Skip to content

Explain OAuth client scope consent errors - #2638

Draft
niemyjski wants to merge 3 commits into
mainfrom
issue/oauth-consent-scope-errors
Draft

niemyjski wants to merge 3 commits into
mainfrom
issue/oauth-consent-scope-errors

Conversation

@niemyjski

@niemyjski niemyjski commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

MCP consent discarded OAuth error descriptions from HTTP 400 responses because FetchClient puts non-success JSON in problem, leaving the page with a generic error. Show the actual description on consent and approval, name only known disallowed scopes with administrator/restart guidance, and make the fallback match the server's optional offline access. A new authorization query now requires fresh validated consent details and ignores obsolete consent responses.

Document scope meanings, how global administrators find and edit dynamically registered applications, and why enabling client scopes requires fresh consent to expand a grant. Registration defaults and permission enforcement remain unchanged.

Closes #2615.

Verification:

  • Original component/browser behavior and scope descriptions fail the added regressions; the fixed behavior passes.

  • Backend build passes with no warnings; 18 focused scope/role cases pass.

  • All 1,021 frontend unit tests, npm run validate, and production build pass.

  • Local Chromium consent journey passes without retries, including real FetchClient HTTP 400 handling, restart, query navigation, and overlapping responses. Its HTTP endpoints are isolated test responses.

  • Independent adversarial review of final head 742e70eeecaabf8c293511ea74ae12de46bedc04: no blocking findings.

  • Exact-head Build CI passes. Downloaded TRX artifacts confirm all 82 OAuth endpoint cases, 13 admin application endpoint cases, four OpenAPI cases, and 18 scope/identity cases passed. All backend shards total 3,152 passed / three unrelated skipped. All 118 browser tests and 1,021 frontend unit tests pass; no browser retries.

  • New live browser journey passes on its first attempt in 10.9 seconds against existing hosted services, with no response interception: ordinary-member edit denial, actual scope error, allowed-subset access-only grant, administrator form save, same-client restarted consent, PKCE exchange and refresh rotation. It owns and cleans up synthetic data and adds no infrastructure or workflow changes.

The reporter's original dynamic registration payload is unknown. Local Docker remains unhealthy; hosted service and live browser evidence closes the verification gate. No unchanged reruns or deployment were triggered.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

Code Coverage

Package Line Rate Branch Rate Complexity Health
Exceptionless.AppHost 23% 23% 128 ❌
Exceptionless.Core 77% 68% 10827 ✔
Exceptionless.Insulation 51% 43% 370 ➖
Exceptionless.Web 86% 70% 9173 ✔
Summary 80% (27827 / 34878) 69% (13762 / 20068) 20498 ✔

@niemyjski niemyjski mentioned this pull request Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP authorisation

1 participant