c6a057073b
/mcp reauth read OAuth clientId/clientSecret from the raw, unexpanded config
while URL and resource used expandEnvVarsDeep, so `${VAR}` placeholders were
sent literally to the token exchange. MCPOAuthFlow.exchangeToken() also accepted
any HTTP-success body, storing an empty access token when a provider signals
failure with HTTP 200 (e.g. Slack `{ ok: false, error }`), surfacing only later
as invalid_token.
- Select flow client credentials from runtimeBaseConfig / expanded auth block;
keep the raw placeholder for the persisted config file.
- Reject token responses without a non-empty access_token, including the
sanitized provider error when present.
- Add regression tests for env-expanded reauth credentials and HTTP-200 token
error bodies.
Fixes #7440