Topic 1: Module 7 at a glance
By the end of this module, you'll have:
- A notes server that runs over streamable HTTP as a real OAuth 2.1 resource server: it answers
401with a pointer to its discovery document, verifies every bearer token, and refuses tokens minted for any other server. notes_assistant/auth.py(theJWTTokenVerifier,mint_dev_token, andauth_from_env) and the finalnotes_assistant/server.py, with a scope check that keepscreate_notebehindnotes:write.- A working understanding of the whole authorization code flow: protected resource metadata, authorization server discovery, PKCE with
S256, resource indicators, and theisscheck, backed by a script that computes the PKCE values for real. - The ability to choose between Client ID Metadata Documents, pre-registration, and the now deprecated dynamic client registration, and to write a client metadata document.
- A least-privilege scope design for the notes tools, a client that works out which scopes to ask for from a
WWW-Authenticatechallenge, and a concrete demonstration of why token passthrough is forbidden. - A path to production: swapping the development HS256 key for a provider's RS256 keys fetched from its JWKS endpoint, plus an overview of enterprise identity provider integration with ID-JAG.
Prerequisites: Modules 1 to 6. You need the server from Module 5 (build_server, main, the environment settings in config.py) and the HTTP client skills from Module 6 (Client, streamable_http_client, httpx2). You should know what an HTTP header is and have seen a JWT before, even if only in a debugger. No OAuth experience is assumed.
Where we are: Module 6 gave Nare a host that talks to the notes server over stdio or HTTP. Over stdio that is fine: the server runs as her own process. Over HTTP, though, anyone who can reach the port can read her lab notes and write new ones. Priya and Tomas want to use the server from their laptops, so in this module we lock the HTTP door properly.