Azure client secrets lapse silently into opaque 401s (AADSTS7000222). Add a self-reported expiry date (SP_SECRET_EXPIRES=YYYY-MM-DD) and a shared secretExpiryStatus() helper in graph.mjs; surface warnings <30 days out via the CLI (stderr on every command + test output), MCP server startup log, /health, and the sharepoint_test tool. Documented in both .env.examples, setup.md, and READMEs. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
24 lines
1.1 KiB
Plaintext
24 lines
1.1 KiB
Plaintext
# Copy to ".env" in this folder and fill in. Git-ignored — never commit real values.
|
|
SP_TENANT_ID=00000000-0000-0000-0000-000000000000
|
|
SP_CLIENT_ID=00000000-0000-0000-0000-000000000000
|
|
SP_CLIENT_SECRET=your-client-secret-value-here
|
|
|
|
# When the client secret expires (shown in Entra > Certificates & secrets).
|
|
# Optional but recommended: the server warns at startup, in /health, and in the
|
|
# sharepoint_test tool when <30 days remain — instead of a surprise 401 later.
|
|
# SP_SECRET_EXPIRES=2027-01-01
|
|
|
|
# Optional: default site so tools can omit the `site` argument.
|
|
# SP_SITE_URL=https://contoso.sharepoint.com/sites/Marketing
|
|
|
|
# Optional safety: set to true to expose ONLY read tools (no create/update/delete).
|
|
# SP_READONLY=false
|
|
|
|
# --- HTTP transport (only when running with --http, e.g. in Docker) ---
|
|
# Shared bearer token required on the /mcp endpoint. Generate a strong random
|
|
# value, e.g. openssl rand -hex 32
|
|
# If left empty, the HTTP endpoint is UNAUTHENTICATED — don't do that off-LAN.
|
|
# MCP_AUTH_TOKEN=
|
|
# Port the HTTP server listens on (default 3838).
|
|
# PORT=3838
|