Gmail plugin: create_filter / list_filters fail with 403 — OAuth missing gmail.settings.basic
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 68/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- google-cloud, typescript
- 领域
- api, authentication
调研方向
定位 Gmail 插件的 OAuth 客户端和 consent-scope 配置,然后追踪 create_filter 和 list_filters 使用的 upscoping 入口点。确认会请求 settings scope,并且已有用户重新同意的流程已有文档记录;完成标准是授权后过滤器工具不再因报告的 403 而失败。
由索引模型根据 Issue 内容生成。
描述
Summary
The Gmail connector exposes create_filter, list_filters (and related filter tools), but calling them fails with 403 after trying upscoping. Google Account → Linked Apps shows the Cursor/Grok app only has “See (but not change) your email settings”, so filter create/list cannot work. Re-auth does not help: Google never requests a settings-write scope during consent.
Environment
- Product: Grok Bot / Cursor Gmail MCP connector
- Plugin id (from install):
45893410 - MCP server id:
user-Gmail--shark5060-gmail-com - Account: personal Gmail (example:
[email protected]) - Other Gmail tools work:
list_labels,search_threads, label apply, etc.
Steps to reproduce
- Install/connect the Gmail plugin and complete OAuth.
- Confirm mail tools work (e.g.
list_labels,search_threads). - Call
list_filtersorcreate_filter(e.g. criteriafrom: youtube.com, action add a user label + removeINBOX). - Optionally force re-auth (
AuthenticateMcpServerwithforce_reauth) and approve all consent screens again. - Retry
create_filter/list_filters.
Expected
- Filter tools succeed, or
- OAuth consent requests
https://www.googleapis.com/auth/gmail.settings.basicso Linked Apps shows edit/create/change settings & filters, then tools work after re-consent.
Actual
- Tool call error (approx.):
HTTP MCP tool execution failed: … Server returned 403 after trying upscoping - Google Linked Apps for the Cursor app under Gmail includes wording like:
- See (but not change) your email settings
- View your settings (e.g., filters and labels)
- There is no Linked Apps toggle to grant settings write; only delete connection.
- Label create/update and message labeling still work (consistent with
gmail.modify, not settings write).
Why this matters
Without users.settings.filters.*, agents cannot install durable server-side routing (skip Inbox + apply label) and must re-label mail after arrival. The tools being present implies filter management is intended.
API / scope note
Per Gmail API users.settings.filters.create, create requires:
https://www.googleapis.com/auth/gmail.settings.basic
(Gmail scopes: that scope is “See, edit, create, or change your email settings and filters in Gmail.”)
gmail.modify covers labels/messages but not filter settings write — matching the Linked Apps “see but not change” text.
Suggested fix
- Add
gmail.settings.basicto the Gmail plugin OAuth client / consent scope list. - Document that existing users must re-consent after the scope is added.
- Ensure upscoping actually requests that scope (current “403 after trying upscoping” suggests upscope does not obtain write settings).
Workaround
Create filters manually (or via browser automation) in Gmail Settings → Filters and Blocked Addresses until the connector requests the correct scope.
Related (third-party, not Cursor)
Other Gmail MCP projects have discussed the same scope requirement, e.g. needing gmail.settings.basic for filter tools — same underlying Google API constraint.
- 主要语言
- TypeScript
- 星标
- 8.8k
- 派生
- 819
- 平均合并
- 14 小时 37 分钟
- 30 天内合并 PR
- 66
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
cursor/plugins 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 88/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 92/100
维护者通常 1 天内回复
-
难度 2/5 半天 新手友好度 84/100
维护者通常 1 天内回复
相似的 Issue
-
check:failed streams:add
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
type: bug
难度 2/5 1-3 小时 新手友好度 84/100
interledger/rafiki#3986 ·
-
难度 2/5 1-3 小时 新手友好度 68/100
Doist/todoist-cli#576 ·
维护者通常 1 天内回复
-
feature
难度 1/5 1 小时以内 新手友好度 72/100
vercel-labs/skills#2370 ·
维护者通常 1 天内回复
-
🐛 Bug supabase/cli
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复