CLI stored-auth flags (--use-stored-auth, --list-stored-auth, --wait-for-auth) miss tokens stored under byIssuer
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 78/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
- Ambito
- authentication, cli
Direzione di ricerca
Start in clients/cli/src/cli.ts at findStoredToken and the --list-stored-auth and --use-stored-auth handlers; inspect the existing stored-auth tests for the byIssuer shape. Reproduce with the OAuth test server and an isolated MCP_STORAGE_DIR. Done means list, use, wait, and refresh write-back operate on the active issuer's joined token view and the tests cover this shape.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Problem
The CLI's stored-auth flags can't see a token the shared OAuth store actually holds:
--use-stored-authexits3withno_stored_token, and its message lists the very URL it failed to match under "Stored keys".--list-stored-authreturns"storedServerUrls": [].--wait-for-authgoes through the same lookup (findStoredToken), so going by the code it waits until it times out even after the token lands. I haven't run this one.
The lookups in clients/cli/src/cli.ts read the token at the server level: state.tokens?.access_token / state.tokens?.refresh_token (on v2/main: L325 findStoredToken, L388, L1010 --list-stored-auth, L1120–1121 --use-stored-auth). Since the OAuth store was re-keyed per issuer (#1625), acquired tokens are stored at servers[url].byIssuer[activeIssuer].tokens, so none of these lookups ever matches. --stored-auth-only is unaffected because it goes through the normal auth provider path, which does read byIssuer.
Found while smoke testing #2482, where it reproduced identically on v2/main (30a9a897) and on the PR head (fc55e11a). So it is not caused by that PR. The PR does change where the tokens live, since they move to the secret store and are joined back on read, so a fix should read the joined view.
Reproduce
- Start an OAuth test server:
node test-servers/build/server-composable.js --config test-servers/configs/oauth-revocation-http.json(:8083). - With an isolated
MCP_STORAGE_DIR, complete an interactive CLI login:mcp-inspector --cli --server-url http://localhost:8083/mcp --method tools/list. - Check the token is there:
--stored-auth-only --method tools/listsucceeds, andoauth.jsonshowsservers["http://localhost:8083/mcp"].byIssuer["http://localhost:8083"].tokens. mcp-inspector --cli --list-stored-authprintsstoredServerUrls: [].mcp-inspector --cli --server-url http://localhost:8083/mcp --use-stored-auth --method tools/listexits 3 with{"error":{"code":"no_stored_token",…"Stored keys: http://localhost:8083/mcp."}}.
Expected
--list-stored-authlists the URL.--use-stored-authrefreshes (or injects) the active issuer's token and succeeds.--wait-for-authreturns as soon as the token lands.- The refresh write-back persists the rotated tokens under the active issuer.
The existing stored-auth tests should cover the byIssuer shape, so this can't regress silently again.
- Lingua principale
- TypeScript
- Stelle
- 11k
- Fork
- 1.5k
- Merge medio
- 5h 18m
- PR unite (30g)
- 130
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di modelcontextprotocol/inspector
-
chore dependencies v2
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
modelcontextprotocol/inspector#2522 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/inspector#2515 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement v2
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
modelcontextprotocol/inspector#2438 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
chore dependencies v2
Difficoltà 3/5 1-2 giorni Idoneità per principianti 75/100
modelcontextprotocol/inspector#2521 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 62/100
modelcontextprotocol/inspector#2518 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di modelcontextprotocol/inspector
Issue simili
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
inu-appcenter/memorIN-frontend#106 ·
I maintainer di solito rispondono entro 1 giorno
-
kind/bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
I maintainer di solito rispondono entro 7 giorni
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
fix: CopyFilters ignores tabApertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
CSCfi/sd-search-ui#145 ·
I maintainer di solito rispondono entro 1 giorno
-
Add: Cbeebies pl SDApertacheck:passed streams:add
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno