AuthMiddleware.install(ctx, config, source) now owns the annotation processor and the flash.auth.policy key, so a second credential source gets annotation-driven authorization without copying the wiring. The key is public: an extension that contributes middleware can order itself around authentication. OidcSession becomes Session in auth-core, carrying claims, an expiry and an opaque attribute map. OpenID Connect keeps its access, id and refresh tokens in that map under its own keys, so renewal stays its business and core has no OAuth2 vocabulary in it. isAccessTokenExpired() becomes isExpired(), with the 30s eager-renewal window it always had and now a test for it. flash-ext-oidc is renamed flash-ext-auth-oidc, matching cache-core/cache-caffeine and data-core/data-hibernate.
flash-ext-mcp
flash-ext-mcp turns a Flash5 app into an MCP (Model Context
Protocol) server: JSON-RPC 2.0 over the Streamable HTTP transport, tools/resources/prompts
declared as plain classes and discovered at boot, optional OAuth2 protection built on
flash-ext-auth-oidc.
Quick Start
FlashApp.create(8080)
.install(new McpExtension(McpConfig.builder("my-mcp-server")
.toolsPackage("com.example.tools")
.build()))
.start();
@Tool(name = "get_weather", description = "Get current weather for a city",
args = @ToolArg(name = "city", description = "City name", required = true))
public class GetWeatherTool extends McpTool {
private WeatherService weatherService;
@Override
protected void onInit() {
weatherService = require(WeatherService.class);
}
@Override
public ToolResponse call(ToolArguments args) {
return ToolResponse.success(new TextContent(weatherService.fetch(args.getString("city"))));
}
}
Operating Model
- One class per tool/resource/prompt — mirrors
RequestHandler: a no-arg constructor,onInit()to cache services fromFlashContext, one hot-path method (call/read/render). No CDI, no field injection, no reflection on the hot path. - Boot-time precompilation —
tools/list/resources/list/prompts/listJSON payloads (including JSON Schema) are built once at boot and spliced verbatim into responses. Seetools-resources-prompts.md. - Transport: Streamable HTTP,
POST-only, stateless in this revision — seetransport.mdfor exactly what that means and why. - Security: optional, policy-driven OAuth2 via
flash-ext-auth-oidc— seesecurity.md. - JSON: this extension owns its JSON handling independently of
flash-ext-jackson— seejackson-interop.mdfor why, and how a future opt-in reuse could work.
Documents
tools-resources-prompts.md— defining tools, resources, promptstransport.md— Streamable HTTP scope, session/SSE limitations, Origin validationsecurity.md—McpSecuritypolicy, OAuth2 resolution, RFC 9728 / RFC 8707keycloak.md— Keycloak-specific setup cookbook: Dynamic Client Registration, the RFC 8707 audience mapper gotcha, and how to verify/debug itjackson-interop.md— why this extension does not depend onflash-ext-jackson