github / github/copilot-cli

copilot-cli ignores grant_types_supported and attempts authorization_code flow for client_credentials-only MCP servers

未關閉
#3,982 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
area:authentication area:mcp
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

### Describe the bug

Hello. I am trying to set up an corporate MCP server in copilot. This MCP server is protected using an OAuth authorization server that advertises only client_credentials in `grant_types_supported`
Copilot-cli still attempts to initiate an interactive `authorization_code` flow instead.

Expected behavior:

copilot-cli should check [grant_types_supported] from the OAuth server metadata
If only client_credentials is listed, it should use that flow
It should NOT launch a browser for interactive auth

Actual behavior:

Launches a browser window for authorization code flow
This fails because the MCP server only permits client_credentials
Even when explicitly configured with "oauthGrantType": "client_credentials", oauthPublicClient": false, and "oauthClientId" in the config file as per https://docs.github.com/en/copilot/reference/copilot-cli-reference/cli-command-reference#headless-oauth-client_credentials-grant, the browser still launches

### Affected version

_No response_

### Steps to reproduce the behavior

_No response_

### Expected behavior

_No response_

### Additional context

_No response_

貢獻指南

開啟貢獻指南

研究方向

Start in the copilot-cli OAuth configuration and metadata-handling paths, focusing on grant_types_supported and the oauthGrantType, oauthPublicClient, and oauthClientId settings. Reproduce with an MCP server advertising only client_credentials, then verify that the CLI selects the supported flow and does not launch a browser.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
shell
領域
authentication, cli
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。