github / github/app

MCP OAuth tokens intermittently invalidated — shared ~/.copilot profile conflicts with other local apps

オープン
#1,946 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る
Bugs
主要言語
言語のデータがありません
スター
2.1k
フォーク
153
PR マージ指標
30日以内にマージされた PR はありません

説明

Description:
GitHub Copilot Desktop/CLI stores its profile (m-mcp-servers.json, m-preferences.json, m-settings.json, mcp-oauth-config/) under %USERPROFILE%\.copilot. On this machine, that directory's creation date and several of its files predate this Copilot install entirely, and a separate installed application (Microsoft Scout) bundles code that directly references and manages the identical filenames (m-mcp-servers.json, m-preferences.json, m-settings.json, m-sync-state.json), including its own MCP store (setMcpStore).

Repro / symptom: Remote MCP servers requiring OAuth (custom endpoints, e.g. NinjaOne, Hudu-style integrations) fail with "no cached tokens; marking as needs-auth" in logs, even seconds after completing the interactive OAuth sign-in in the app. A valid, non-expired token file exists on disk for that server at the same time. Additionally, multiple orphaned OAuth config entries accumulate for the same server URL with different client IDs/redirect ports and non-contiguous timestamps — consistent with more than one process/app independently negotiating OAuth against the same server without coordination.

Expected: Once a user completes OAuth for an MCP server, that session should reliably reuse the cached token across new Copilot processes, and Copilot's profile/token cache shouldn't be readable/writable by unrelated applications.

Ask: Please confirm whether ~/.copilot is intended to be shared across Microsoft products, and if so, add per-writer/owner identification or locking to mcp-oauth-config so concurrent writers can't silently shadow each other's valid tokens.

---
| Field | Value |
| --- | --- |
| App version | 1.0.21 |
| OS | Windows 10.0.26200 |
| Theme | Noctis Azureus |
| Path | /chat |
| Tenure | Day 1 |

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by tracing the profile files named in the report: m-mcp-servers.json, m-preferences.json, m-settings.json, m-sync-state.json, and mcp-oauth-config/. Review the logs showing “no cached tokens” alongside the existing token file, then determine whether concurrent processes can write the same OAuth configuration. Done means confirming the ownership model and defining reliable token reuse without unrelated applications silently shadowing entries.

索引モデルが issue の本文から書いたものです。

評価

領域
authentication, desktop, security
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
30/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。