1: <?php
2:
3: declare(strict_types=1);
4:
5: /**
6: * This file is part of the Nexus MCP SDK package.
7: *
8: * (c) 2026 John Paul E. Balandan, CPA <paulbalandan@gmail.com>
9: *
10: * For the full copyright and license information, please view
11: * the LICENSE file that was distributed with this source code.
12: */
13:
14: namespace Nexus\Mcp\Client\Exception;
15:
16: use Nexus\Mcp\Core\Exception\McpExceptionInterface;
17:
18: /**
19: * Thrown when an authorization endpoint would be contacted over plain HTTP from a host that is not loopback.
20: *
21: * @see https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/security-considerations#communication-security
22: */
23: final class InsecureAuthorizationEndpointException extends \RuntimeException implements McpExceptionInterface
24: {
25: public function __construct(string $label, string $url)
26: {
27: parent::__construct(\sprintf('The %s must be served over HTTPS or from a loopback host, "%s" given.', $label, $url));
28: }
29: }
30: