Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Gong plugin: desktop OAuth can't be completed — Gong rejects the http://localhost:8787/callback redirect URI

Abierto
#328 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
52/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
typescript

Línea de trabajo

Comienza con el paso 2 de third_party/gong/README.md y sigue la configuración del callback de OAuth de escritorio utilizada por el plugin de Gong. Confirma que el callback elegido funciona con la validación de redirect-URI de Gong, actualiza la configuración documentada y verifica que la autorización de escritorio se complete sin unauthorized_client.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Summary

The Gong plugin's documented setup can't be completed on desktop. third_party/gong/README.md step 2 tells admins to register http://localhost:8787/callback as a redirect URI on the Gong MCP integration, but Gong's admin API refuses to store any http:// redirect URI. Since that URI can never be whitelisted, desktop OAuth always ends in unauthorized_client.

Error

After clicking ALLOW on Gong's consent screen, the browser lands on:

http://localhost:8787/callback?error=unauthorized_client&error_description=This%20MCP%20client%20is%20not%20authorized%20for%20your%20company.%20Please%20ask%20your%20Gong%20technical%20admin%20to%20authorize%20it.

The message points at the admin, which sends people hunting for an approval setting that doesn't exist. The real cause is the redirect URI.

Why the documented step can't be done

Gong's Redirect URL field accepts https:// only:

  • Saving http://localhost:8787/callback → the admin API PUT returns 400 Bad Request; on a retry the line is silently dropped from the saved list.
  • The same field saves https:// URIs without complaint — including https://localhost:<port>/oauth/callback and the Cursor web callback already in the README.

So the scheme is what's rejected, not loopback itself.

Isolation

Same Gong integration, same client ID and secret, changing one variable at a time:

Redirect URI Scopes Result
https://<whitelisted-https-host>:<port>/oauth/callback mcp:read access token issued
http://localhost:8787/callback mcp:read mcp:write + resource unauthorized_client
http://localhost:8787/callback mcp:read unauthorized_client

Scopes and the resource parameter make no difference. Only the redirect URI does.

One detail that makes this painful to diagnose: Gong renders the consent screen before validating the redirect URI. The flow looks healthy — the app name, the requested scopes, everything — right up until you click ALLOW. Only then does it reject. It's easy to conclude the callback is fine and go looking elsewhere.

Tested against both a Personal access and a Shared access integration, both Manual registration. Same result.

Suggested fixes

  1. Use an https loopback callback for desktop, or route desktop through the same https://www.cursor.com/agents/mcp/oauth/callback that Web and Cloud Agents already use.
  2. At minimum, update third_party/gong/README.md so admins aren't asked to register a URI that Gong won't accept.

RFC 8252 §7.3 expects native apps to use loopback redirects, so this is arguably worth raising with Gong as well — but as things stand their admin API rejects http://, so the plugin can't depend on it.

Environment

  • Gong MCP server: https://mcp.gong.io/mcp
  • Integration: Manual registration (client ID + secret)
  • Plugin: third_party/gong 1.0.0
Lenguaje dominante
TypeScript
Estrellas
9.7k
Forks
919
Merge medio
14 h 37 min
PR fusionados (30 d)
66

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de cursor/plugins

Todos los issues de cursor/plugins

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.