Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
MCP consent discarded OAuth error descriptions from HTTP 400 responses because FetchClient puts non-success JSON in
problem, leaving the page with a generic error. Show the actual description on consent and approval, name only known disallowed scopes with administrator/restart guidance, and make the fallback match the server's optional offline access. A new authorization query now requires fresh validated consent details and ignores obsolete consent responses.Document scope meanings, how global administrators find and edit dynamically registered applications, and why enabling client scopes requires fresh consent to expand a grant. Registration defaults and permission enforcement remain unchanged.
Closes #2615.
Verification:
Original component/browser behavior and scope descriptions fail the added regressions; the fixed behavior passes.
Backend build passes with no warnings; 18 focused scope/role cases pass.
All 1,021 frontend unit tests,
npm run validate, and production build pass.Local Chromium consent journey passes without retries, including real FetchClient HTTP 400 handling, restart, query navigation, and overlapping responses. Its HTTP endpoints are isolated test responses.
Independent adversarial review of final head
742e70eeecaabf8c293511ea74ae12de46bedc04: no blocking findings.Exact-head Build CI passes. Downloaded TRX artifacts confirm all 82 OAuth endpoint cases, 13 admin application endpoint cases, four OpenAPI cases, and 18 scope/identity cases passed. All backend shards total 3,152 passed / three unrelated skipped. All 118 browser tests and 1,021 frontend unit tests pass; no browser retries.
New live browser journey passes on its first attempt in 10.9 seconds against existing hosted services, with no response interception: ordinary-member edit denial, actual scope error, allowed-subset access-only grant, administrator form save, same-client restarted consent, PKCE exchange and refresh rotation. It owns and cleans up synthetic data and adds no infrastructure or workflow changes.
The reporter's original dynamic registration payload is unknown. Local Docker remains unhealthy; hosted service and live browser evidence closes the verification gate. No unchanged reruns or deployment were triggered.