-
Notifications
You must be signed in to change notification settings - Fork 4k
Preserve empty URL paths on OAuth metadata models #2925
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+19
−3
Merged
Changes from 1 commit
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 Adding
url_preserve_empty_path=TruetoOAuthClientMetadatachanges the wire serialization ofredirect_uris, not just metadata parsing: a path-less redirect URI passed as a string (e.g.redirect_uris=['http://localhost:8080']) previously serialized ashttp://localhost:8080/but now keeps the empty path, and the client sends this value verbatim in the /authorize and token-exchange requests (oauth2.py:337, :393). A client that registered with the old SDK (registration persisted in TokenStorage, so no re-registration) will now send a redirect_uri that no longer exact-string-matches the one recorded at an RFC 6749-compliant authorization server, breaking a previously working flow. Consider scoping the flag toOAuthMetadata/ProtectedResourceMetadata(which is all the issuer-comparison goal needs) or calling out the redirect_uri implication in the migration note.Extended reasoning...
What the bug is. The PR's stated goal is to make
issuer/resource/authorization_serversround-trip as transmitted for RFC 9207 / RFC 8414 issuer comparison. But the flag is also applied toOAuthClientMetadata, where the comparison-sensitive field on the wire isredirect_uris— and that field's serialized form is exact-string-matched by an external party (the authorization server), persistently, across SDK upgrades.The PR's scope claim doesn't fully hold. The description says "URLs constructed in Python from an already-built
AnyHttpUrlobject are unchanged ... only values parsed from strings/JSON change." That is true for pre-builtAnyHttpUrlobjects, but the common way client metadata is constructed is with plain strings:OAuthClientMetadata(redirect_uris=['http://localhost:8080']). Verified on pydantic 2.12.5 (the repo's installed floor): withurl_preserve_empty_path=True, python-mode validation of that string now yields'http://localhost:8080'(andmodel_dump_jsonemits it without the slash), whereas before this PR it normalized to'http://localhost:8080/'. So user code that hasn't changed at all produces a different wire value after upgrading.The code path that puts it on the wire.
src/mcp/client/auth/oauth2.pysendsstr(self.context.client_metadata.redirect_uris[0])directly in both the authorization request (oauth2.py:337) and the token-exchange request (oauth2.py:393), and the DCR registration body is serialized from this same model. Nothing re-normalizes the URI before transmission.Step-by-step regression scenario.
OAuthClientMetadata(redirect_uris=['http://localhost:8080'])and performs dynamic client registration. The registration request carries"redirect_uris": ["http://localhost:8080/"](old normalization), so the AS records exactly that string. The resultingclient_id/client info is persisted inTokenStorage— the SDK's normal mode of operation — so no re-registration happens later.redirect_uris[0]now serializes ashttp://localhost:8080(no trailing slash).redirect_uri=http://localhost:8080in the /authorize request (oauth2.py:337). RFC 6749 §3.1.2.3 requires the AS to compare redirect URIs using simple string comparison, so a spec-compliant external AS rejects the request withinvalid_redirect_uri— a hard, confusing auth failure for a flow that worked before the upgrade, until the user clears stored client info and re-registers.Why nothing else prevents it. The SDK's own server-side
AuthorizationHandleris not affected, because pydanticAnyUrlequality treatshttp://localhost:8080andhttp://localhost:8080/as equal (verified), sovalidate_redirect_uristill matches. The breakage is specifically against third-party authorization servers doing the RFC-mandated literal string match on the transmitted value, where pydantic equality is irrelevant. Neither the migration note nor the PR description mentions thatOAuthClientMetadata.redirect_urisoutput changes on the wire.Mitigating factors and how to fix. The trigger is fairly narrow: it requires a path-less redirect URI (uncommon — the SDK examples use
/callback), a DCR registration persisted across the upgrade, and an AS that does strict string matching; recovery is re-registering. Still, the fix is cheap: scopeurl_preserve_empty_path=TruetoOAuthMetadataandProtectedResourceMetadataonly (which is everything the issuer-comparison goal and #2921 need), or — if the new behavior onOAuthClientMetadatais intentional — explicitly document the redirect_uri wire-format change in the migration note so users with persisted registrations know to re-register.