github / github/copilot-cli

CIMD declares callback port 33418 but Copilot CLI uses an ephemeral port

Aperta
#4,793 1 commento 2 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

triage
Lingua principale
Shell
Stelle
11.2k
Fork
1.9k
Merge medio
14h 16m
PR unite (30g)
6

Descrizione

Describe the bug

Copilot CLI’s Client ID Metadata Document declares a fixed loopback callback port, but the CLI sends a different ephemeral port in the OAuth authorization request.

Client metadata: https://github.com/copilot/cli/client-metadata.json

{
  "client_id": "https://github.com/copilot/cli/client-metadata.json",
  "application_type": "native",
  "redirect_uris": [
    "http://127.0.0.1:33418/"
  ]
}

The authorization request generated by Copilot CLI instead contains a callback such as:

  redirect_uri=http://127.0.0.1:60005/

My authorization server rejects the request with:

  unauthorized_client: Callback URL mismatch.
  http://127.0.0.1:60005/ is not in the list of allowed callback URLs
Affected version

GitHub Copilot CLI 1.0.83

Steps to reproduce the behavior
  1. Configure a remote MCP server protected by an Auth0 authorization server.
  2. Register Copilot CLI in Auth0 using: https://github.com/copilot/cli/client-metadata.json
  3. Add the remote MCP server to Copilot CLI.
  4. Start authentication.
  5. Inspect the generated /authorize request.

The request uses an ephemeral loopback port rather than the 33418 port declared in the metadata document.

Expected behavior

The redirect URI used by Copilot CLI should be compatible with its published metadata.

Either:

  1. Copilot CLI should bind to the declared callback:

      http://127.0.0.1:33418/
    
  2. The metadata should declare a portless loopback callback compatible with ephemeral ports:

      "redirect_uris": [
        "http://127.0.0.1/"
      ]
    

There should not be a requirement for every MCP server operator or Copilot user to configure a callback-port override.

Additional context
  • Operating system: macOS 26.5.1
  • MCP transport: Streamable HTTP
  • Authorization server: Auth0
  • Client registration: Client ID Metadata Document

For reference, Claude Code also uses an ephemeral loopback but its metadata document declares port-less loopback callbacks:

  "redirect_uris": [
    "http://localhost/callback",
    "http://127.0.0.1/callback"
  ]

The same Auth0 authorization server accepts Claude Code’s runtime callback while rejecting Copilot CLI’s callback because Copilot’s metadata explicitly pins port 33418.

Claude's metadata: https://claude.ai/oauth/claude-code-client-metadata

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia con il client-metadata.json pubblicato e il flusso di autorizzazione OAuth di Copilot CLI che genera la richiesta /authorize. Confronta l’URI di reindirizzamento dichiarata con il callback loopback a runtime e determina quale comportamento debba essere allineato; il lavoro è completato quando un authorization server accetta il callback senza un override della porta per utente.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Ambito
authentication, cli
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
58/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.