Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

CLI stored-auth flags (--use-stored-auth, --list-stored-auth, --wait-for-auth) miss tokens stored under byIssuer

オープン
#2,517 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
78/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript

調査の方向性

Start in clients/cli/src/cli.ts at findStoredToken and the --list-stored-auth and --use-stored-auth handlers; inspect the existing stored-auth tests for the byIssuer shape. Reproduce with the OAuth test server and an isolated MCP_STORAGE_DIR. Done means list, use, wait, and refresh write-back operate on the active issuer's joined token view and the tests cover this shape.

索引モデルが issue の本文から書いたものです。

説明

bug v2

Problem

The CLI's stored-auth flags can't see a token the shared OAuth store actually holds:

  • --use-stored-auth exits 3 with no_stored_token, and its message lists the very URL it failed to match under "Stored keys".
  • --list-stored-auth returns "storedServerUrls": [].
  • --wait-for-auth goes through the same lookup (findStoredToken), so going by the code it waits until it times out even after the token lands. I haven't run this one.

The lookups in clients/cli/src/cli.ts read the token at the server level: state.tokens?.access_token / state.tokens?.refresh_token (on v2/main: L325 findStoredToken, L388, L1010 --list-stored-auth, L1120–1121 --use-stored-auth). Since the OAuth store was re-keyed per issuer (#1625), acquired tokens are stored at servers[url].byIssuer[activeIssuer].tokens, so none of these lookups ever matches. --stored-auth-only is unaffected because it goes through the normal auth provider path, which does read byIssuer.

Found while smoke testing #2482, where it reproduced identically on v2/main (30a9a897) and on the PR head (fc55e11a). So it is not caused by that PR. The PR does change where the tokens live, since they move to the secret store and are joined back on read, so a fix should read the joined view.

Reproduce

  1. Start an OAuth test server: node test-servers/build/server-composable.js --config test-servers/configs/oauth-revocation-http.json (:8083).
  2. With an isolated MCP_STORAGE_DIR, complete an interactive CLI login: mcp-inspector --cli --server-url http://localhost:8083/mcp --method tools/list.
  3. Check the token is there: --stored-auth-only --method tools/list succeeds, and oauth.json shows servers["http://localhost:8083/mcp"].byIssuer["http://localhost:8083"].tokens.
  4. mcp-inspector --cli --list-stored-auth prints storedServerUrls: [].
  5. mcp-inspector --cli --server-url http://localhost:8083/mcp --use-stored-auth --method tools/list exits 3 with {"error":{"code":"no_stored_token",…"Stored keys: http://localhost:8083/mcp."}}.

Expected

  • --list-stored-auth lists the URL.
  • --use-stored-auth refreshes (or injects) the active issuer's token and succeeds.
  • --wait-for-auth returns as soon as the token lands.
  • The refresh write-back persists the rotated tokens under the active issuer.

The existing stored-auth tests should cover the byIssuer shape, so this can't regress silently again.

主要言語
TypeScript
スター
11k
フォーク
1.5k
平均マージ
5時間 18分
マージ済み PR(30日)
130

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

modelcontextprotocol/inspector のほかの issue

modelcontextprotocol/inspector の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。