Atlassian MCP server auto-connects without completing OAuth flow (Sign in button disappears)
- Linguagem predominante
- Shell
- Estrelas
- 11.2k
- Forks
- 1.9k
- Merge médio
- 14h 16min
- PRs com merge (30d)
- 6
Descrição
## Description
The Atlassian MCP server (https://mcp.atlassian.com/v1/mcp) shows a green checkmark (connected) in MCP Settings without completing the OAuth browser flow. No atlassian-* tools are loaded in sessions.
## Expected behavior
Clicking 'Sign in' or toggling the server on should open a browser for OAuth authorization (like LeanIX and Lucid do).
## Actual behavior
- The 'Sign in' button flashes briefly and disappears
- Green checkmark appears immediately without browser redirect
- No OAuth token is saved (no .tokens.json file in ~/.copilot/mcp-oauth-config/)
- Sessions do not have access to any Atlassian tools
## Steps to reproduce
1. Add Atlassian MCP to a plugin .mcp.json:
```
"atlassian": { "type": "http", "url": "https://mcp.atlassian.com/v1/mcp" }
```
2. Open MCP Settings
3. Toggle Atlassian on
4. Observe: green checkmark appears without browser opening
## Root cause hypothesis
Atlassian MCP endpoint responds to discovery/health-check requests with HTTP 200 without requiring authentication. The app interprets this as 'connected' and skips the OAuth flow. Other MCP servers (LeanIX, Lucid) correctly require auth on these requests.
## Workaround
Using Atlassian REST API directly with personal API tokens.
## Environment
- Copilot CLI version: 1.0.69
- OS: Windows 11
- Plugin: custom plugin with Atlassian MCP config
- Other MCP servers working correctly: LeanIX, Lucid, QMD (local)
Guia de contribuição
Direção de pesquisa
Comece pelo fluxo de MCP Settings e pela configuração plugin .mcp.json e, em seguida, reproduza o comportamento do endpoint Atlassian descrito na issue. Compare a descoberta e o tratamento da autenticação com LeanIX e Lucid; estará concluído quando Sign in abrir o fluxo OAuth no navegador, um token for salvo e as ferramentas Atlassian forem carregadas nas sessões.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Domínio
- authentication, cli
- Tipo de issue
- Bug
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Status de atividade
- Pouca atividade
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 55/100