When authorization.resourceUri includes a path (for example https://mcp.example.com/mcp, which authorization.md lists as a valid canonical URI), protected-resource discovery breaks:
src/auth/prehandler.ts builds the 401 challenge as resource_metadata="${resourceUri}/.well-known/oauth-protected-resource". That gives https://mcp.example.com/mcp/.well-known/oauth-protected-resource, which returns 404.
src/routes/well-known.ts only serves /.well-known/oauth-protected-resource and /.well-known/oauth-protected-resource/mcp. The /mcp variant appends /mcp again and advertises resource: "https://mcp.example.com/mcp/mcp".
Expected (RFC 9728 §3.1): the metadata URL is the origin plus /.well-known/oauth-protected-resource plus the resource path, and the advertised resource equals resourceUri exactly.
Repro: configure resourceUri: 'https://mcp.example.com/mcp', send an unauthenticated request to /mcp, then fetch the URL in the resource_metadata parameter. The fetch returns 404.
Found while reviewing #170. Already present on main.
When
authorization.resourceUriincludes a path (for examplehttps://mcp.example.com/mcp, whichauthorization.mdlists as a valid canonical URI), protected-resource discovery breaks:src/auth/prehandler.tsbuilds the 401 challenge asresource_metadata="${resourceUri}/.well-known/oauth-protected-resource". That giveshttps://mcp.example.com/mcp/.well-known/oauth-protected-resource, which returns 404.src/routes/well-known.tsonly serves/.well-known/oauth-protected-resourceand/.well-known/oauth-protected-resource/mcp. The/mcpvariant appends/mcpagain and advertisesresource: "https://mcp.example.com/mcp/mcp".Expected (RFC 9728 §3.1): the metadata URL is the origin plus
/.well-known/oauth-protected-resourceplus the resource path, and the advertisedresourceequalsresourceUriexactly.Repro: configure
resourceUri: 'https://mcp.example.com/mcp', send an unauthenticated request to/mcp, then fetch the URL in theresource_metadataparameter. The fetch returns 404.Found while reviewing #170. Already present on
main.