mirror of
https://github.com/davidkaya/aryx.git
synced 2026-07-28 23:48:39 +02:00
fix: try both RFC 9728 and appended well-known URL paths for MCP OAuth discovery
Some MCP servers place .well-known metadata at the appended path (e.g. /v1/.well-known/oauth-protected-resource) instead of the RFC 9728 compliant inserted path. Now tries the RFC-compliant URL first and falls back to the appended form. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
import { describe, expect, test } from 'bun:test';
|
||||
|
||||
import { buildWellKnownUrl } from '@main/services/mcpTokenStore';
|
||||
import { buildWellKnownUrl, buildWellKnownUrlFallback } from '@main/services/mcpTokenStore';
|
||||
|
||||
describe('buildWellKnownUrl', () => {
|
||||
test('inserts well-known segment after origin for URL with path', () => {
|
||||
@@ -33,3 +33,20 @@ describe('buildWellKnownUrl', () => {
|
||||
.toBe('https://example.com/.well-known/oauth-protected-resource/mcp');
|
||||
});
|
||||
});
|
||||
|
||||
describe('buildWellKnownUrlFallback', () => {
|
||||
test('appends well-known segment to the full URL path', () => {
|
||||
expect(buildWellKnownUrlFallback('https://icm-mcp-prod.azure-api.net/v1/', 'oauth-protected-resource'))
|
||||
.toBe('https://icm-mcp-prod.azure-api.net/v1/.well-known/oauth-protected-resource');
|
||||
});
|
||||
|
||||
test('handles URL without trailing slash', () => {
|
||||
expect(buildWellKnownUrlFallback('https://example.com/mcp', 'oauth-protected-resource'))
|
||||
.toBe('https://example.com/mcp/.well-known/oauth-protected-resource');
|
||||
});
|
||||
|
||||
test('handles origin-only URL', () => {
|
||||
expect(buildWellKnownUrlFallback('https://auth.example.com/', 'oauth-authorization-server'))
|
||||
.toBe('https://auth.example.com/.well-known/oauth-authorization-server');
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user