fix(mcp): blocked reauth after failed client registration

Surfaced rejected dynamic client registration from generateAuthUrl before probing or returning an authorization URL without client_id.

Added coverage for a Cropwise-style 403 unapproved_client response.

Fixes #5852
This commit is contained in:
roboomp
2026-07-17 14:39:15 +00:00
parent 0f9fceeea4
commit 33f2f00d58
3 changed files with 25 additions and 18 deletions
@@ -385,6 +385,9 @@ export class MCPOAuthFlow extends OAuthCallbackFlow {
async generateAuthUrl(state: string, redirectUri: string): Promise<{ url: string; instructions?: string }> {
if (!this.#resolvedClientId) {
await this.#tryRegisterClient(redirectUri);
if (!this.#resolvedClientId && this.#registrationFailure) {
throw this.#missingClientIdError();
}
}
const authUrl = new URL(this.config.authorizationUrl);