Conversation
|
Actions checks haven’t started for this fork PR yet (workflow runs show “Action required”). I ran the focused checks locally and they pass:
Could a maintainer please approve/run the workflows so CI can execute? |
|
Thanks for picking this up @Epochex — this PR fixes the exact issue I reported in #36230 (Google Drive MCP, and any other MCP server that returns We hit this on a self-hosted Dify 1.14.1 deployment and had to build a separate Flask service as a workaround, since the official Google Drive MCP can't be used until this is fixed. Would really appreciate a maintainer (@QuantumGhost, @laipz8200) approving CI and reviewing — the change is small (116 LOC, +tests) and unblocks a meaningful integration path. Happy to test against my reproducer once it lands. |
2af3b44 to
ef29030
Compare
ef29030 to
8fa05e4
Compare
|
Rebased this onto current The guard now checks parsed OAuth client information rather than a raw credential key, so a server with no OAuth configuration still follows the normal success path. The focused cases now cover:
Validation:
This is ready for CI approval and review. |
8fa05e4 to
f2eec1f
Compare
|
Rebased onto current
|
What
Fix MCP OAuth authorization flow for servers that return
200 OKoninitializeeven when no tokens are present.Today
ToolMCPAuthApimarks the provider asauthed=trueas soon as it can connect, which breaks OAuth-protected servers like Google Drive MCP:initializesucceeds, but later tool calls fail because no access token was ever obtained.How
After a successful connect, if the provider has
client_informationconfigured but still has no tokens, start the OAuth flow viacore.mcp.auth.auth_flow.auth()and return theauthorization_urlresponse instead of savingauthed=true.Tests
uv run --project api pytest -q api/tests/unit_tests/controllers/console/workspace/test_tool_providers.py -k mcp_authuv run --project api ruff check api/controllers/console/workspace/tool_providers.py api/tests/unit_tests/controllers/console/workspace/test_tool_providers.pyFixes #36230