Files
oh-my-pi/packages/coding-agent/test
roboomp ff6e1b6e17 fix(mcp/oauth): skip discovery metadata with mismatched issuer
`discoverOAuthEndpoints` probes `/.well-known/oauth-authorization-server` at
the origin root before path-prefixed candidates and returns on the first hit.
Plane hosts a root issuer (`https://mcp.plane.so/`) at origin root and a
separate path-scoped issuer (`https://mcp.plane.so/http`) at the path-prefixed
well-known. The `/http/mcp` endpoint advertises only the path-scoped issuer
through protected-resource metadata, so discovery should follow that issuer's
metadata — instead it accepted the wrong origin-root document and routed the
grant to `https://mcp.plane.so/authorize`, which rejects every request with
`server_error=An unexpected error occurred` before the consent screen.

RFC 8414 §3.3 requires the metadata's `issuer` to equal the URL the client
used to construct the metadata URL. Validate it in the discovery loop: when
the queried well-known is the official authorization-server or OpenID Connect
document, skip metadata whose `issuer` doesn't match (after trailing-slash
normalization). Documents without an `issuer` field keep the existing
permissive behavior so legacy/nonstandard servers continue to work.

Verified live against `https://mcp.plane.so/http/authorize` with the same
client/PKCE: pre-fix `302 -> /callback?error=server_error`, post-fix
`302 -> /http/consent?txn_id=…`. Adds an `oauth-discovery.test.ts`
regression suite covering Plane's wrong-issuer origin-root document plus
trailing-slash and no-issuer paths.

Fixes #3537
2026-06-26 07:09:24 +00:00
..
2026-06-23 10:41:59 +00:00
2026-06-25 11:41:56 +00:00
2026-06-11 21:03:49 +02:00
2026-05-30 18:08:51 +02:00
2026-05-30 18:08:51 +02:00
2026-06-12 11:24:26 +02:00
2026-05-30 18:08:51 +02:00
2026-06-24 13:44:47 +00:00