copilot-cli ignores grant_types_supported and attempts authorization_code flow for client_credentials-only MCP servers
- 主要言語
- Shell
- スター
- 11.2k
- フォーク
- 1.9k
- 平均マージ
- 14時間 16分
- マージ済み PR(30日)
- 6
説明
### Describe the bug
Hello. I am trying to set up an corporate MCP server in copilot. This MCP server is protected using an OAuth authorization server that advertises only client_credentials in `grant_types_supported`
Copilot-cli still attempts to initiate an interactive `authorization_code` flow instead.
Expected behavior:
copilot-cli should check [grant_types_supported] from the OAuth server metadata
If only client_credentials is listed, it should use that flow
It should NOT launch a browser for interactive auth
Actual behavior:
Launches a browser window for authorization code flow
This fails because the MCP server only permits client_credentials
Even when explicitly configured with "oauthGrantType": "client_credentials", oauthPublicClient": false, and "oauthClientId" in the config file as per https://docs.github.com/en/copilot/reference/copilot-cli-reference/cli-command-reference#headless-oauth-client_credentials-grant, the browser still launches
### Affected version
_No response_
### Steps to reproduce the behavior
_No response_
### Expected behavior
_No response_
### Additional context
_No response_
コントリビューションガイド
調査の方向性
Start in the copilot-cli OAuth configuration and metadata-handling paths, focusing on grant_types_supported and the oauthGrantType, oauthPublicClient, and oauthClientId settings. Reproduce with an MCP server advertising only client_credentials, then verify that the CLI selects the supported flow and does not launch a browser.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- shell
- 領域
- authentication, cli
- issue の種類
- バグ
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 48/100