MCP forced re-auth appends prompt=select_account for non-Microsoft OAuth providers
还没有人认领这个 Issue。
- 主要语言
- Shell
- 星标
- 11.2k
- 派生
- 1.9k
- 平均合并
- 14 小时 16 分钟
- 30 天内合并 PR
- 6
描述
Describe the bug
When an MCP OAuth flow is started with forced re-authentication, Copilot CLI unconditionally appends prompt=select_account to the authorization URL, including for non-Microsoft authorization servers that do not advertise support for this prompt value.
A non-Microsoft OpenID Connect provider rejects this unsupported value with invalid_request. The same authorization request succeeds after removing only &prompt=select_account from the URL.
Affected version
GitHub Copilot CLI 1.0.80
Steps to reproduce the behavior
- Configure a remote Streamable HTTP MCP server that uses OAuth with a non-Microsoft OpenID Connect authorization server.
- Complete Dynamic Client Registration and PKCE setup normally.
- Trigger forced re-authentication through
/mcp auth, the MCP server Authenticate action, or therre-auth shortcut. - Inspect the generated authorization URL.
- Observe that Copilot CLI appends
prompt=select_account. - Open the URL and observe that the authorization server rejects it with HTTP 400
invalid_request. - Remove only
&prompt=select_accountand reload the URL while the Copilot CLI callback server remains running. - Observe that the OAuth request proceeds successfully.
Control result:
forceReauth=false: nopromptparameter; authorization proceeds.forceReauth=true:prompt=select_account; authorization is rejected.
Expected behavior
Copilot CLI should not add prompt=select_account unconditionally for every authorization server.
Possible solutions include:
- Add the parameter only when the authorization server advertises
select_accountthroughprompt_values_supported. - Make the forced re-authentication prompt configurable.
- Use a provider-neutral re-authentication mechanism such as
prompt=loginwhen account-selection support is unknown.
Additional context
Environment:
- Windows 11 x64
- PowerShell
- Remote Streamable HTTP MCP server
- OAuth Authorization Code flow with PKCE
- Dynamic Client Registration
- Non-Microsoft OpenID Connect provider
Temporary workaround: copy the generated authorization URL, remove &prompt=select_account, and open the modified URL while the Copilot CLI OAuth callback server is still running.
No credentials, tokens, or private authorization-server URLs are included in this report.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从通过 /mcp auth、MCP 服务器的 Authenticate 操作和 r 重新认证快捷方式进入的 OAuth 授权 URL 生成开始,跟踪 forceReauth 如何添加 prompt=select_account。检查授权服务器公布的 prompt_values_supported 元数据,并验证强制重新认证不再向非 Microsoft 提供商发送不受支持的 prompt,同时 OAuth 流程仍能成功完成。
由索引模型根据 Issue 内容生成。
评估
- 领域
- authentication, cli
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 活跃
- 描述清晰度
- 基本清楚
- 新手友好度
- 55/100