Bumps mcp-chassis to v0.3.0, which adds structured audit logging on every auth rejection and returns 503 temporarily_unavailable (not a silent 401) when Dex is unreachable at validation time. Wires slog.SetDefault so those audit lines flow through gitea-mcp's JSON handler. Together with the earlier /healthz jwt-status reporting and startup degradation warning, this closes #6 (Dex-down is now observable and distinct from a bad token) and #9 (auth failures are audit-logged: reason, IP, token type, hashed fingerprint — never the raw token). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Reference in New Issue
Block a user