Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -83,4 +83,33 @@ public function testEmptyAuthorizationServersThrows(): void

new ProtectedResourceMetadata([]);
}

#[TestDox('the SDK advertises exactly the scopes it was given, and never adds offline_access')]

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not changing this — the test's input has no whitespace/empties/duplicates, so normalize() is a no-op here; the TestDox describes this test's specific SEP-2207 guard, not a general preservation guarantee.

public function testScopesAreOperatorSuppliedOnly(): void
{
// SEP-2207: `offline_access` is a refresh-token scope, not something a
// resource requires. Nothing in the SDK injects it — this pins that, so
// a future default cannot quietly start advertising one.
$metadata = new ProtectedResourceMetadata(
resource: 'https://api.example.com/mcp',
authorizationServers: ['https://auth.example.com'],
scopesSupported: ['mcp:read', 'mcp:write'],
);

$data = $metadata->jsonSerialize();

$this->assertSame(['mcp:read', 'mcp:write'], $data['scopes_supported']);
$this->assertNotContains('offline_access', $data['scopes_supported']);
Comment on lines +99 to +102

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not adding assertArrayHasKey here — line 101 already dereferences the same key and would fail first with a clear message if it were missing; jsonSerialize() also guarantees the key is set whenever scopesSupported is non-null.

}

#[TestDox('no scopes given means no scopes_supported member at all')]
public function testNoScopesMeansNoMember(): void
{
$metadata = new ProtectedResourceMetadata(
resource: 'https://api.example.com/mcp',
authorizationServers: ['https://auth.example.com'],
);

$this->assertArrayNotHasKey('scopes_supported', $metadata->jsonSerialize());
}
}