Files
oh-my-pi/packages/coding-agent/test
roboomp dbff881fba fix(mcp/oauth): apply self-referential resource filter on refresh too
When the initial grant strips a self-referential resource (per the previous
commit), the credential is stored with `resource: undefined`. On the next
refresh, `MCPManager.prepareConfig` (`packages/coding-agent/src/mcp/manager.ts:1232-1233`)
falls back from `material?.resource` to `config.url` and pipes it into
`refreshMCPOAuthToken` — re-introducing the same self-referential value that
broke the initial authorize against strict servers like Plane. RFC 8707 §2.2
also requires the token-request indicator to match the authorize indicator,
so dropping in one mandates dropping in the other.

- Hoisted `filterSelfReferentialResource(resource, serverUrl)` to module scope so the class-method form and the free `refreshMCPOAuthToken` share the rule. `MCPOAuthFlow.#filterResourceIndicator` is now a thin delegate.
- `refreshMCPOAuthToken` now passes the resource through the same filter, using `tokenUrl` as the origin yardstick (RFC 8414 puts authorize and token endpoints on the same issuer, and MCP discovery follows that contract).
- Added 3-test `RFC 8707 resource indicator (refresh)` suite covering: resource equals token-server origin (stripped), origin with trailing slash (stripped), and a path-bearing resource (preserved).

Fixes #3502
2026-06-25 20:54:16 +00:00
..
2026-06-23 10:41:59 +00:00
2026-06-23 08:18:29 +02:00
2026-06-25 11:41:56 +00:00
2026-06-11 21:03:49 +02:00
2026-05-30 18:08:51 +02:00
2026-05-30 18:08:51 +02:00
2026-06-12 11:24:26 +02:00
2026-05-30 18:08:51 +02:00
2026-06-24 13:44:47 +00:00