mcp: classify auth failures (HTTP + SSE) and guard OAuth credential deletion - #15536
Conversation
Contributor
Author
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
This was referenced Aug 25, 2026
Draft
mcp: re-mint expired managed proxy tokens on demand instead of failing or misrouting to OAuth
#15538
Draft
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
Auth failures were invisible to the code that needs to react to them:
WWW-Authenticate: Bearer error="invalid_token", error_description="proxy_token_expired"|"proxy_token_stale"), but nothing client-side parsed it.error_for_status(), discarding HTTP error bodies and challenges entirely, and its auto-reconnect retried forever at 1s — an expired-token SSE server got hammered indefinitely.command not found— unconditionally deleted the server's cached OAuth credentials, forcing interactive re-auth (source of the throttled report_error noise, see Throttle 'No template UUID found' report_error! to once per run #15498).Changes
mcp::error_classificationmodule:classify_service_error→AuthExpiredRecoverable(reason)/AuthRequiresUser/Transient/Fatal, digging through rmcp'sStreamableHttpErrorand both nestings of the fork'sSseTransportError(the OAuth path double-wraps).parse_www_authenticate_reasonrecognizes the proxy's re-mintable codes;downstream_auth_failedbodies classify as user-fixable.SseTransportError::HttpStatus { status, body (≤4KiB), www_authenticate }variant replaceserror_for_status(); GET-stream errors no longer silently map to a closed stream. Reconnects are bounded (exponential, max 6) and a 401/403 on reconnect terminates immediately instead of retrying.spawn_servernow returns a typedMcpSpawnErrordistinguishingAuthRequired { reason }from other failures (auth-context-missing and failed-OAuth flows populate it).AuthRequired { reason: None }) deletes cached credentials. Network/DNS/command failures and re-mintable proxy expiry never log the user out.Tests
cargo test -p mcp— axum-based tests assert the HttpStatus capture (status/body/challenge, bounded body), challenge parsing, classification of every class, nested-error unwrapping, bounded/fatal SSE retry behavior, and the credential-deletion predicate.