MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / finishAuthorized

Function finishAuthorized

apps/cloud/src/mcp/auth-provider.ts:170–240  ·  view source on GitHub ↗
(request: Request, token: VerifiedToken)

Source from the content-addressed store, hash-verified

168 * and 403s carry the client fingerprint.
169 */
170 const finishAuthorized = (request: Request, token: VerifiedToken): Effect.Effect<AuthOutcome> =>
171 Effect.gen(function* () {
172 // OLD `mcpApp` annotated with parseBody = (POST && isAuthorized) BEFORE
173 // org-authz, so a verified-but-no/revoked-org POST still captured
174 // mcp.rpc.method/id. The body is read via `request.clone().text()`
175 // (annotateMcpRequest -> readJsonRpcEnvelope), so it never consumes the
176 // original stream a downstream dispatch reads — safe on every path,
177 // including the Forbidden short-circuit. Keep parseBody keyed on POST,
178 // not on the org outcome, to preserve that telemetry.
179 const parseBody = request.method === "POST";
180
181 // URL is the source of truth for the active org when pinned — the org's
182 // slug (`/acme/mcp`, what the install card prints) or a legacy org id
183 // (`/org_xxx/mcp`), carried in the header by `prepareMcpOrgScope`; the
184 // bare `/mcp` falls back to the token's `org_id`. Either way
185 // `orgAuth.authorize` resolves the selector and re-checks live WorkOS
186 // membership below, so the URL is a selector, not a trust boundary.
187 const organizationSelector = mcpOrganizationFromRequest(request) ?? token.organizationId;
188 if (!organizationSelector) {
189 yield* annotateMcpRequest(request, { token, parseBody });
190 return forbidden(NO_ORGANIZATION_MESSAGE, -32001);
191 }
192
193 // Capture success-vs-failure explicitly instead of collapsing both into
194 // `null`, then classify the failure (see the classification table on
195 // ORGANIZATION_AUTHORIZE_UNAVAILABLE above): a definitive WorkOS 4xx
196 // denial fails CLOSED as Forbidden, anything else is a transient error
197 // that must become a retryable 503 with the session left intact.
198 const authorizeResult = yield* orgAuth
199 .authorize(token.accountId, organizationSelector)
200 .pipe(
201 Effect.result,
202 Effect.withSpan("mcp.auth.authorize_organization", {
203 attributes: {
204 "mcp.auth.organization_selector": organizationSelector,
205 },
206 }),
207 );
208
209 yield* annotateMcpRequest(request, { token, parseBody });
210
211 if (Result.isFailure(authorizeResult)) {
212 if (isDefinitiveWorkOSDenial(authorizeResult.failure)) {
213 // WorkOS ANSWERED and said no (revoked key, forbidden, deleted
214 // org). Deterministic denial — same as a successful lookup with no
215 // membership, so the Forbidden/condemn path applies.
216 yield* Effect.annotateCurrentSpan({
217 "mcp.auth.outcome": "denied",
218 "mcp.auth.organization_authorize_error": String(authorizeResult.failure).slice(
219 0,
220 500,
221 ),
222 });
223 return forbidden(NO_ORGANIZATION_MESSAGE, -32001);
224 }
225 yield* Effect.annotateCurrentSpan({
226 "mcp.auth.outcome": "system_error",
227 "mcp.auth.system_error.reason": "organization_authorize",

Callers 1

toOutcomeFunction · 0.85

Calls 7

annotateMcpRequestFunction · 0.90
isDefinitiveWorkOSDenialFunction · 0.90
forbiddenFunction · 0.85
unavailableFunction · 0.85
authenticatedFunction · 0.85
principalFromTokenFunction · 0.85

Tested by

no test coverage detected