🪪 fix: Consolidate MCP OAuth Policy - #13254
Conversation
…ctory Co-authored-by: Copilot <copilot@github.com>
|
@codex review |
There was a problem hiding this comment.
Pull request overview
Refines MCP proactive OAuth initiation so OAuth flows are started even when a server allows unauthenticated initialize/tools/list (e.g., Google hosted MCPs), including cases where protected-resource OAuth metadata is present, while preserving requiresOAuth: false as an explicit opt-out. It also adds regression tests to validate the new gating and listener cleanup behavior.
Changes:
- Added proactive OAuth initiation before connecting when no stored tokens exist and the server is determined to require OAuth (via
requiresOAuth,oauthconfig, or discoveredoauthMetadata), with an explicitrequiresOAuth: falseescape hatch. - Implemented proactive OAuth event waiting with explicit cleanup of
oauthHandled/oauthFailedlisteners on success, failure, and timeout. - Added Jest coverage for proactive OAuth triggers (including metadata-driven), explicit-false gating, listener cleanup, and discovery-mode behavior.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| packages/api/src/mcp/MCPConnectionFactory.ts | Adds proactive OAuth gating + pre-connect OAuth initiation with listener cleanup and timeout handling. |
| packages/api/src/mcp/tests/MCPConnectionFactory.test.ts | Adds regression tests for proactive OAuth behavior, gating rules, listener cleanup, and discovery-mode behavior. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Codex Review: Didn't find any major issues. Nice work! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
GitNexus: 🚀 deployedThe |
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
GitNexus: 🚀 deployedThe |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 55ff945c66
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep it up! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
GitNexus: 🚀 deployedThe |
|
@codex review |
|
Codex Review: Didn't find any major issues. Breezy! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
GitNexus: 🚀 deployedThe |
|
@codex review |
|
Codex Review: Didn't find any major issues. Bravo. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
* 🦉 feat: Implement proactive OAuth flow for connections without stored tokens * 🤝 fix: Enhance proactive OAuth flow handling in MCPConnectionFactory * fix: Add timeout handling for proactive OAuth flow in MCPConnectionFactory Co-authored-by: Copilot <copilot@github.com> * fix: Refine proactive MCP OAuth flow * test: Cover proactive OAuth missing handler * fix: Require explicit MCP OAuth signal * fix: Consolidate MCP OAuth policy --------- Co-authored-by: Gil Assunção <gil.assuncao@parceiros.nos.pt> Co-authored-by: Copilot <copilot@github.com>
Range: 8310e9a..190cdee Highlights: - Security: MCP OAuth hardening (LibreChat-AI#13264, LibreChat-AI#13274, LibreChat-AI#13276, LibreChat-AI#13254, LibreChat-AI#13256), SSRF guards, system tenant rejection (LibreChat-AI#13278), data retention semantics (LibreChat-AI#13049) - LLM: Gemini 3.5 Flash (LibreChat-AI#13231), Gemini Tool Combinations (LibreChat-AI#13273), AWS Bedrock API key support (LibreChat-AI#8690) [pending removal in stage-1] - Streaming/UI: cache preservation, race fixes, optimistic sidebar (LibreChat-AI#13298) - Observability: Prometheus metrics (LibreChat-AI#13265), OTel SSE tracing (LibreChat-AI#13266), build metadata (LibreChat-AI#12756) - Infra: graceful shutdown (LibreChat-AI#13211), readiness endpoints (LibreChat-AI#13212), Redis cluster safe delete (LibreChat-AI#13275) - CI/format: prettier --write all workspaces (LibreChat-AI#13281), ESLint enforcement (LibreChat-AI#13280) - Deps: @librechat/agents -> v3.1.96
* 🦉 feat: Implement proactive OAuth flow for connections without stored tokens * 🤝 fix: Enhance proactive OAuth flow handling in MCPConnectionFactory * fix: Add timeout handling for proactive OAuth flow in MCPConnectionFactory Co-authored-by: Copilot <copilot@github.com> * fix: Refine proactive MCP OAuth flow * test: Cover proactive OAuth missing handler * fix: Require explicit MCP OAuth signal * fix: Consolidate MCP OAuth policy --------- Co-authored-by: Gil Assunção <gil.assuncao@parceiros.nos.pt> Co-authored-by: Copilot <copilot@github.com>
I built on #12759 and folded in the policy-layer fix from #12511 to make MCP OAuth decisions consistent across proactive connection, discovery, and user connection setup. This supersedes #12759 and #12511.
requiresOAuth: falseopts out,requiresOAuth: trueopts in, and configuredoauthopts in whenrequiresOAuthis unset.requiresOAuth: falseas an explicit escape hatch so private/OIDC pass-through MCP servers do not show unwanted OAuth prompts and continue to fail promptly on normal auth failures.useOAuthfrom server config instead of hardcoding OAuth for every user connection.oauthRequiredhandler so 401/403 responses from non-OAuth servers fail promptly instead of waiting for OAuth handling timeouts.Change Type
Testing
npx jest src/mcp/__tests__/MCPConnectionFactory.test.ts src/mcp/__tests__/MCPManager.test.ts --runInBandfrompackages/api.npx eslint packages/api/src/mcp/MCPConnectionFactory.ts packages/api/src/mcp/UserConnectionManager.ts packages/api/src/mcp/MCPManager.ts packages/api/src/mcp/utils.ts packages/api/src/mcp/types/index.ts packages/api/src/mcp/__tests__/MCPConnectionFactory.test.ts packages/api/src/mcp/__tests__/MCPManager.test.ts.npm run build:api.git diff --check.Test Configuration:
requiresOAuthConfig in User MCP Connections #12511 policy changes folded in, targetingdevChecklist