github / github/copilot-cli

[BUG]: MCP OAuth callback unreachable when running in remote container / Codespaces — no manual token paste fallback

オープン
#3,009 コメント 2 件 リアクション 1 件 担当者 0 名 GitHub で見る
area:authentication area:mcp
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

### Describe the bug

When running Copilot CLI inside a remote container (e.g., GitHub Codespaces, Dev Containers), the MCP OAuth flow redirects to a `localhost` callback URL that is unreachable from the user's browser. There is no mechanism to manually paste the authorization code/callback URL back into the CLI, unlike Claude Desktop which provides a dialog for this.

### Affected version

1.0.36

### Steps to reproduce

1. Run Copilot CLI inside a GitHub Codespace or remote dev container
2. Add an HTTP MCP server that requires OAuth
3. Run `/mcp` → trigger auth → browser opens and user authorises
4. Browser attempts to redirect to `http://127.0.0.1:/?code=...&state=...`
5. Redirect fails — localhost resolves to the user's local machine, not the container
6. OAuth handshake never completes; MCP server remains unauthenticated

### Expected behavior

The CLI should either: (a) detect that the callback was not received and prompt the user to paste the callback URL manually, or (b) provide a `/mcp auth paste` style command to accept the code out-of-band.

### Workaround

Paste the callback URL to an AI agent running inside the container and have it `curl` the URL against the local listener. Not a user-friendly solution.

### Additional context

Claude Desktop handles this via a dedicated token paste dialog. Related to #1491 (random port issue) but distinct — this is specifically about remote container environments where localhost is unreachable from the browser.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the `/mcp` OAuth flow and its localhost callback listener, focusing on how callback failures behave in Codespaces and remote dev containers. Compare the proposed manual callback URL or authorization-code fallback with the existing flow; done means an HTTP MCP server can complete authentication when the browser cannot reach the container's localhost.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
shell
領域
authentication, cli
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
52/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。