Commit 874e11b9 authored by Irene Denazi's avatar Irene Denazi
Browse files

Issue #7: Fix MCP BE Authorization issue with MCP server

parent 90aede6a
Loading
Loading
Loading
Loading
Loading
+17 −10
Original line number Diff line number Diff line
package org.etsi.osl.mcp.backend.configuration;

import org.springaicommunity.mcp.security.client.sync.AuthenticationMcpTransportContextProvider;
import org.springaicommunity.mcp.security.client.sync.oauth2.http.client.OAuth2AuthorizationCodeSyncHttpRequestCustomizer;
import org.springframework.ai.mcp.customizer.McpSyncClientCustomizer;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.oauth2.client.OAuth2AuthorizedClientManager;
import org.springframework.security.oauth2.client.registration.ClientRegistrationRepository;
import org.springframework.security.oauth2.client.registration.InMemoryClientRegistrationRepository;

import io.modelcontextprotocol.client.transport.customizer.McpSyncHttpClientRequestCustomizer;

/**
 * @author Daniel Garnier-Moiroux
 */
@@ -13,17 +20,17 @@ class McpConfiguration {
    // Disabled OAuth2 customization for MCP client - not needed for JWT-based API
    // The MCP server connection doesn't need OAuth2 authentication
    
    // @Bean
    // McpSyncHttpClientRequestCustomizer requestCustomizer(OAuth2AuthorizedClientManager oAuth2AuthorizedClientManager,
    //         ClientRegistrationRepository clientRegistrationRepository) {
    //     var registrationId = findUniqueClientRegistration(clientRegistrationRepository);
    //     return new OAuth2AuthorizationCodeSyncHttpRequestCustomizer(oAuth2AuthorizedClientManager, registrationId);
    // }

    // @Bean
    // McpSyncClientCustomizer syncClientCustomizer() {
    //     return (name, syncSpec) -> syncSpec.transportContextProvider(new AuthenticationMcpTransportContextProvider());
    // }
    @Bean
    McpSyncHttpClientRequestCustomizer requestCustomizer(OAuth2AuthorizedClientManager oAuth2AuthorizedClientManager,
            ClientRegistrationRepository clientRegistrationRepository) {
        var registrationId = findUniqueClientRegistration(clientRegistrationRepository);
        return new OAuth2AuthorizationCodeSyncHttpRequestCustomizer(oAuth2AuthorizedClientManager, registrationId);
    }

    @Bean
    McpSyncClientCustomizer syncClientCustomizer() {
        return (name, syncSpec) -> syncSpec.transportContextProvider(new AuthenticationMcpTransportContextProvider());
    }

    /**
     * Returns the ID of the {@code spring.security.oauth2.client.registration}, if