Skip to content

Preserve OAuth resource path during scope discovery - #1618

Closed
blakewang-atlassian wants to merge 1 commit into
modelcontextprotocol:v1/mainfrom
blakewang-atlassian:bwang7/preserve-oauth-resource-path
Closed

Preserve OAuth resource path during scope discovery#1618
blakewang-atlassian wants to merge 1 commit into
modelcontextprotocol:v1/mainfrom
blakewang-atlassian:bwang7/preserve-oauth-resource-path

Conversation

@blakewang-atlassian

Copy link
Copy Markdown

Summary

  • Preserve the full MCP server URL when discovering OAuth protected resource metadata
  • Add a regression test for path-based MCP endpoints such as /v1/mcp/preview

Why

Some MCP servers expose different protected resource metadata per path. Discovering metadata from the origin URL drops the endpoint path and can cause Inspector to request scopes for the wrong resource.

Test plan

  • npm test -- --runTestsByPath src/lib/hooks/tests/useConnection.test.tsx
  • npx prettier --check client/src/lib/hooks/useConnection.ts client/src/lib/hooks/tests/useConnection.test.tsx
  • git diff --check

@cliffhall
cliffhall changed the base branch from main to v1/main July 28, 2026 03:04
@cliffhall

cliffhall commented Jul 31, 2026

Copy link
Copy Markdown
Member

Closing: v1 is deprecated.

Thank you for this contribution, and apologies for the long wait for a response.

v1 will receive security fixes only. We reviewed every open v1 PR for security impact before closing — see the backlog triage in #1819 — and a small number were retained for a final 1.0.5 patch release. This one is a functionality, compatibility, or cleanup change rather than a vulnerability fix, so it is being closed unmerged. This is not a judgment on the quality of the work — it's a consequence of the branch it targets being frozen.

If the underlying problem still exists in v2, we'd genuinely like to know. Please open an issue describing it against v2. Note that we accept external contributions as issues rather than pull requests — maintainers handle design and implementation through a prompt-driven workflow. See CONTRIBUTORS.md.

Thanks again for taking the time to contribute to the Inspector.

@cliffhall cliffhall closed this Jul 31, 2026
@cliffhall cliffhall added the closed-v1-deprecated Closed: v1 is deprecated and accepting security fixes only label Jul 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

closed-v1-deprecated Closed: v1 is deprecated and accepting security fixes only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants