pomerium/internal
Denis Mishin f5c5326c72
mcp: respond with jsonrpc error when MCP request is denied (#5694)
## Summary

Individual MCP method calls may be denied (i.e. via `mcp_tool`
criterion) and Pomerium has to respond with MCP protocol error, which is
JSON-RPC error message, rather then with HTTP level error which seems to
break some MCP clients.


## Related issues

Fix
https://linear.app/pomerium/issue/ENG-2521/pomerium-does-not-return-an-mcp-error-when-a-tool-call-is-unauthorized

## User Explanation

<!-- How would you explain this change to the user? If this
change doesn't create any user-facing changes, you can leave
this blank. If filled out, add the `docs` label -->

## Checklist

- [x] reference any related issues
- [x] updated unit tests
- [x] add appropriate label (`enhancement`, `bug`, `breaking`,
`dependencies`, `ci`)
- [x] ready for review
2025-07-08 09:07:26 -06:00
..
atomicutil upgrade to go v1.24 (#5562) 2025-04-02 15:53:09 -06:00
authenticateflow ssh: implement authorization policy evaluation (#5665) 2025-07-01 12:04:00 -07:00
autocert chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
benchmarks upgrade to go v1.24 (#5562) 2025-04-02 15:53:09 -06:00
chanutil fileutil: update watcher to use fsnotify and polling (#3663) 2022-10-19 09:13:08 -06:00
contextkeys
controlplane chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
databroker chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
deterministicecdsa core/ci: update linting (#4844) 2023-12-14 09:07:54 -08:00
enabler chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
encoding core/lint: upgrade golangci-lint, replace interface{} with any (#5099) 2024-05-02 14:33:52 -06:00
errgrouputil core/go: use max procs (#4766) 2023-12-07 09:14:57 -07:00
events chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
fileutil remove debug log message for directories (#5560) 2025-04-02 10:17:42 -06:00
handlers Add an 'issuer' field to the /.well-known/pomerium endpoint (#5344) 2024-10-25 13:07:57 -04:00
hashutil replace xxhash with xxh3 (#5457) 2025-01-31 08:44:08 -07:00
headertemplate add support for pomerium.request.headers for set_request_headers (#5563) 2025-04-07 10:32:03 -06:00
httputil chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
jsonrpc mcp: respond with jsonrpc error when MCP request is denied (#5694) 2025-07-08 09:07:26 -06:00
jwtutil authorize: support authenticating with idp tokens (#5484) 2025-02-18 13:02:06 -07:00
log authorize: add request body logging (#5696) 2025-07-07 12:12:29 -04:00
mcp mcp: split mcp into server and client for better option grouping (#5666) 2025-06-24 10:21:32 -07:00
middleware New tracing system (#5388) 2025-01-21 13:26:32 -05:00
oauth21 mcp: client registration/token fixes (#5649) 2025-06-11 11:28:24 -04:00
registry upgrade to go v1.24 (#5562) 2025-04-02 15:53:09 -06:00
retry chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
rfc7591 mcp: client registration/token fixes (#5649) 2025-06-11 11:28:24 -04:00
scheduler
sessions chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
sets core/go: use hashicorp/go-set (#5278) 2024-10-03 12:59:11 -06:00
signal
syncutil config: generate cookie secret if not set in all-in-one mode (#3742) 2022-11-11 14:14:30 -07:00
telemetry chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00
testenv ssh: add runtime flag for jump host mode (#5699) 2025-07-07 12:29:05 -04:00
tests/xdserr Fix many instances of contexts and loggers not being propagated (#5340) 2024-10-25 14:50:56 -04:00
testutil ssh: implement authorization policy evaluation (#5665) 2025-07-01 12:04:00 -07:00
tripper config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
urlutil multi-domain login redirects (#5564) 2025-04-04 13:14:30 -07:00
version ci: do not include timestamp into buildmeta (#5215) 2024-08-15 10:57:10 -04:00
zero chore(deps): bump the go group with 24 updates (#5638) 2025-06-17 09:36:50 -07:00