[BUG]: MCP OAuth callback unreachable when running in remote container / Codespaces — no manual token paste fallback
- 主要语言
- Shell
- 星标
- 11.2k
- 派生
- 1.9k
- 平均合并
- 14 小时 16 分钟
- 30 天内合并 PR
- 6
描述
### Describe the bug
When running Copilot CLI inside a remote container (e.g., GitHub Codespaces, Dev Containers), the MCP OAuth flow redirects to a `localhost` callback URL that is unreachable from the user's browser. There is no mechanism to manually paste the authorization code/callback URL back into the CLI, unlike Claude Desktop which provides a dialog for this.
### Affected version
1.0.36
### Steps to reproduce
1. Run Copilot CLI inside a GitHub Codespace or remote dev container
2. Add an HTTP MCP server that requires OAuth
3. Run `/mcp` → trigger auth → browser opens and user authorises
4. Browser attempts to redirect to `http://127.0.0.1:/?code=...&state=...`
5. Redirect fails — localhost resolves to the user's local machine, not the container
6. OAuth handshake never completes; MCP server remains unauthenticated
### Expected behavior
The CLI should either: (a) detect that the callback was not received and prompt the user to paste the callback URL manually, or (b) provide a `/mcp auth paste` style command to accept the code out-of-band.
### Workaround
Paste the callback URL to an AI agent running inside the container and have it `curl` the URL against the local listener. Not a user-friendly solution.
### Additional context
Claude Desktop handles this via a dedicated token paste dialog. Related to #1491 (random port issue) but distinct — this is specifically about remote container environments where localhost is unreachable from the browser.
贡献指南
调研方向
Start with the `/mcp` OAuth flow and its localhost callback listener, focusing on how callback failures behave in Codespaces and remote dev containers. Compare the proposed manual callback URL or authorization-code fallback with the existing flow; done means an HTTP MCP server can complete authentication when the browser cannot reach the container's localhost.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- shell
- 领域
- authentication, cli
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 活跃
- 描述清晰度
- 基本清楚
- 新手友好度
- 52/100