oauth-github-new-application.png differ diff --git a/plugin-tutorial/usage/images/oauth-github-success.png b/plugin-tutorial/usage/images/oauth-github-success.png new file mode 100644 index 0000000..c84c737 Binary files /dev/null and b/plugin-tutorial/usage/images/oauth-github-success.png differ diff --git a/plugin-tutorial/usage/images/oauth-github-tool.png b/plugin-tutorial/usage/images/oauth-github-tool.png new file mode 100644 index 0000000..f503075 Binary files /dev/null and b/plugin-tutorial/usage/images/oauth-github-tool.png differ diff --git a/plugin-tutorial/usage/sse-oauth2.md b/plugin-tutorial/usage/sse-oauth2.md index 7fb85f4..b422090 100644 --- a/plugin-tutorial/usage/sse-oauth2.md +++ b/plugin-tutorial/usage/sse-oauth2.md @@ -1 +1,75 @@ -# SSE 在线部署的鉴权器实现 \ No newline at end of file +# MCP Server的OAuth鉴权实现 + +在使用 **SSE** 或 **Streamable HTTP** 进行连接时,为增强安全性可为接口设计鉴权机制,MCP 官方推荐采用 OAuth 协议。下面以获取 GitHub 用户信息为例,演示如何通过 openmcp-client 完成带 OAuth 认证的接口调试。 + + +## 部署服务器 + + + +### 1. 获取Github OAuth认证ID和secret + +由于我们使用了Github用户信息相关API,需要先获取Github OAuth应用的Client ID和Client secret。 + +先进入[Github Developers](https://github.com/settings/developers),点击`New OAuth App`新建一个OAuth APP,应用名称随便填,`Homepage URL`填写`http://localhost:8000`,`Authorization callback URL`填写`http://localhost:8000/github/callback`。然后点击`Register application`按钮,即可成功注册一个应用。 + + +![](images/oauth-github-new-application.png) + + +注册成功后,请记录`Client ID`,然后点击`Generate a new client secret`生成一个`secret`,注意secret仅在生成的时候可见。 + +### 2. 设置环境变量 + +在获取`Client ID`和`secret`之后,需要将其设置为环境变量: + +在bash里: + +```bash +export MCP_GITHUB_GITHUB_CLIENT_ID={{Client ID}} +export MCP_GITHUB_GITHUB_CLIENT_SECRET={{secret}} +``` + +在windows cmd里: + +```bash +set MCP_GITHUB_GITHUB_CLIENT_ID={{Client ID}} +set MCP_GITHUB_GITHUB_CLIENT_SECRET={{secret}} +``` + +注意:cmd里面设置环境变量请不要加引号。 + +### 3. 克隆源码 + +首先,我们需要部署MCP服务器。可以参照[官方python例子](https://github.com/modelcontextprotocol/python-sdk/tree/main/examples/servers/simple-auth)进行。 + +需要先克隆官方python-sdk源码: + +```bash +git clone https://github.com/modelcontextprotocol/python-sdk/ # 克隆源码 +cd examples/servers/simple-auth # 进入对应的目录 +``` + +### 4. 启动MCP Server + +先根据需要创建虚拟环境安装依赖,然后直接运行`python main.py`即可,注意需要先设置环境变量,不然启动会报错`2 validation errors for ServerSettings`。 + +### 5. 启动openmcp-client + +接下来,你就可以使用openmcp-client连接刚刚启动的server了,不管是使用网页端还是VSCode均可。 + +点击加号添加连接,根据server代码中的`--transport`参数决定是SSE还是Streamable HTTP。如果是SSE,则URL填写`http://localhost:8000/sse`;如果是Streamable HTTP,则URL填写`http://localhost:8000/mcp`。认证签名无需填写。 + +接下来连接到当前server,此时会自动打开一个网页进行认证,首次打开需要点击认证,认证成功后该网页会自动关闭。 + +![](images/oauth-github-success.png) + +认证成功后,进入工具页面,应该能看到一个`get_user_profile`工具,点击使用就可以获取到你的Github个人信息了。 + +![](images/oauth-github-tool.png) + + + + + +