Repository navigation
fix(server): use canonical OAuth health in MCP upstream list - #1525
Conversation
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Thank you @neylwalecki, this is an excellent fix and it's merged. You had it as a draft pending the CI lint lane; that lane (and the full suite) is green, so I marked it ready and merged it. What made it easy to land:
I also reviewed it with an independent second model; there were no defects, and the full CI suite passed on the merge with current Thanks again for this and for your earlier #1291 and #1057. Contributions like these make mcpproxy better for everyone. |
|
Glad to help ;-) |
An enabled OAuth upstream with a valid stored token reports
Connected / ready / usable=truethrough the CLI/runtime, butAuthentication required / sign_in_required / usable=falsethrough MCPupstream_servers/list.Reuse the runtime's canonical health projection for the MCP listing instead of reconstructing it without OAuth status and expiry metadata. Keep the existing server visibility filters, scrub health text at the MCP boundary, and preserve the connection-based fallback before runtime state is available. Authentication enforcement and tool search are unchanged.
Fixes #1522.
Validation
f2e58df3; 16 scenarios cover valid/missing/expired tokens, refresh metadata, OAuth failures, logout, 401 rejection, static-header auth, disabled/quarantined servers, redaction/scope, and absent runtime state.-race -count=3: pass.go vet ./internal/server/... ./internal/runtime/... ./internal/health/...: pass.server-everythingfixture. The global npm cache returned EACCES; its permissions and contents were preserved.internal/serverfails onlyTestProfileMiddleware_RefusalWorkIndependentOfFleet. The same flake reproduces on the clean, unmodified base in 4/15 isolated runs, tracked separately in [Bug]: Profile-gate allocation parity still flakes under race on Go 1.27/macOS #1523. No assertion was relaxed or skipped to hide it.The regression uses synthetic tokens,
.invalidendpoints and temporary storage. No installed proxy or real OAuth session was changed.