1: <?php
2:
3: declare(strict_types=1);
4:
5: /**
6: * This file is part of the Nexus MCP SDK package.
7: *
8: * (c) 2026 John Paul E. Balandan, CPA <paulbalandan@gmail.com>
9: *
10: * For the full copyright and license information, please view
11: * the LICENSE file that was distributed with this source code.
12: */
13:
14: namespace Nexus\Mcp\Client\Exception;
15:
16: use Nexus\Mcp\Core\Exception\McpExceptionInterface;
17:
18: /**
19: * Thrown when a metadata document names a subject other than the one whose URL served it, which is how a
20: * hostile server tries to redirect a client to an authorization server it controls.
21: *
22: * @see https://datatracker.ietf.org/doc/html/rfc8414#section-3.3
23: */
24: final class UntrustedAuthorizationMetadataException extends \RuntimeException implements McpExceptionInterface
25: {
26: public function __construct(string $reason, ?\Throwable $previous = null)
27: {
28: parent::__construct(
29: \sprintf('The authorization metadata cannot be trusted because %s', $reason),
30: previous: $previous,
31: );
32: }
33: }
34: