Files
oh-my-pi/packages/coding-agent/test
roboomp f7fa80e00e fix(mcp/oauth): strip same-origin path resource indicators too
Plane also rejects `resource=https://mcp.plane.so/http/mcp`, not only the bare
origin forms. That means the MCP OAuth resource filter must treat any resource
URL on the authorization-server origin as redundant for these MCP servers, not
just exact origin/origin-slash values.

- Broadened the filter to compare `new URL(resource).origin` with the persisted authorization-server origin.
- Updated grant and refresh RFC 8707 tests: same-origin path resources such as `/http/mcp` are now stripped from authorize, token exchange, and refresh; cross-origin resources remain preserved.
- Updated docs/changelog wording from exact self-referential origin to same-origin resource indicators.

Verified live against `https://mcp.plane.so/authorize`: patched `MCPOAuthFlow` with `resource=https://mcp.plane.so/http/mcp` generates no `resource` parameter and Plane redirects to `/consent?txn_id=…`.

Fixes #3502
2026-06-25 21:36:32 +00:00
..
2026-06-23 10:41:59 +00:00
2026-06-23 08:18:29 +02:00
2026-06-25 11:41:56 +00:00
2026-06-11 21:03:49 +02:00
2026-05-30 18:08:51 +02:00
2026-05-30 18:08:51 +02:00
2026-06-12 11:24:26 +02:00
2026-05-30 18:08:51 +02:00
2026-06-24 13:44:47 +00:00