All Classes and Interfaces

Classes
Class
Description
Entry point for the MCP endpoint's security chain: behaves like Http401AuthenticationEntryPoint, but additionally advertises the RFC 9728 protected resource metadata on the 401 via a WWW-Authenticate: Bearer resource_metadata="..." challenge.
OAuth 2.0 discovery for the MCP endpoint, active only under the oidcAuth profile — i.e.
Serves the OAuth 2.0 Protected Resource Metadata (RFC 9728) for the MCP endpoint, so MCP clients (Claude, etc.) can discover the OIDC authorization server protecting /s/mcp and run the OAuth 2.1 + PKCE flow on their own.
Keeps the MCP server's advertised tools/list in sync with the "read-only mode" feature setting, cluster-wide and without a restart.
Acknowledges and discards notifications/roots/list_changed before it reaches the MCP servlet.
Stands up an MCP server on the bare MCP Java SDK: a Jackson JsonMapper with XlrMcpJacksonModule, the SDK's Servlet transport, and the McpSyncServer with tool specs from the McpToolset beans, mounted at /s/mcp.
 
Runtime gate: answers 404 while the "MCP server" feature setting is disabled, so the endpoint can be toggled from the UI without a restart.
Bridges McpToolset extensions - whichever plugin contributed them, and however it authored the contribution (a Spring plugin context bean or a Declarative Services component) - out into the running McpSyncServer, live and without restart, by subscribing to PluginExtensionRegistryImpl's add/remove events.
Turns the McpTool-annotated methods on the McpToolset beans into MCP SDK McpServerFeatures.SyncToolSpecifications: discover the tools, derive a JSON input schema from each method's parameters (via the victools generator, recursing into object types so clients can render their fields), bind arguments, invoke, and convert the result.
Jackson 3 module for MCP (de)serialization, registered on the mapper in McpServerConfiguration.