{"version":3,"file":"oauth-protected-resource.mjs","names":[],"sources":["../../../../../src/astro/routes/api/well-known/oauth-protected-resource.ts"],"sourcesContent":["/**\n * GET /.well-known/oauth-protected-resource\n *\n * RFC 9728 Protected Resource Metadata. Tells MCP clients where to find\n * the authorization server. Injected at the site root (not under /_emdash/)\n * because RFC 9728 requires it at the well-known URI of the resource's origin.\n *\n * Also serves as `/.well-known/oauth-protected-resource/_emdash/api/mcp`\n * (path-scoped variant) when Astro's routing allows.\n *\n * Public, unauthenticated.\n */\n\nimport type { APIRoute } from \"astro\";\n// @ts-ignore - virtual module\nimport virtualConfig from \"virtual:emdash/config\";\n\nimport { getPublicOrigin } from \"#api/public-url.js\";\nimport { builtinPolicies } from \"@premium-cms/auth\";\n\nexport const prerender = false;\n\nexport const GET: APIRoute = async ({ url, locals }) => {\n\t// Anonymous discovery requests omit runtime config; use build-time config\n\t// so `siteUrl` can override the proxy's internal origin (#2016).\n\tconst origin = getPublicOrigin(url, locals.emdash?.config ?? virtualConfig);\n\n\treturn Response.json(\n\t\t{\n\t\t\tresource: `${origin}/_emdash/api/mcp`,\n\t\t\tauthorization_servers: [`${origin}/_emdash`],\n\t\t\t// OAuth scopes are policy slugs; the built-in ones are always present.\n\t\t\tscopes_supported: builtinPolicies().map((p) => p.slug),\n\t\t\tbearer_methods_supported: [\"header\"],\n\t\t},\n\t\t{\n\t\t\theaders: {\n\t\t\t\t\"Cache-Control\": \"public, max-age=3600\",\n\t\t\t\t\"Access-Control-Allow-Origin\": \"*\",\n\t\t\t},\n\t\t},\n\t);\n};\n"],"mappings":";;;;;AAoBA,MAAa,YAAY;AAEzB,MAAa,MAAgB,OAAO,EAAE,KAAK,aAAa;CAGvD,MAAM,SAAS,gBAAgB,KAAK,OAAO,QAAQ,UAAU,cAAc;AAE3E,QAAO,SAAS,KACf;EACC,UAAU,GAAG,OAAO;EACpB,uBAAuB,CAAC,GAAG,OAAO,UAAU;EAE5C,kBAAkB,iBAAiB,CAAC,KAAK,MAAM,EAAE,KAAK;EACtD,0BAA0B,CAAC,SAAS;EACpC,EACD,EACC,SAAS;EACR,iBAAiB;EACjB,+BAA+B;EAC/B,EACD,CACD"}