Hosted MCP `get_check_runs` fails with 403 where the equivalent REST call succeeds
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 38/100
- Issue-Typ
- Bug
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Ruhig
- Tech-Stack
- github, go
- Bereich
- api, authentication, security
Rechercherichtung
Beginne am pull_request_read-Einstiegspunkt für die Methode get_check_runs und vergleiche ihren gehosteten Authentifizierungs- und Berechtigungspfad mit der hier beschriebenen erfolgreichen REST-Anfrage. Überprüfe die durch #1942 eingeführte Änderung; abgeschlossen ist die Aufgabe, wenn die gehostete Methode für den gemeldeten Fall eines privaten Repositorys Check-Runs zurückgibt oder die erforderliche Berechtigung klar dokumentiert, falls die gehostete Installation nicht geändert werden kann.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Describe the bug
pull_request_read with method: get_check_runs returns 403 Resource not accessible by personal access token [] for a private repo that the same classic PAT can read via the plain REST API (gh pr checks / GET /repos/{owner}/{repo}/commits/{ref}/check-runs). Every other pull_request_read method (get, get_files, get_reviews, get_review_comments, etc.) works with that token on the same PR — only get_check_runs fails.
This means the method shipped via #1942 is effectively unusable against repos where the user's PAT is fine but the underlying MCP app installation is missing Checks: Read. The caller cannot fix it by adding PAT scopes, since the failing call isn't authenticated with the caller's PAT permission surface.
Affected version
Hosted remote MCP at https://api.githubcopilot.com/mcp/. github-mcp-server --version not available for the hosted deployment.
Steps to reproduce the behavior
- Authenticate the hosted Copilot MCP with a classic PAT that has
repo,read:org, and SSO authorization for the org hosting a private repo.k - Invoke
mcp__github__pull_request_readwith:method: get_check_runs owner: <org> repo: <private-repo> pullNumber: <N> - From a local shell using the same PAT:
returns 200 with the full check-runs payload.gh api /repos/<org>/<private-repo>/commits/<head-sha>/check-runs
Expected vs actual behavior
Expected: MCP get_check_runs returns the same payload as the REST API.
Actual:
failed to get check runs: GET https://api.github.com/repos/<org>/<private-repo>/commits/<sha>/check-runs?page=1&per_page=30: 403 Resource not accessible by personal access token []
All other pull_request_read methods succeed against the same PR with the same token.
Logs
Error string as surfaced to the MCP client:
failed to get check runs: GET https://api.github.com/repos/<org>/<private-repo>/commits/<sha>/check-runs?page=1&per_page=30: 403 Resource not accessible by personal access token []
Notes
- Feature was added in #1942 (closed). This report is a regression / follow-up: the method is reachable but consistently 403s under hosted-MCP auth where the caller's PAT has
repo. - Likely fix direction: ensure the hosted MCP's GitHub App installation requests
Checks: Read, or document the fine-grained permission requirement alongside the tool description.
Remark: This issue was analyzed and the report was created with Claude Code.
- Vorherrschende Sprache
- Go
- Sterne
- 33.1k
- Forks
- 5k
- Ø Merge
- 2 T. 1 Std.
- Gemergte PRs (30 T.)
- 25
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/github-mcp-server
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
github/github-mcp-server#3235 ·
-
enhancement
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
github/github-mcp-server#3042 · 2 Kommentare ·
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
github/github-mcp-server#3032 · 1 Reaktion ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
github/github-mcp-server#2803 · 1 Kommentar ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
github/github-mcp-server#2740 ·
Alle Issues in github/github-mcp-server
Ähnliche Issues
-
area/dev-productivity area/disaster-recovery area/ipcei kind/enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 85/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
-
kind/bug status/0-triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
-
🤔 refinement needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
equinor/radix-operator#1979 ·