Skip to content

Gateway: CIMD (client_id metadata documents) with SSRF-safe fetch #405

Description

@kengio

PR #403 ships RFC 7591 DCR only, which recon confirmed is sufficient on its own for both ChatGPT and Claude connectors today. CIMD is the spec's preferred mechanism (MCP 2026-07-28 downgraded DCR to MAY/back-compat) and avoids registering a fresh client on every connection.

Deliberately deferred from PR 3 because the AS must fetch an attacker-supplied HTTPS URL and validate the returned document — that needs an SSRF-safe fetch path (no redirects to private ranges, no loopback/link-local/metadata endpoints, timeouts, size caps, cache-header handling), which is real security work and was wrong to rush.

Requirements when built:

  • client_id is an HTTPS URL with a path; fetch it, validate the document's client_id matches the URL exactly (self-referential), validate redirect_uri against the document's redirect_uris, validate required fields.
  • Advertise client_id_metadata_document_supported: true and keep "none" in token_endpoint_auth_methods_supported (Claude selects CIMD only when BOTH are present, else falls back to DCR).
  • Consent screen must show the host of the client_id URL as the relying party, not the self-asserted client_name.
  • Cache respecting HTTP cache headers.

Should land before or with the tunnel phase.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions