fix(client): forward User-Agent through OAuth auth flow#2526
Open
Genmin wants to merge 4 commits intomodelcontextprotocol:mainfrom
Open
fix(client): forward User-Agent through OAuth auth flow#2526Genmin wants to merge 4 commits intomodelcontextprotocol:mainfrom
Genmin wants to merge 4 commits intomodelcontextprotocol:mainfrom
Conversation
Author
|
Pushed a follow-up for the coverage blocker. The full-flow exception path is now covered directly, so the auth flow still logs Validation:
|
Author
|
Follow-up pushed for the pre-commit/pyright failure: the new Validated locally after the update:
One local note: |
3d641bf to
78eafac
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
User-Agentheader onto OAuth-generated discovery, registration, refresh, and token requests.User-Agentis preserved.Why
Streamable HTTP callers can configure a custom
User-Agenton their HTTP client, but OAuth requests are created inside the auth provider as freshhttpx.Requestinstances. Those generated requests dropped the caller's user agent, which breaks deployments behind WAF rules that require it.Fixes #1664
Tests
uv run pytest tests/client/test_auth.py -k user_agent -quv run pytest tests/client/test_auth.py -quv run ruff check src/mcp/client/auth/oauth2.py tests/client/test_auth.pyuv run ruff format --check src/mcp/client/auth/oauth2.py tests/client/test_auth.pygit diff --check