#!/usr/bin/env bash ############################################################################### # KISC MCPF - Validate .well-known Endpoints # # Tests all MCPF endpoints are accessible and return valid JSON # # Usage: ./validate-endpoints.sh [domain] # Default domain: localhost (for local testing) # Production: ./validate-endpoints.sh llm.kis.gov.lv ############################################################################### set -euo pipefail DOMAIN="${1:-localhost}" BASE_URL="https://$DOMAIN" # Use -k for localhost self-signed certs CURL_OPTS="-sS --connect-timeout 5 --max-time 10" if [[ "$DOMAIN" == "localhost" ]]; then CURL_OPTS="$CURL_OPTS -k" fi # Colors GREEN='\033[0;32m' RED='\033[0;31m' YELLOW='\033[1;33m' NC='\033[0m' PASSED=0 FAILED=0 echo "============================================" echo "MCPF Endpoint Validation" echo "============================================" echo "Target: $BASE_URL" echo "" test_endpoint() { local path=$1 local name=$2 local required_field=$3 echo -n "Testing $name... " local url="$BASE_URL$path" local response response=$(curl $CURL_OPTS "$url" 2>/dev/null || echo "") if [[ -z "$response" ]]; then echo -e "${RED}❌ FAIL${NC} (No response)" echo " URL: $url" ((FAILED++)) return 1 fi # Check if valid JSON if ! echo "$response" | jq empty 2>/dev/null; then echo -e "${RED}❌ FAIL${NC} (Invalid JSON)" echo " URL: $url" echo " Response: ${response:0:100}..." ((FAILED++)) return 1 fi # Check for required field if [[ -n "$required_field" ]]; then if ! echo "$response" | jq -e "$required_field" >/dev/null 2>&1; then echo -e "${YELLOW}⚠️ WARN${NC} (Missing field: $required_field)" echo " URL: $url" fi fi echo -e "${GREEN}✅ PASS${NC}" echo " URL: $url" ((PASSED++)) } # ============================================================================= # Test Suite # ============================================================================= # Test 1: DID Document test_endpoint "/.well-known/did.json" "DID Document" ".id" # Test 2: JWKS test_endpoint "/.well-known/jwks.json" "JWKS" ".keys" # Test 3: MCPF Registry Discovery test_endpoint "/.well-known/mcp-trust-registry.json" "MCPF Registry Discovery" ".mcpfVersion" # Test 4: Security.txt echo -n "Testing Security.txt... " response=$(curl $CURL_OPTS "$BASE_URL/.well-known/security.txt" 2>/dev/null || echo "") if echo "$response" | grep -q "Contact:"; then echo -e "${GREEN}✅ PASS${NC}" echo " URL: $BASE_URL/.well-known/security.txt" ((PASSED++)) else echo -e "${RED}❌ FAIL${NC}" ((FAILED++)) fi # Test 5: MCP Manifest test_endpoint "/.well-known/mcp/manifest.json" "MCP Manifest" ".capabilities" # Test 6: MCP Credential test_endpoint "/.well-known/credentials/mcp-server.json" "MCP Credential" ".credentialSubject" # ============================================================================= # Results # ============================================================================= echo "" echo "============================================" echo "Results" echo "============================================" echo "Passed: $PASSED" echo "Failed: $FAILED" echo "" if [[ $FAILED -eq 0 ]]; then echo -e "${GREEN}✅ All tests passed!${NC}" echo "" echo "MCPF integration is working correctly." echo "Next steps:" echo " 1. Submit to VeriTrust for credential issuance" echo " 2. Replace placeholder credential in /.well-known/credentials/mcp-server.json" echo " 3. Test with AI agents (Claude Desktop, ChatGPT, etc.)" exit 0 else echo -e "${RED}❌ Some tests failed${NC}" echo "" echo "Troubleshooting:" echo " 1. Check nginx is serving .well-known directory" echo " 2. Verify .well-known files exist in /opt/kisc-llm/poc/deploy/.well-known/" echo " 3. Check nginx logs: docker logs kisc-nginx" echo " 4. Verify TLS certificates are valid" exit 1 fi