Desktop app 1.1.17: COPILOT_ENTRA_AUTH_AUD (EMU audience) breaks MCP Entra sign-in with ENTRA_CONFIG 2002 - CLI on the same machine works
まだ誰も着手していません。
- 主要言語
- Shell
- スター
- 11.2k
- フォーク
- 1.9k
- 平均マージ
- 14時間 16分
- マージ済み PR(30日)
- 6
説明
Describe the bug
Environment
| Item | Detail |
|---|---|
| Failing | GitHub Copilot desktop app 1.1.17, Windows |
| Bundled CLI runtime | 1.0.83 (resources/copilot-sdk/cliVersion.d.ts) |
| Machine | Windows 11, Entra-joined, GitHub EMU configured |
| Working | @github/copilot CLI on the same machine, same variable set |
| Working | Desktop app 1.1.17 on macOS, that build contains no OneAuth code path |
| Related | #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing) |
The bug
Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:
COPILOT_ENTRA_AUTH_AUD = "some-value"
= "GitHub Enterprise Managed User (OIDC)" (GitHub's tenant)
It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:
Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
- Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"
Sign-in then succeeds immediately.
-
The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.
-
macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.
Steps to reproduce
- Windows machine with
COPILOT_ENTRA_AUTH_AUDset machine-wide (any EMU-configured device). - Add an Entra-protected MCP server whose API lives in a different tenant.
- Sign in from the MCP tab. Fails 100%.
- Same server, same machine, via the CLI. Succeeds.
Expected behavior
MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
まず、resources/copilot-sdk/cliVersion.d.ts にあるデスクトップアプリのバンドル済み CLI ランタイムを、Windows で動作する @github/copilot CLI の挙動と比較します。COPILOT_ENTRA_AUTH_AUD を設定した状態で MCP サインインを再現し、次にそれを削除した状態、さらに COPILOT_ENTRA_DISABLE_ONEAUTH=1 を設定した状態で再現します。MCP サインインが Copilot の audience を無視し、ENTRA_CONFIG による拒否の後にブラウザーへフォールバックすれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github
- 領域
- authentication, cli, desktop-dev
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 48/100