| @@ -322,9 +322,15 @@ | ||
| 322 | 322 | * @param \WP_REST_Response $resp Response. |
| 323 | 323 | * @return \WP_REST_Response |
| 324 | 324 | */ |
| 325 | 325 | protected function with_challenge( $resp ) { |
| 326 | - $metadata_url = home_url( '/.well-known/oauth-protected-resource' ); | |
| 326 | + // Our own REST namespace, not `/.well-known/`: that path is shared by the | |
| 327 | + // whole site, so a plugin hooking `parse_request` earlier than us -- or a | |
| 328 | + // host that serves `/.well-known/` itself for ACME -- would hand our | |
| 329 | + // clients another resource's metadata, and RFC 9728 requires an exact | |
| 330 | + // match. This route is ours alone. The well-known paths keep working for | |
| 331 | + // clients that construct them directly. | |
| 332 | + $metadata_url = rest_url( 'notificationx/v1/mcp/oauth/protected-resource' ); | |
| 327 | 333 | $resp->header( 'WWW-Authenticate', sprintf( 'Bearer resource_metadata="%s"', $metadata_url ) ); |
| 328 | 334 | return $resp; |
| 329 | 335 | } |
| 330 | 336 | |