mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
docs(mcp): name both verifying key settings
This commit is contained in:
2 files changed
+4
-3
No files matched your search
@@ -105,7 +105,7 @@ Deploy your own remote MCP server:
|
||||
|
||||
- Full control over deployment
|
||||
- Requires Python 3.12+ or Docker
|
||||
- Set `DJANGO_TOKEN_VERIFYING_KEY` to the Prowler API's JWT public key (PEM, `\n`-escaped newlines allowed) so the server verifies the signature of user tokens before forwarding them; without it only their expiration is checked
|
||||
- Set `DJANGO_TOKEN_VERIFYING_KEY` to the Prowler API's JWT public key (PEM, `\n`-escaped newlines allowed), or `DJANGO_TOKEN_VERIFYING_KEY_FILE` to a file holding it, so the server verifies the signature of user tokens before forwarding them; with neither set only their expiration is checked
|
||||
|
||||
See the [Installation Guide](https://docs.prowler.com/getting-started/installation/prowler-mcp) for complete instructions.
|
||||
|
||||
|
||||
@@ -57,8 +57,9 @@ class ProwlerAppAuth:
|
||||
raise ValueError("Prowler API key format is incorrect")
|
||||
elif mode == "http" and not self.jwt_verifying_key:
|
||||
logger.warning(
|
||||
"DJANGO_TOKEN_VERIFYING_KEY is not set: JWT signatures will not be "
|
||||
"verified by the MCP server, only their expiration"
|
||||
f"Neither DJANGO_TOKEN_VERIFYING_KEY nor {VERIFYING_KEY_FILE_ENV} is "
|
||||
"set: JWT signatures will not be verified by the MCP server, only "
|
||||
"their expiration"
|
||||
)
|
||||
|
||||
def _parse_jwt(self, token: str) -> dict | None:
|
||||
|
||||
Reference in new issue
Block a user