Skip to content

fix(oauth): merge auth params into existing authorization_endpoint query (RFC 6749 3.1) - #3509

Closed
ege-arhan wants to merge 1 commit into
modelcontextprotocol:mainfrom
ege-arhan:fix/issue-3505
Closed

ege-arhan wants to merge 1 commit into
modelcontextprotocol:mainfrom
ege-arhan:fix/issue-3505

Conversation

@ege-arhan

Copy link
Copy Markdown

Problem

OAuthClientProvider._perform_authorization builds the redirect by appending a query string with a hardcoded question mark. When the advertised authorization_endpoint already carries a query (allowed by RFC 6749 section 3.1, e.g. Azure AD B2C policy param or multi-tenant tag), the result has a second question mark and the server misparses every authorization. The TS SDK is unaffected (URL + searchParams merge).

Solution

Merge via urlsplit/parse_qsl/urlunsplit so existing query params are retained and new params appended with ampersand. Plain endpoints render byte-identically to before.

Impact

OAuth flows against servers advertising query-bearing authorization endpoints now succeed; all other endpoints unchanged.

Evidence

Stdlib check: query-bearing endpoint merges correctly PASS; plain endpoint unchanged PASS. py_compile OK.

Fixes #3505

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 16, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3505.

If a maintainer assigns you to #3505, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

@github-actions github-actions Bot closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OAuth client: authorization URL is built with a second ? when the advertised authorization_endpoint already carries a query (RFC 6749 §3.1)

1 participant