Add OAuth2 Client ID Metadata Document support
MCP connectors such as ChatGPT and Claude register via HTTPS client_id URLs instead of pre-provisioned GIDs. Fetch and cache their metadata documents, upsert clients on first use, and advertise CIMD in OIDC discovery when allowed URLs are configured. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
22
pkg/coredata/migrations/20260619T094531Z.sql
Normal file
22
pkg/coredata/migrations/20260619T094531Z.sql
Normal file
@@ -0,0 +1,22 @@
|
||||
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
||||
--
|
||||
-- Permission to use, copy, modify, and/or distribute this software for any
|
||||
-- purpose with or without fee is hereby granted, provided that the above
|
||||
-- copyright notice and this permission notice appear in all copies.
|
||||
--
|
||||
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
-- PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-- Store the HTTPS client_id URL for OAuth Client ID Metadata Document (CIMD)
|
||||
-- clients registered on first use (e.g. ChatGPT, Claude MCP connectors).
|
||||
ALTER TABLE iam_oauth2_clients
|
||||
ADD COLUMN external_client_id TEXT;
|
||||
|
||||
CREATE UNIQUE INDEX iam_oauth2_clients_external_client_id_unique
|
||||
ON iam_oauth2_clients (external_client_id)
|
||||
WHERE external_client_id IS NOT NULL;
|
||||
Reference in New Issue
Block a user