Commit Graph
7 Commits
Author SHA1 Message Date
can1357 3e90576228 test(coding-agent): updated mcp profile auth binding tests
- Added AbortSignal expectation to auth binding test assertions.
2026-07-11 00:13:49 +02:00
can1357 963dd0eb69 test: align MCP OAuth refresh assertions with options-object signature
refreshMCPOAuthToken now takes a trailing { authorizationUrl, stripSameOriginResource } options object (issue #3502 follow-up). Update the two stale per-profile binding assertions to expect it, and assert the fallback resource is not persisted (resource: undefined) since it is re-derived from config.url on each refresh.
2026-06-26 07:39:02 +02:00
can1357 9ffaace8bc test(coding-agent): prevented sqlite database handle leaks in tests
- Track and explicitly close in-memory SQLite database handles in MCP auth tests.
- Resolved Bun GC-related crashes occurring when parallel tests finalize dangling database handles.
2026-06-25 20:59:38 +02:00
can1357 3f82589ec1 fix: fixed OAuth and profile-boundary regressions across CLI and env handling
- Fixed OAuth credentials to keep unknown fields in schema while preserving existing shape checks.
- Fixed MCP OAuth IDs to be profile-scoped and avoid deleting credentials from non-active profiles.
- Fixed string-flag parsing so PROFILE_BOOTSTRAP_BOUNDARY tokens are not consumed as values.
- Fixed active-profile directory resolution to refresh after env updates so profile .env overrides apply.
2026-06-15 03:20:45 +02:00
Ogrodev f9bc96e96c fix(coding-agent): harden profile auth shipping gaps 2026-06-14 20:30:50 -03:00
Ogrodev ef3ae501fb Merge upstream/main into feat/profiles-and-alias 2026-06-11 13:07:52 -03:00
Ogrodev 2f60eaf938 feat(coding-agent): bind MCP OAuth credentials per profile via url-keyed ids
Store MCP OAuth credentials under deterministic mcp_oauth:<url> ids in each
profile's agent.db with refresh material embedded, so a definition-only entry
in a shared project mcp.json resolves each profile's own credential instead
of profiles clobbering each other's auth.credentialId pointer.

- Refresh material is single-source: embedded credential fields win over the
  config auth block (which may belong to another profile); legacy rows fall
  back to the auth block wholesale
- Wire the 401 refresh hook off the resolvable credential, not the auth
  block, so definition-only bindings refresh mid-session too
- The url-keyed fallback never overrides a pinned Authorization header
- Send prompt=consent by default (oauth.prompt to override, "" to omit) so
  reauth can switch accounts past an active browser session
- /mcp reauth fails fast on stdio transports (with an mcp-remote ~/.mcp-auth
  hint), probes http/sse without OAuth injection, GCs the superseded legacy
  row only after the flow succeeds, and leaves definition-only entries
  untouched on disk
- DCR-issued client secrets stay embedded in the stored credential and are
  never written into config files; user-supplied secrets survive reauth
2026-06-10 18:40:07 -03:00