Documentation
¶
Overview ¶
Package main implements the MCP gateway service.
Request filter pipeline ¶
Every inbound request is processed through a fixed ordered pipeline of five stages before audit/analytics finalization runs unconditionally as stage 6. Stage order is security-sensitive and is fixed in code:
Stage 1 – InspectFilter: bounded body capture; RPC method and tool name extraction Stage 2 – PolicyFilter: atomic policy snapshot acquisition; OAuth metadata early-exit Stage 3 – AuthFilter: optional OAuth and adapter-certificate authentication Stage 4 – AuthzFilter: authorization and session/grant evaluation Stage 5 – UpstreamFilter: credential cleanup; path rewrite; upstream proxy Stage 6 – (orchestrator): audit/analytics finalization
Ordering guarantees:
- Authentication (stage 3) always completes before authorization (stage 4).
- The policy snapshot (stage 2) is captured once and held immutable for the entire exchange lifetime; no later stage may re-acquire it.
- Authorization inputs (Policy and Identity on Exchange) must not be mutated after the authz stage sets Decision; upstream preparation (stage 5) only reads them.
Each filter returns Continue, Reject, or Respond. On any non-Continue result the pipeline halts and stage 6 runs from the orchestrator.
Click to show internal directories.
Click to hide internal directories.