github / github/copilot-cli

copilot-cli ignores grant_types_supported and attempts authorization_code flow for client_credentials-only MCP servers

オープン
#3,982 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:authentication area:mcp
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

### Describe the bug

Hello. I am trying to set up an corporate MCP server in copilot. This MCP server is protected using an OAuth authorization server that advertises only client_credentials in `grant_types_supported`
Copilot-cli still attempts to initiate an interactive `authorization_code` flow instead.

Expected behavior:

copilot-cli should check [grant_types_supported] from the OAuth server metadata
If only client_credentials is listed, it should use that flow
It should NOT launch a browser for interactive auth

Actual behavior:

Launches a browser window for authorization code flow
This fails because the MCP server only permits client_credentials
Even when explicitly configured with "oauthGrantType": "client_credentials", oauthPublicClient": false, and "oauthClientId" in the config file as per https://docs.github.com/en/copilot/reference/copilot-cli-reference/cli-command-reference#headless-oauth-client_credentials-grant, the browser still launches

### Affected version

_No response_

### Steps to reproduce the behavior

_No response_

### Expected behavior

_No response_

### Additional context

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start in the copilot-cli OAuth configuration and metadata-handling paths, focusing on grant_types_supported and the oauthGrantType, oauthPublicClient, and oauthClientId settings. Reproduce with an MCP server advertising only client_credentials, then verify that the CLI selects the supported flow and does not launch a browser.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
shell
領域
authentication, cli
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。