CLI stored-auth flags (--use-stored-auth, --list-stored-auth, --wait-for-auth) miss tokens stored under byIssuer
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 78/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- authentication, cli
Línea de trabajo
Start in clients/cli/src/cli.ts at findStoredToken and the --list-stored-auth and --use-stored-auth handlers; inspect the existing stored-auth tests for the byIssuer shape. Reproduce with the OAuth test server and an isolated MCP_STORAGE_DIR. Done means list, use, wait, and refresh write-back operate on the active issuer's joined token view and the tests cover this shape.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem
The CLI's stored-auth flags can't see a token the shared OAuth store actually holds:
--use-stored-authexits3withno_stored_token, and its message lists the very URL it failed to match under "Stored keys".--list-stored-authreturns"storedServerUrls": [].--wait-for-authgoes through the same lookup (findStoredToken), so going by the code it waits until it times out even after the token lands. I haven't run this one.
The lookups in clients/cli/src/cli.ts read the token at the server level: state.tokens?.access_token / state.tokens?.refresh_token (on v2/main: L325 findStoredToken, L388, L1010 --list-stored-auth, L1120–1121 --use-stored-auth). Since the OAuth store was re-keyed per issuer (#1625), acquired tokens are stored at servers[url].byIssuer[activeIssuer].tokens, so none of these lookups ever matches. --stored-auth-only is unaffected because it goes through the normal auth provider path, which does read byIssuer.
Found while smoke testing #2482, where it reproduced identically on v2/main (30a9a897) and on the PR head (fc55e11a). So it is not caused by that PR. The PR does change where the tokens live, since they move to the secret store and are joined back on read, so a fix should read the joined view.
Reproduce
- Start an OAuth test server:
node test-servers/build/server-composable.js --config test-servers/configs/oauth-revocation-http.json(:8083). - With an isolated
MCP_STORAGE_DIR, complete an interactive CLI login:mcp-inspector --cli --server-url http://localhost:8083/mcp --method tools/list. - Check the token is there:
--stored-auth-only --method tools/listsucceeds, andoauth.jsonshowsservers["http://localhost:8083/mcp"].byIssuer["http://localhost:8083"].tokens. mcp-inspector --cli --list-stored-authprintsstoredServerUrls: [].mcp-inspector --cli --server-url http://localhost:8083/mcp --use-stored-auth --method tools/listexits 3 with{"error":{"code":"no_stored_token",…"Stored keys: http://localhost:8083/mcp."}}.
Expected
--list-stored-authlists the URL.--use-stored-authrefreshes (or injects) the active issuer's token and succeeds.--wait-for-authreturns as soon as the token lands.- The refresh write-back persists the rotated tokens under the active issuer.
The existing stored-auth tests should cover the byIssuer shape, so this can't regress silently again.
- Lenguaje dominante
- TypeScript
- Estrellas
- 11k
- Forks
- 1.5k
- Merge medio
- 5 h 13 min
- PR fusionados (30 d)
- 132
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de modelcontextprotocol/inspector
-
bug v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
modelcontextprotocol/inspector#2525 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
enhancement v2
Dificultad 2/5 Medio día Aptitud para principiantes 76/100
modelcontextprotocol/inspector#2524 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
modelcontextprotocol/inspector#2523 ·
Los mantenedores suelen responder en 1 día
-
Plain HTTP 403 without `WWW-Authenticate` starts OAuth discovery in the Inspector web clientAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
modelcontextprotocol/inspector#2515 ·
Los mantenedores suelen responder en 1 día
-
enhancement v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
modelcontextprotocol/inspector#2438 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de modelcontextprotocol/inspector
Issues similares
-
area/frontend good first issue kind/cooldown
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
voidzero-dev/oxc-angular-compiler#511 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
langchain-ai/deepagentsjs#898 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
anomalyco/models.dev#8509 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
bug documentation P2 UI/UX
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
Los mantenedores suelen responder en 1 día