I’m trying to enable the Form Builder MCP server in Orbeon Forms 2025.1.2 PE (build 202606221236), running on Tomcat behind Apache with header-based authentication.
I have configured:
<property as="xs:boolean" name="oxf.fb.mcp.enable" value="true"/>However, an MCP initialize POST to /forms/fr/mcp/builder, with an Authorization: Bearer header, returns HTTP 403 with an empty body.
Apache exempts this endpoint from our login redirect and permits my workstation’s IP. The logs confirm the request reaches Orbeon, which logs:
PageFlowControllerProcessor - HTTP status code 403 {The MCP route in the bundled apps/fr/page-flow.xml is:
<serviceCould the absence of public-methods="POST DELETE" cause the page-flow controller to reject external requests before the MCP handler validates the bearer token?
Is this expected behavior requiring additional authorization configuration, or should the bundled route include that attribute? Is there anything else needed for MCP when using header-based authentication behind a reverse proxy?
Thanks!
Aaron Spike
--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to orbeon+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/orbeon/092c57fd-7a90-453b-9859-07f96c467b21n%40googlegroups.com.
Thanks for the suggestions. I tried each in turn and the MCP only started working after setting the service-public-methods property. Is the global service-public-methods property the recommended configuration for enabling MCP? Does allowing these methods globally have any security or behavioral implications I should consider? Or perhaps this is just a test?
Additionally after the MCP stopped returning 403, I tried form_new for a blank form returned a session ID, but list_available_toolbox_form_controls returned {"controls":[]}. Calling form_get_structure with the same session ID then failed with java.util.NoSuchElementException: None.get. I closed the session without saving.
This test did not involve importing an existing form. Form Builder works in the browser, and I was previously able to create a form using its browser-based WebMCP tools. Does the behavior above suggest another configuration setting is needed for the standalone MCP server?