github / github/copilot-cli

MCP OAuth client discovery: OAuth servers connect briefly then disconnect — tools never available in session

未關閉
#4,084 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
area:authentication area:mcp triaged
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

## Description

OAuth-protected MCP servers (Work IQ Calendar/Mail/Teams/OneDrive/Word + custom SkylineApi) show green/connected in the MCP servers settings page but consistently fail to provide tools in any session.

## Reproduction steps

1. Configure multiple OAuth-protected HTTP MCP servers in `~/.copilot/mcp-config.json` (e.g. Work IQ servers at `agent365.svc.cloud.microsoft` and a custom Azure-hosted server)
2. Start the Copilot app — MCP servers settings page shows all servers with green status indicators
3. Open any new session (chat or project session)
4. Try to use tools from any OAuth-protected server → tools are not available

## What the logs show

From `process-*.log` during session creation:

### Phase 1: Initial connection fails with AuthRequired
```
Server SkylineApi requires authentication, initiating OAuth flow
OAuth authentication required for SkylineApi
```

### Phase 2: OAuth request sent to wrong handler
```
[extension:...\task-housekeeping\extension.mjs] Received MCP OAuth request without a registered MCP auth handler.
OAuth handler did not provide credentials for SkylineApi (cancelled); marking as needs-auth
OAuth required for SkylineApi with no cached tokens; marking as needs-auth
```

The OAuth request is being routed to an **unrelated local extension** (task-housekeeping) instead of the app's built-in OAuth handler. The extension correctly reports it has no MCP auth handler registered, but the app interprets this as a cancellation and permanently marks the server as `needs-auth`.

### Phase 3: Work IQ servers eventually connect after retries (~10-30s)
```
MCP client for Work IQ Calendar connected, took 3022ms
MCP client for Work IQ Teams connected, took 718ms
MCP client for Work IQ Word connected, took 587ms
MCP client for Work IQ Mail connected, took 690ms
```

### Phase 4: All connections drop ~90 seconds later
```
MCP connection for Work IQ OneDrive closed
MCP connection for Work IQ Mail closed
MCP connection for Work IQ Word closed
MCP connection for Work IQ Teams closed
MCP connection for Work IQ Calendar closed
```

### Phase 5 (SkylineApi): Never reconnects
```
OAuth required for SkylineApi with no cached tokens; marking as needs-auth
```
The SkylineApi uses Azure AD OAuth (`api://eadfb142-206f-4a1b-a917-a719539433a0/user_impersonation`). The app detects the `AuthRequired` response from the `/.well-known/oauth-protected-resource` endpoint but cannot complete the OAuth flow because the auth request is routed to the wrong handler.

## Expected behavior

- The app's built-in OAuth handler should handle MCP OAuth requests, not route them to unrelated extensions
- OAuth tokens should be cached and refreshed automatically
- Once connected, MCP connections should remain open for the session lifetime (or reconnect automatically)
- The settings page green indicator should reflect actual runtime connectivity, not just config validity

## Environment

- **App version**: 1.0.19 (`com.github.githubapp`)
- **CLI version**: 1.0.69
- **OS**: Windows 11
- **MCP servers affected**: All OAuth-protected HTTP servers (5× Work IQ at `agent365.svc.cloud.microsoft` + 1× custom Azure Container Apps server)
- **MCP servers working**: Non-OAuth servers (`microsoft-learn`, `github-mcp-server`, `markitdown` local) all connect fine

## MCP config (sanitized)

```json
{
"mcpServers": {
"SkylineApi": {
"type": "http",
"url": "https:///mcp",
"timeout": 28800000
},
"Work IQ Calendar": {
"type": "http",
"url": "https://agent365.svc.cloud.microsoft/agents/tenants//servers/mcp_CalendarTools",
"timeout": 14400000
}
}
}
```
(Same pattern for Work IQ Mail, Teams, OneDrive, Word)

貢獻指南

開啟貢獻指南

研究方向

從 process-*.log 檔案中的 OAuth 與 MCP 連線事件開始,使用經過清理的 ~/.copilot/mcp-config.json 重現受 OAuth 保護的 HTTP 伺服器。追蹤請求為何會到達 task-housekeeping,以及伺服器為何被標記為 needs-auth,接著驗證 OAuth 伺服器在整個工作階段生命週期內仍可使用,並確認設定狀態反映執行階段的連線狀態。

由索引模型根據 Issue 內容生成。

評估

領域
api, authentication
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。