github / github/copilot-cli

MCP forced re-auth appends prompt=select_account for non-Microsoft OAuth providers

未关闭
#4,526 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

triage
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

Describe the bug

When an MCP OAuth flow is started with forced re-authentication, Copilot CLI unconditionally appends prompt=select_account to the authorization URL, including for non-Microsoft authorization servers that do not advertise support for this prompt value.

A non-Microsoft OpenID Connect provider rejects this unsupported value with invalid_request. The same authorization request succeeds after removing only &prompt=select_account from the URL.

Affected version

GitHub Copilot CLI 1.0.80

Steps to reproduce the behavior

  1. Configure a remote Streamable HTTP MCP server that uses OAuth with a non-Microsoft OpenID Connect authorization server.
  2. Complete Dynamic Client Registration and PKCE setup normally.
  3. Trigger forced re-authentication through /mcp auth, the MCP server Authenticate action, or the r re-auth shortcut.
  4. Inspect the generated authorization URL.
  5. Observe that Copilot CLI appends prompt=select_account.
  6. Open the URL and observe that the authorization server rejects it with HTTP 400 invalid_request.
  7. Remove only &prompt=select_account and reload the URL while the Copilot CLI callback server remains running.
  8. Observe that the OAuth request proceeds successfully.

Control result:

  • forceReauth=false: no prompt parameter; authorization proceeds.
  • forceReauth=true: prompt=select_account; authorization is rejected.

Expected behavior

Copilot CLI should not add prompt=select_account unconditionally for every authorization server.

Possible solutions include:

  • Add the parameter only when the authorization server advertises select_account through prompt_values_supported.
  • Make the forced re-authentication prompt configurable.
  • Use a provider-neutral re-authentication mechanism such as prompt=login when account-selection support is unknown.

Additional context

Environment:

  • Windows 11 x64
  • PowerShell
  • Remote Streamable HTTP MCP server
  • OAuth Authorization Code flow with PKCE
  • Dynamic Client Registration
  • Non-Microsoft OpenID Connect provider

Temporary workaround: copy the generated authorization URL, remove &prompt=select_account, and open the modified URL while the Copilot CLI OAuth callback server is still running.

No credentials, tokens, or private authorization-server URLs are included in this report.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从通过 /mcp auth、MCP 服务器的 Authenticate 操作和 r 重新认证快捷方式进入的 OAuth 授权 URL 生成开始,跟踪 forceReauth 如何添加 prompt=select_account。检查授权服务器公布的 prompt_values_supported 元数据,并验证强制重新认证不再向非 Microsoft 提供商发送不受支持的 prompt,同时 OAuth 流程仍能成功完成。

由索引模型根据 Issue 内容生成。

评估

领域
authentication, cli
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
55/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。