YeonGyu-Kim
dcda8769cc
feat(mcp-oauth): add full OAuth 2.1 authentication for MCP servers ( #1169 )
...
* feat(mcp-oauth): add oauth field to ClaudeCodeMcpServer schema
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-opencode )
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
* feat(mcp-oauth): add RFC 7591 Dynamic Client Registration
* feat(mcp-oauth): add RFC 9728 PRM + RFC 8414 AS discovery
* feat(mcp-oauth): add secure token storage with {host}/{resource} key format
* feat(mcp-oauth): add dynamic port OAuth callback server
* feat(mcp-oauth): add RFC 8707 Resource Indicators
* feat(mcp-oauth): implement full-spec McpOAuthProvider
* feat(mcp-oauth): add step-up authorization handler
* feat(mcp-oauth): integrate authProvider into SkillMcpManager
* feat(doctor): add MCP OAuth token status check
* feat(cli): add mcp oauth subcommand structure
* feat(cli): implement mcp oauth login command
* fix(mcp-oauth): address cubic review — security, correctness, and test issues
- Remove @ts-nocheck from provider.ts, storage.ts, provider.test.ts
- Fix server resource leak on missing code/state (close + reject)
- Fix command injection in openBrowser (spawn array args, cross-platform)
- Mock McpOAuthProvider in login.test.ts for deterministic CI
- Recreate auth provider with merged scopes in step-up flow
- Add listAllTokens() for global status listing
- Fix logout to accept --server-url for correct token deletion
- Support both quoted and unquoted WWW-Authenticate params (RFC 2617)
- Save/restore OPENCODE_CONFIG_DIR in storage.test.ts
- Fix index.test.ts: vitest → bun:test
* fix(mcp-oauth): use explorer instead of cmd /c start on Windows to prevent shell injection
* fix(mcp-oauth): address remaining cubic review issues
- Add 5-minute timeout to provider callback server to prevent indefinite hangs
- Persist client registration from token storage across process restarts
- Require --server-url for logout to match token storage key format
- Use listTokensByHost for server-specific status lookups
- Fix callback-server test to handle promise rejection ordering
- Fix provider test port expectations (8912 → 19877)
- Fix cli-guide.md duplicate Section 7 numbering
- Fix manager test for login-on-missing-tokens behavior
* fix(mcp-oauth): address final review issues
- P1: Redact token values in status.ts output to prevent credential leakage
- P2: Read OAuth error response body before throwing in token exchange
- Test: Fix mcp-oauth doctor test to use epoch seconds (not milliseconds)
---------
Co-authored-by: justsisyphus <justsisyphus@users.noreply.github.com >
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-01-29 19:48:36 +09:00
justsisyphus
c433e7397e
feat(skill-mcp): add auto-reconnect retry on "Not connected" errors
...
- Added withOperationRetry<T>() helper method that retries operations up to 3 times
- Catches "Not connected" errors (case-insensitive)
- Cleans up stale client before retry
- Modified callTool, readResource, getPrompt to use retry logic
- Added tests for retry behavior (3 new test cases)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai >
2026-01-17 18:14:48 +09:00
stranger2904
951df07c0f
fix: correct test syntax for headers verification
...
Fix syntax error where expect().rejects.toThrow() was not properly closed
before the headers assertion.
2026-01-14 15:10:45 -05:00
stranger2904
c9ef648c60
test: mock StreamableHTTPClientTransport for faster, deterministic tests
...
Add mocks for HTTP transport to avoid real network calls during tests.
This addresses reviewer feedback about test reliability:
- Tests are now faster (no network latency)
- Tests are deterministic across environments
- Test intent is clearer (unit testing error handling logic)
The mock throws immediately with a controlled error message,
allowing tests to validate error handling without network dependencies.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-14 15:01:10 -05:00
stranger2904
570b51d07b
feat(skill-mcp): add HTTP transport support for remote MCP servers
...
Add support for connecting to remote MCP servers via HTTP in addition to
the existing stdio (local process) connections. This enables skills to
use cloud-hosted MCP servers and aggregated MCP gateways.
## Changes
- Extend SkillMcpManager to detect connection type from config:
- Explicit `type: "http"` or `type: "sse"` → HTTP connection
- Explicit `type: "stdio"` → stdio connection
- Infer from `url` field → HTTP connection
- Infer from `command` field → stdio connection
- Add StreamableHTTPClientTransport from MCP SDK for HTTP connections
- Supports custom headers for authentication (e.g., API keys)
- Proper error handling with helpful hints
- Maintain full backward compatibility with existing stdio configurations
## Usage
```yaml
# HTTP connection (new)
mcp:
remote-server:
url: https://mcp.example.com/mcp
headers:
Authorization: Bearer ${API_KEY}
# stdio connection (existing, unchanged)
mcp:
local-server:
command: npx
args: [-y, @some/mcp-server]
```
## Tests
Added comprehensive tests for:
- Connection type detection (explicit type vs inferred)
- HTTP URL validation and error messages
- Headers configuration
- Backward compatibility with stdio configs
2026-01-14 11:35:32 -05:00
YeonGyu-Kim
a51ad98182
fix(skill-mcp): always inherit process.env for MCP servers
...
- Always merge parent process.env when spawning MCP child processes
- Overlay config.env on top if present (for skill-specific overrides)
- Fixes issue where skills without explicit env: block started with zero environment variables
- Adds 2 tests for env inheritance behavior
🤖 Generated with assistance of OhMyOpenCode (https://github.com/code-yeongyu/oh-my-opencode )
2026-01-02 16:07:33 +09:00
YeonGyu-Kim
06dee7248b
feat(skill-mcp): add MCP client manager with lazy loading and session cleanup
...
🤖 GENERATED WITH ASSISTANCE OF [OhMyOpenCode](https://github.com/code-yeongyu/oh-my-opencode )
2026-01-01 23:02:43 +09:00