Files
oh-my-pi/packages/coding-agent/test
roboomp 132531ee47 fix(mcp/oauth): preserve advertised origin resource indicators
Review on PR #3503 caught the last provenance edge case: some servers can
explicitly advertise an origin-only resource equal to the authorization-server
origin. That value is still authoritative provider metadata and must be sent;
only OMP-synthesized fallback resources should be stripped.

- `filterResourceIndicator` now strips same-origin values only when `stripSameOriginResource` is set. Provider-advertised `oauth.resource` and authorization-URL `?resource=` values preserve both origin-only and path-scoped forms.
- Updated grant tests to preserve advertised origin resources, trailing-slash origin resources, and URL-embedded origin resources while still stripping fallback origin/path resources for Plane.
- Updated refresh tests to preserve advertised origin resources and strip only fallback origin/path resources.
- Updated changelog wording to describe fallback-only stripping.

Fixes #3502
2026-06-25 22:04:49 +00:00
..
2026-06-23 10:41:59 +00:00
2026-06-23 08:18:29 +02:00
2026-06-25 11:41:56 +00:00
2026-06-11 21:03:49 +02:00
2026-05-30 18:08:51 +02:00
2026-05-30 18:08:51 +02:00
2026-06-12 11:24:26 +02:00
2026-05-30 18:08:51 +02:00
2026-06-24 13:44:47 +00:00