fix(client/auth): preserve an authorization endpoint's existing query parameters - #3567
dgilman-perplexity wants to merge 1 commit into
Conversation
… parameters
RFC 6749 §3.1 allows the authorization endpoint URI to carry a query
component. The client built the authorization URL with a bare
f"{endpoint}?{params}", producing a second "?" and a broken URL for
any discovered authorization_endpoint that already has one (e.g.
Salesforce's "...?prompt=select_account").
Merge the flow's parameters into the endpoint's existing query instead.
Fixes modelcontextprotocol#3505, fixes modelcontextprotocol#2776.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
This PR has been closed automatically. It's still a draft, but we close those early so you don't put in more time only to have it closed the moment you mark it ready. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3505, #2776. If a maintainer assigns you to #3505, #2776, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take. You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
Fixes #3505, fixes #2776.
Motivation
RFC 6749 §3.1 allows the authorization endpoint URI to include a query component, but the client builds the authorization URL with a bare
f"{endpoint}?{params}". Any discoveredauthorization_endpointthat already carries a query (e.g. Salesforce's...?prompt=select_account) gets a second?and a broken URL. We hit this in production and currently work around it with a subclass override.Change
_perform_authorization_code_grantnow builds the URL through a_build_authorization_urlhelper that merges the flow's parameters into the endpoint's existing query (parse_qsl/urlunparse, blank values preserved). Regression test included; it fails onmainand passes with the fix.#2779 takes the same approach but predates the httpx2 rename and no longer applies cleanly to
main.🤖 Generated with Claude Code