Copilot CLI OAuth login fails — CLI doesn't bind to port declared in its own CIMD client-metadata.json
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 64/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- shell
- 领域
- authentication, cli
调研方向
首先跟踪从 /authorize 请求到本地 loopback 回调监听器的 OAuth 流程,然后将其选择的端口与已发布的 client-metadata.json 中的 redirect_uris 值进行比较。在端口 33418 空闲且使用 CIMD MCP 服务器的情况下复现;完成标准是监听器和请求使用所声明的 URI,并且登录不再返回 invalid_request。
由索引模型根据 Issue 内容生成。
描述
Describe the bug
When authenticating to an MCP server that uses CIMD (Client ID Metadata Document) OAuth, Copilot CLI fails with:
{"error":"invalid_request","error_description":"Redirect URI 'http://127.0.0.1:<random_port>/' does not match CIMD redirect_uris.","state":"..."}
Root cause: Copilot CLI's own published client metadata ( https://github.com/copilot/cli/client-metadata.json ) declares a single fixed redirect URI:
"redirect_uris": ["http://127.0.0.1:33418/"]
Per the CIMD/OAuth spec, the redirect_uri used in the /authorize request must exactly match this declared value (RFC 8252's "any loopback port" leniency only applies when no port is specified — here one is).
However, Copilot CLI does not bind its local OAuth callback listener to port 33418 — it uses a different, seemingly random port instead (observed: 63450, then 61566), even when port 33418 is confirmed free/unused on the machine. This causes every login attempt against CIMD-based OAuth servers to fail.
Affected version
Copilot CLI v1.0.83, Windows
Steps to reproduce the behavior
- Confirm port 33418 is free ( Get-NetTCPConnection -LocalPort 33418 returns nothing).
- Attempt login to an MCP server using CIMD OAuth (client_id = a metadata document URL).
- Copilot CLI opens a callback listener on a different port than 33418.
- Server rejects with invalid_request / redirect_uri mismatch.
Expected behavior
Copilot CLI should bind its OAuth loopback listener to the exact port(s) declared in its own client-metadata.json (33418), consistent with CIMD requirements.
Additional context
No response
- 主要语言
- Shell
- 星标
- 11.2k
- 派生
- 1.9k
- 平均合并
- 17 小时 6 分钟
- 30 天内合并 PR
- 5
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/copilot-cli 的其他 Issue
-
triage
难度 1/5 1 小时以内 新手友好度 88/100
github/copilot-cli#4963 · 1 条评论 ·
维护者通常 1 天内回复
-
triage
难度 2/5 1-3 小时 新手友好度 75/100
github/copilot-cli#4932 ·
维护者通常 1 天内回复
-
triage
难度 2/5 1-3 小时 新手友好度 78/100
github/copilot-cli#4909 ·
维护者通常 1 天内回复
-
triage
难度 2/5 1-3 小时 新手友好度 76/100
github/copilot-cli#4906 ·
维护者通常 1 天内回复
-
triage
难度 2/5 1-3 小时 新手友好度 72/100
github/copilot-cli#4848 ·
维护者通常 1 天内回复
查看 github/copilot-cli 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
-
backlog bug
难度 2/5 1-3 小时 新手友好度 86/100
WLAN-Pi/wlanpi-profiler#306 ·
维护者通常 1 天内回复
-
area: backend good first issue priority: P3 - low size: S type: bug
难度 2/5 1-3 小时 新手友好度 78/100
Mizithra/ActiveTerrain#31 ·
-
难度 2/5 1-3 小时 新手友好度 68/100
obra/superpowers#2422 ·
维护者通常 6 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
ComplianceAsCode/content#15152 ·
维护者通常 2 天内回复