github / github/app

MCP OAuth tokens intermittently invalidated — shared ~/.copilot profile conflicts with other local apps

Abierto
#1,946 1 comentario 1 reacción 0 asignados Ver en GitHub
Bugs
Lenguaje dominante
Sin datos de lenguaje
Estrellas
2.1k
Forks
153
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Description:
GitHub Copilot Desktop/CLI stores its profile (m-mcp-servers.json, m-preferences.json, m-settings.json, mcp-oauth-config/) under %USERPROFILE%\.copilot. On this machine, that directory's creation date and several of its files predate this Copilot install entirely, and a separate installed application (Microsoft Scout) bundles code that directly references and manages the identical filenames (m-mcp-servers.json, m-preferences.json, m-settings.json, m-sync-state.json), including its own MCP store (setMcpStore).

Repro / symptom: Remote MCP servers requiring OAuth (custom endpoints, e.g. NinjaOne, Hudu-style integrations) fail with "no cached tokens; marking as needs-auth" in logs, even seconds after completing the interactive OAuth sign-in in the app. A valid, non-expired token file exists on disk for that server at the same time. Additionally, multiple orphaned OAuth config entries accumulate for the same server URL with different client IDs/redirect ports and non-contiguous timestamps — consistent with more than one process/app independently negotiating OAuth against the same server without coordination.

Expected: Once a user completes OAuth for an MCP server, that session should reliably reuse the cached token across new Copilot processes, and Copilot's profile/token cache shouldn't be readable/writable by unrelated applications.

Ask: Please confirm whether ~/.copilot is intended to be shared across Microsoft products, and if so, add per-writer/owner identification or locking to mcp-oauth-config so concurrent writers can't silently shadow each other's valid tokens.

---
| Field | Value |
| --- | --- |
| App version | 1.0.21 |
| OS | Windows 10.0.26200 |
| Theme | Noctis Azureus |
| Path | /chat |
| Tenure | Day 1 |

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by tracing the profile files named in the report: m-mcp-servers.json, m-preferences.json, m-settings.json, m-sync-state.json, and mcp-oauth-config/. Review the logs showing “no cached tokens” alongside the existing token file, then determine whether concurrent processes can write the same OAuth configuration. Done means confirming the ownership model and defining reliable token reuse without unrelated applications silently shadowing entries.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Área
authentication, desktop, security
Tipo de issue
Error
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
30/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.