github / github/copilot-cli

Google Workspace MCP OAuth fails on accounts.google.com trailing-slash issuer mismatch

未关闭
#4,606 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

area:authentication area:mcp
主要语言
Shell
星标
11.2k
派生
1.9k
平均合并
14 小时 16 分钟
30 天内合并 PR
6

描述

Describe the bug

Native HTTP MCP authentication fails for Google's official Workspace MCP
endpoints before the browser authorization flow begins.

The protected-resource metadata advertises this authorization server:

https://accounts.google.com/

Google's authorization-server/OpenID metadata advertises this issuer:

https://accounts.google.com

These URLs differ only by the trailing slash on the origin root, but Copilot CLI
compares them literally and rejects the server:

OAuth authentication failed for google-calendar: MCPOAuthError:
Incompatible authorization server: authorization server advertised an issuer
that does not match the URL its metadata was discovered from (RFC 8414 §3.3);
refusing to connect

This affects all seven currently documented Google Workspace MCP endpoints:

  • Calendar: https://calendarmcp.googleapis.com/mcp/v1
  • Gmail: https://gmailmcp.googleapis.com/mcp/v1
  • Drive: https://drivemcp.googleapis.com/mcp/v1
  • People: https://people.googleapis.com/mcp/v1
  • Docs: https://docsmcp.googleapis.com/mcp/v1
  • Slides: https://slidesmcp.googleapis.com/mcp/v1
  • Sheets: https://sheetsmcp.googleapis.com/mcp/v1

Each endpoint's protected-resource metadata currently returns:

{
  "resource": "<the MCP endpoint>",
  "authorization_servers": ["https://accounts.google.com/"]
}

Google's public metadata returns:

GET https://accounts.google.com/.well-known/openid-configuration
{
  "issuer": "https://accounts.google.com"
}
Affected version
GitHub Copilot CLI 1.0.81-10
Steps to reproduce the behavior
  1. Register the localhost OAuth redirect URI required by Google and configure
    Calendar as a native HTTP MCP server (credentials redacted):

    {
      "mcpServers": {
        "google-calendar": {
          "type": "http",
          "url": "https://calendarmcp.googleapis.com/mcp/v1",
          "oauthClientId": "<redacted>",
          "auth": {
            "clientSecret": "<redacted>",
            "redirectPort": 8080
          }
        }
      }
    }
    
  2. Start Copilot CLI.

  3. Run /mcp auth google-calendar.

  4. Authentication fails with the RFC 8414 issuer-mismatch error above. The
    browser consent flow never starts.

The same behavior occurs with the other Google Workspace MCP endpoints.

Expected behavior

Copilot CLI should be able to authenticate with Google's official Workspace MCP
endpoints.

Ideally, the implementation would preserve strict issuer validation while
canonicalizing only semantically equivalent origin-root URLs before selecting
the discovery issuer (or otherwise handling the empty-path/trailing-slash
equivalence safely). If that is not acceptable under the CLI's RFC 8414
validation policy, the error should identify the two compared values and
provide an actionable, narrowly scoped compatibility option.

Additional context
  • OS: macOS 26.6
  • Architecture: Apple Silicon (arm64)
  • Terminal: iTerm2
  • Shell: zsh

A pinned mcp-remote@0.2.4 stdio proxy using the same endpoint, OAuth client,
redirect URI, and Google account completes the OAuth flow successfully and can
call the Google tools. This confirms the client registration, consent, token
exchange, scopes, and MCP endpoints are functional; the failure is specific to
Copilot CLI's native HTTP MCP OAuth discovery/issuer validation.

Related reports:

  • #4480 covers an Atlassian hostname mismatch.
  • #4439 covers malformed GitLab protected-resource metadata and fallback
    discovery.

This Google case is distinct: the protected-resource metadata uses the
RFC 9728 resource string and authorization_servers array correctly, and the
issuer differs only by a trailing slash at the authorization server's root.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

首先,使用文档中的 Calendar MCP endpoint 重现 /mcp auth google-calendar,并检查原生 HTTP MCP OAuth discovery 和 issuer 验证路径。将受保护资源的授权服务器 URL 与发现的 issuer 进行比较,然后验证 Google 的 endpoints 是否能够成功完成身份验证,同时不削弱通用的 issuer 验证;如果存在兼容性失败,则应明确报告这两个值。

由索引模型根据 Issue 内容生成。

评估

领域
api, authentication, cli
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。