From 0edc786207089a1bc272f299e129fd5259e81939 Mon Sep 17 00:00:00 2001 From: pedrooot Date: Thu, 8 Oct 2026 00:34:15 +0200 Subject: [PATCH] docs(mcp): name both verifying key settings --- mcp_server/README.md | 2 +- mcp_server/prowler_mcp_server/prowler_app/utils/auth.py | 5 +++-- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/mcp_server/README.md b/mcp_server/README.md index 11f5901dfe..063a5b8c48 100644 --- a/mcp_server/README.md +++ b/mcp_server/README.md @@ -105,7 +105,7 @@ Deploy your own remote MCP server: - Full control over deployment - Requires Python 3.12+ or Docker -- Set `DJANGO_TOKEN_VERIFYING_KEY` to the Prowler API's JWT public key (PEM, `\n`-escaped newlines allowed) so the server verifies the signature of user tokens before forwarding them; without it only their expiration is checked +- Set `DJANGO_TOKEN_VERIFYING_KEY` to the Prowler API's JWT public key (PEM, `\n`-escaped newlines allowed), or `DJANGO_TOKEN_VERIFYING_KEY_FILE` to a file holding it, so the server verifies the signature of user tokens before forwarding them; with neither set only their expiration is checked See the [Installation Guide](https://docs.prowler.com/getting-started/installation/prowler-mcp) for complete instructions. diff --git a/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py b/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py index fb01970de8..1ebb738447 100644 --- a/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py +++ b/mcp_server/prowler_mcp_server/prowler_app/utils/auth.py @@ -57,8 +57,9 @@ class ProwlerAppAuth: raise ValueError("Prowler API key format is incorrect") elif mode == "http" and not self.jwt_verifying_key: logger.warning( - "DJANGO_TOKEN_VERIFYING_KEY is not set: JWT signatures will not be " - "verified by the MCP server, only their expiration" + f"Neither DJANGO_TOKEN_VERIFYING_KEY nor {VERIFYING_KEY_FILE_ENV} is " + "set: JWT signatures will not be verified by the MCP server, only " + "their expiration" ) def _parse_jwt(self, token: str) -> dict | None: