Skip to content

fix(auth): forward user-agent to oauth flow requests - #2077

Closed
mrutunjay-kinagi wants to merge 5 commits into
modelcontextprotocol:mainfrom
mrutunjay-kinagi:fix-1664-forward-user-agent-auth-flow
Closed

mrutunjay-kinagi wants to merge 5 commits into
modelcontextprotocol:mainfrom
mrutunjay-kinagi:fix-1664-forward-user-agent-auth-flow

Conversation

@mrutunjay-kinagi

Copy link
Copy Markdown

Summary

  • forward caller User-Agent from the original MCP request into OAuth flow sub-requests
  • apply forwarding to PRM discovery, auth server metadata discovery, dynamic client registration, and token exchange/refresh requests
  • add regression coverage ensuring forwarded User-Agent is preserved throughout the 401 -> OAuth handshake path

Why

Fixes missing User-Agent propagation in Streamable HTTP auth flow requests, which can break environments that enforce WAF rules requiring User-Agent headers.

Closes #1664

Validation

  • pytest -q tests/client/test_auth.py -k "forwards_user_agent or auth_flow_with_no_tokens"
  • ruff check src/mcp/client/auth/oauth2.py tests/client/test_auth.py
  • ruff format --check src/mcp/client/auth/oauth2.py tests/client/test_auth.py

@mrutunjay-kinagi

Copy link
Copy Markdown
Author

Thanks for sharing this run.

I pushed a follow-up commit (40f173f) to address the failure pattern shown there:

  • removed a stale # pragma: no cover on tests/client/test_auth.py:48 that is now exercised by the new auth-flow test.

That was what caused Linux matrix failures in that run under strict-no-cover.

@mrutunjay-kinagi

mrutunjay-kinagi commented Feb 18, 2026 •

Copy link
Copy Markdown
Author

Follow-up commit 40f173f addressed the previous Linux strict-no-cover failure, and all checks are now green.

@Kludex Ready for review Thanks!

@mrutunjay-kinagi

Copy link
Copy Markdown
Author

Follow-up on CI run https://github.com/modelcontextprotocol/python-sdk/actions/runs/22261553587 (job 64400559254):\n\n- Only checks / test (3.13, locked, windows-latest) failed.\n- Failure appears unrelated/flaky (not in auth-flow code path):\n - tests/client/test_stdio.py::TestChildProcessCleanup::test_early_parent_exit (AssertionError: Child should be writing)\n - tests/client/transports/test_memory.py::test_raise_exceptions\n- Workflow conclusion is success and all-green passed, but this stale failed check remains visible.\n\nI don't have permission to rerun upstream Actions jobs from CLI. If needed, a maintainer rerun of the failed job should clear this.

@maxisbey maxisbey added bug Something isn't working auth Issues and PRs related to Authentication / OAuth P2 Moderate issues affecting some users, edge cases, potentially valuable feature labels Mar 5, 2026
@mrutunjay-kinagi

mrutunjay-kinagi commented Mar 24, 2026 •

Copy link
Copy Markdown
Author

@maxisbey : Please take a look at the PR let me know of what do you think ?

@mrutunjay-kinagi

Copy link
Copy Markdown
Author

@Kludex @maxisbey Please take a look at this PR.

@maxisbey

maxisbey commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Thanks for the PR, and sorry it sat here without a proper review.

We're closing most of the open PR backlog. v2 is out and changed a lot of the SDK, so many older PRs no longer apply as written, and we're a small team that realistically doesn't have the capacity to work through the rest.

If this still matters to you on v2, the most useful thing you can do is open an issue (or comment on the existing one) with your use case and a repro. Hearing why it matters to you is what we use to decide what to prioritise.

AI Disclaimer

@maxisbey maxisbey closed this Oct 5, 2026
@maxisbey maxisbey added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auth Issues and PRs related to Authentication / OAuth bug Something isn't working missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) P2 Moderate issues affecting some users, edge cases, potentially valuable feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User-Agent header in sHTTP transport is not forwarded to auth flow

2 participants