Gong plugin: desktop OAuth can't be completed — Gong rejects the http://localhost:8787/callback redirect URI
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 52/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- authentication, desktop, documentation
Línea de trabajo
Comienza con el paso 2 de third_party/gong/README.md y sigue la configuración del callback de OAuth de escritorio utilizada por el plugin de Gong. Confirma que el callback elegido funciona con la validación de redirect-URI de Gong, actualiza la configuración documentada y verifica que la autorización de escritorio se complete sin unauthorized_client.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
The Gong plugin's documented setup can't be completed on desktop. third_party/gong/README.md step 2 tells admins to register http://localhost:8787/callback as a redirect URI on the Gong MCP integration, but Gong's admin API refuses to store any http:// redirect URI. Since that URI can never be whitelisted, desktop OAuth always ends in unauthorized_client.
Error
After clicking ALLOW on Gong's consent screen, the browser lands on:
http://localhost:8787/callback?error=unauthorized_client&error_description=This%20MCP%20client%20is%20not%20authorized%20for%20your%20company.%20Please%20ask%20your%20Gong%20technical%20admin%20to%20authorize%20it.
The message points at the admin, which sends people hunting for an approval setting that doesn't exist. The real cause is the redirect URI.
Why the documented step can't be done
Gong's Redirect URL field accepts https:// only:
- Saving
http://localhost:8787/callback→ the admin APIPUTreturns400 Bad Request; on a retry the line is silently dropped from the saved list. - The same field saves
https://URIs without complaint — includinghttps://localhost:<port>/oauth/callbackand the Cursor web callback already in the README.
So the scheme is what's rejected, not loopback itself.
Isolation
Same Gong integration, same client ID and secret, changing one variable at a time:
| Redirect URI | Scopes | Result |
|---|---|---|
https://<whitelisted-https-host>:<port>/oauth/callback |
mcp:read |
access token issued |
http://localhost:8787/callback |
mcp:read mcp:write + resource |
unauthorized_client |
http://localhost:8787/callback |
mcp:read |
unauthorized_client |
Scopes and the resource parameter make no difference. Only the redirect URI does.
One detail that makes this painful to diagnose: Gong renders the consent screen before validating the redirect URI. The flow looks healthy — the app name, the requested scopes, everything — right up until you click ALLOW. Only then does it reject. It's easy to conclude the callback is fine and go looking elsewhere.
Tested against both a Personal access and a Shared access integration, both Manual registration. Same result.
Suggested fixes
- Use an
httpsloopback callback for desktop, or route desktop through the samehttps://www.cursor.com/agents/mcp/oauth/callbackthat Web and Cloud Agents already use. - At minimum, update
third_party/gong/README.mdso admins aren't asked to register a URI that Gong won't accept.
RFC 8252 §7.3 expects native apps to use loopback redirects, so this is arguably worth raising with Gong as well — but as things stand their admin API rejects http://, so the plugin can't depend on it.
Environment
- Gong MCP server:
https://mcp.gong.io/mcp - Integration: Manual registration (client ID + secret)
- Plugin:
third_party/gong1.0.0
- Lenguaje dominante
- TypeScript
- Estrellas
- 9.7k
- Forks
- 919
- Merge medio
- 14 h 37 min
- PR fusionados (30 d)
- 66
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cursor/plugins
-
pstack: Comment Sicko agent name has a space and Grok rejects the spawnPosiblemente ocupada @lab1207 la tomó hace 2 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
cursor/plugins#483 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
create-plugin README documents a /create-plugin command that does not existPosiblemente ocupada @lab1207 la tomó hace 2 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
cursor/plugins#475 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
principle-test-behavior-not-implementation: listed matchers do not all pass when imports return undefinedPosiblemente ocupada @Yi-111-a la tomó hace 3 días. Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
cursor/plugins#474 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
cursor-sdk auth.md: non-null assertion described as a runtime missing-variable checkPosiblemente ocupada @lab1207 la tomó hace 2 días. Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
cursor/plugins#473 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
watch-pr: review threads are fetched without pagination (first 100 only)Posiblemente ocupada @Yi-111-a la tomó hace 2 días. Abierto
Dificultad 2/5 Medio día Aptitud para principiantes 84/100
cursor/plugins#471 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de cursor/plugins
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Effect-TS/effect#8728 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Add: CanalPlusSport8SK.skAbiertocheck:passed streams:add
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
linagora/twake-drive-mobile#436 ·
Los mantenedores suelen responder en 1 día
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display languagePosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
apache/rocketmq-dashboard#5561 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 87/100
heygen-com/hyperframes#5002 ·
Los mantenedores suelen responder en 1 día