Fetching from the wire…
Infra2026-09-03 · source-backed
PR #3398 makes the OAuth client fix its expected issuer before fetching any authorization server metadata. On the 2025-03-26 legacy fallback path the document's issuer was never checked and stored-credential binding was re-evaluated against whatever issuer the document named, against RFC 8414 §3.3. Discovery now computes the expected issuer once, validates unconditionally, and stops rather than falling through to the legacy path when a resource-metadata location returns 5xx or 429, so a transient failure cannot walk a bound client onto the weaker path.
Each link below shares sources, entities, or timing with this story.
PR #29081, merged August 26 and in nightly v0.59.0-nightly.20260827, enforces RFC 9728 §7.7 and RFC 8414 constraints across MCP OAuth metadata discovery, dynamic client registration, and token exchange. It requires HTTPS for remote endpoints with HTTP allowed only for loopback...
Duende's breakdown of six authorization-hardening SEPs: SEP-2468 requires the iss parameter per RFC 9207, defending against mixup attacks where a client talks to multiple authorization servers and one is attacker-controlled. SEP-837 has AS operators validate redirect URIs via...
AWS's August 21 post stages agent tool governance as Connect, Control, Catalog and Harden, from one SSO-backed MCP endpoint for a 1-20 user pilot through identity-aware authorization with PII redaction and self-service tool publishing at 100+ users. It supports Cognito-backed...
A Chinese lab shipped a runtime that manages two American coding agents as subagents, and it went from repo creation to 145,439 stars in four days. deepseek-ai/deepseek-harness published dsh-v0.1.0-rc.7 at 12:01 UTC today, its first tagged release since the repo appeared on Au...
holaboss-ai/holaOS puts Claude Code, Codex and its own agent in one Electron workspace where context and history live as editable local files rather than a hosted database, so memory persists across sessions *and* across agents. Built-in frontier models (Kimi K3, GLM 5.2, GPT...
The failure that forced it: teams independently implemented auth, some with none, some API keys, some full OAuth, leaving no consistent way to authorize callers, audit actions, or offboard a departing employee (arXiv 2608.10760). The architecture crosses persona (interactive u...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.