WorkIQ OAuth callback returns 404 only when Copilot CLI runs in WSL
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Shell
- Estrellas
- 11.2k
- Forks
- 1.9k
- Merge medio
- 14 h 16 min
- PR fusionados (30 d)
- 6
Descripción
Describe the bug
Summary
WorkIQ authentication fails when GitHub Copilot CLI runs inside WSL2.
The same WorkIQ authentication flow succeeds when GitHub Copilot CLI runs natively on Windows. The failure occurs only when Copilot CLI runs inside WSL2.
After completing Microsoft Entra sign-in, the loopback callback includes valid code and state parameters but returns 404 Not Found.
Environment
- GitHub Copilot CLI:
1.0.80 - WorkIQ plugin:
2.0.0 - WSL:
2.7.1.11 - Kernel:
6.1.18.3-2 - Windows:
10.0.26200.9106 - Ubuntu:
26.04
Steps to reproduce
-
Run
copilotinside WSL. -
Enable the WorkIQ plugin.
-
Trigger a WorkIQ tool call, causing authentication to start.
-
Open the Microsoft Entra authorization URL displayed by Copilot and complete sign-in.
-
The browser redirects to:
text http://127.0.0.1:12798/?code=...&state=...
Actual behavior
The callback URL returns:
HTTP/1.1 404 Not Found
Content-Type: text/plain
Not Found
Additional observations:
• The callback includes both code and state .
• The callback is reachable from Windows and WSL.
• ss -ltnp 'sport = :12798' shows that copilot itself owns 127.0.0.1:12798 .
• Calling the complete callback URL from WSL with curl also returns 404 Not Found .
• Restarting Copilot and shutting down WSL do not resolve the issue.
• Clearing the persisted WorkIQ OAuth configuration/cache does not change the behavior.
Expected behavior
When running under WSL2, Copilot CLI should handle the WorkIQ OAuth callback as it does when running natively on Windows: associate the valid code and state with the pending OAuth transaction and exchange the authorization code successfully.
Related context
This may be related to WSL support in microsoft/work-iq#15 , but differs from callback-reachability issues: here the loopback callback is reachable and handled by the Copilot process itself, which returns 404 .
Affected version
No response
Steps to reproduce the behavior
-
Run
copilotinside WSL. -
Enable the WorkIQ plugin.
-
Trigger a WorkIQ tool call, causing authentication to start.
-
Open the Microsoft Entra authorization URL displayed by Copilot and complete sign-in.
-
The browser redirects to:
Actual behavior
The callback URL returns:
HTTP/1.1 404 Not Found
Content-Type: text/plain
Not Found
Expected behavior
When running under WSL2, Copilot CLI should handle the WorkIQ OAuth callback as it does when running natively on Windows: associate the valid code and state with the pending OAuth transaction and exchange the authorization code successfully.
Additional context
This may be related to WSL support in https://github.com/microsoft/work-iq/issues/15 , but differs from callback-reachability issues: here the loopback callback is reachable and handled by the Copilot process itself, which returns 404 .
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Comienza con el callback de WorkIQ OAuth en http://127.0.0.1:12798/ y reproduce el flujo de Copilot CLI dentro de WSL2, usando curl y ss tal como se describe. Compara el manejo del callback con el flujo nativo de Windows y verifica que los parámetros code y state válidos estén asociados con la transacción pendiente, que el authorization code se intercambie y que el callback ya no devuelva 404.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- linux, shell, ubuntu
- Área
- authentication, cli, operating-systems
- Tipo de issue
- Error
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Activo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 52/100