fix: restore MCP OAuth registration and authorization (#3421)

* fix: align MCP OAuth provider schema and authorization flow

* test: isolate OpenAPI generation from OAuth initialization

* fix: accept auth routes without a callback query

* fix: require explicit OAuth consent and preserve signed requests

* test: verify OAuth audiences through real MCP initialization

* test(e2e): isolate OAuth token audience validation
This commit is contained in:
Amruth Pillai
2026-09-05 09:33:15 -07:00
committed by GitHub
parent bf71253ca4
commit fe9b59e111
35 changed files with 7837 additions and 144 deletions
+9 -3
View File
@@ -118,9 +118,9 @@ Reactive Resume is configured as an OAuth authorization server for MCP clients:
- The MCP endpoint is `https://rxresu.me/mcp`.
- OAuth discovery metadata is exposed under `/.well-known/*` endpoints.
- The login/authorization route is `/auth/oauth`.
- If the user is not signed in, `/auth/oauth` redirects to `/auth/login`, then resumes OAuth.
- If the user is signed in, `/auth/oauth` validates `client_id` and `redirect_uri`, issues an authorization code, and redirects back to the client.
- The login/authorization route is `/api/auth/oauth`.
- If the user is not signed in, `/api/auth/oauth` redirects to `/auth/login`, then resumes OAuth.
- If the user is signed in, `/api/auth/oauth` uses the OAuth provider to validate the signed request, registered redirect URI, scopes, resource grants, and PKCE before issuing an authorization code, and redirects back to the client.
- PKCE parameters (`code_challenge`, `code_challenge_method`) are preserved in the authorization flow.
## Popular client setup
@@ -205,6 +205,12 @@ If you're running a self-hosted Reactive Resume instance, replace `https://rxres
}
```
### Reconnecting after the OAuth provider upgrade
Self-hosted instances automatically apply the additive OAuth schema migration at startup. This preserves existing client and token records and adds the provider's resource and client-resource tables.
Clients registered before OAuth provider 1.7 do not have per-resource grants. Remove the old connection from your MCP client and add it again so it dynamically registers a new client, then sign in again. Refreshing an existing token does not create these grants. New registrations receive only the resources configured for this instance; existing clients are not automatically granted access.
## Available tools
Tool names use canonical unprefixed `snake_case` names.