github / github/copilot-cli

Authorization header length limit is too low to accomodate some Entra ID tokens

Offen
#2,960 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:mcp area:networking
Vorherrschende Sprache
Shell
Sterne
11.2k
Forks
1.9k
Ø Merge
14 Std. 16 Min.
Gemergte PRs (30 T.)
6

Beschreibung

### Describe the bug

I'm trying to use the Grafana MCP over an Azure Managed Grafana instance, which authenticates with my Entra account, but it fails upon invoking the MCP commands with the following error:
```
MCP server 'grafana': An error occurred invoking 'amgmcp_datasource_list': Authorization header length 11034 exceeds maximum allowed length of 8192.
```
The issue being that I have a few too many AD Groups (but not enough to trigger the overflow yet), which causes my token to be fairly huge and go past the current 8k limit.
My understanding is that this limit happens on the Copilot side, as this exact setup is working fine in Claude Code.

### Affected version

GitHub Copilot CLI 1.0.35.

### Steps to reproduce the behavior

The MCP is configured as such:
```json
"grafana": {
"type": "http",
"url": "https://.eus.grafana.azure.com/api/azure-mcp",
"headers": {
"Authorization": "Bearer ${GRAFANA_MCP_TOKEN}"
},
"tools": [
"*"
],
},
```

And upon opening Copilot, I'm setting the environment variable like so:
```
export GRAFANA_MCP_TOKEN=$(az account get-access-token --resource "ce34e7e5-485f-4d76-964f-b3d2b16d1e4f" --query accessToken -o tsv)
```
To get an authorization token for the managed grafana resource. The token is indeed around 11kB long.

### Expected behavior

The header length limit should be higher, to accomodate the authorization tokens that might be generated in practice by users, apparently especially users of Entra ID which can get fairly large tokens of ~11-12kB

### Additional context

_No response_

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie damit, die Validierung des 8192-Byte-Autorisierungs-Headers in der MCP-Anforderungsverarbeitung der CLI zu lokalisieren, und reproduzieren Sie sie anschließend mit der hier gezeigten Grafana-Konfiguration und dem Befehl zur Token-Generierung. Als erledigt gilt die Aufgabe, wenn realistische Entra ID-Token mit etwa 11–12 kB ohne den gemeldeten Fehler akzeptiert werden und das relevante Limit-Verhalten durch Tests abgedeckt ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure, shell
Bereich
authentication, cli
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
52/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.