Repository navigation
Commit fb5548e
authored
Name stdio MCP OAuth clients and isolate auth caches (#268)
## Summary
- Set the OAuth client name for each stdio MCP target, including Goose's
printed YAML.
- Give each target a separate mcp-remote auth cache and callback port so
clients can authorize independently and do not share a client identity.
Preserve existing explicit callback ports.
- Preserve existing environment settings, mcp-remote options, and other
OAuth metadata fields. Reject external metadata files with a clear error
instead of changing them.
- Include Goose's required enabled field in the printed config.
## Validation
- Extended install tests for client names, cache isolation, distinct
callback ports, preserved explicit ports, existing metadata and
environment settings, malformed settings, duplicate OAuth metadata, and
repeated installs.
- Built the CLI and parsed the printed Goose config as YAML, including
its enabled flag, string callback-port argument, metadata, and cache
path.
- Verified all five generated stdio configs can hold independent
callback listeners simultaneously using mcp-remote 0.14.3. Verified
earlier configs without a port upgrade correctly.
- Live desktop OAuth flows were not exercised.
## Rollout
Existing stdio installs will prompt for authorization again when the new
per-client cache is used. A custom nonempty MCP_REMOTE_CONFIG_DIR
remains in place and may require manual cache cleanup. Existing explicit
callback ports remain in place; custom ports must be distinct across
clients. Existing shared cache files are left untouched because other
MCP clients may use them.
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Medium Risk**
> Changes how stdio MCP OAuth is configured and where tokens are stored,
which can force re-authorization and affect users with custom ports or
metadata; install remains conservative on invalid or external metadata.
>
> **Overview**
> Stdio MCP installs now generate **per-target** `mcp-remote`
invocations with a dedicated OAuth **client name**, **callback port**
(46093–46097), and **`MCP_REMOTE_CONFIG_DIR`** under
`~/.mcp-auth/kernel-<target>` so multiple editors can authorize
independently without sharing identity or cache.
>
> Install merge logic was reworked: default args come from
`stdioArgs(spec)` instead of per-target `stdioArgs` slices; existing
`args` keep custom flags/versions while upgrading URL, inserting a port
when missing, and merging `--static-oauth-client-metadata` (other JSON
fields preserved; external `@` metadata files fail with a clear error).
Non-empty custom cache paths are left alone; empty cache values are
replaced.
>
> **Goose** printed YAML now includes `enabled: true`, the same stdio
args/env as JSON targets, via a new `gooseConfig` helper;
`gopkg.in/yaml.v3` is a direct dependency for parsing that output in
tests.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
9039534. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
---------
Co-authored-by: Sayan- <1415138+Sayan-@users.noreply.github.com>1 parent f22b917 commit fb5548e
5 files changed
Lines changed: 384 additions & 60 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
10 | 11 | | |
11 | 12 | | |
12 | 13 | | |
| |||
29 | 30 | | |
30 | 31 | | |
31 | 32 | | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
43 | 45 | | |
44 | 46 | | |
45 | 47 | | |
| |||
80 | 82 | | |
81 | 83 | | |
82 | 84 | | |
83 | | - | |
| 85 | + | |
84 | 86 | | |
85 | 87 | | |
86 | | - | |
87 | | - | |
88 | | - | |
| 88 | + | |
| 89 | + | |
89 | 90 | | |
90 | 91 | | |
91 | 92 | | |
92 | | - | |
| 93 | + | |
93 | 94 | | |
94 | | - | |
| 95 | + | |
95 | 96 | | |
96 | 97 | | |
97 | 98 | | |
| |||
126 | 127 | | |
127 | 128 | | |
128 | 129 | | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
129 | 138 | | |
130 | 139 | | |
131 | 140 | | |
| |||
140 | 149 | | |
141 | 150 | | |
142 | 151 | | |
143 | | - | |
| 152 | + | |
144 | 153 | | |
145 | 154 | | |
146 | 155 | | |
| |||
319 | 328 | | |
320 | 329 | | |
321 | 330 | | |
322 | | - | |
323 | | - | |
324 | | - | |
325 | | - | |
326 | | - | |
| 331 | + | |
327 | 332 | | |
328 | 333 | | |
329 | 334 | | |
| |||
367 | 372 | | |
368 | 373 | | |
369 | 374 | | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
370 | 380 | | |
371 | 381 | | |
372 | 382 | | |
373 | | - | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
374 | 426 | | |
375 | 427 | | |
376 | 428 | | |
| |||
385 | 437 | | |
386 | 438 | | |
387 | 439 | | |
388 | | - | |
389 | | - | |
390 | | - | |
391 | | - | |
392 | | - | |
393 | | - | |
394 | | - | |
395 | | - | |
396 | | - | |
397 | | - | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
398 | 452 | | |
399 | | - | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
400 | 461 | | |
| 462 | + | |
401 | 463 | | |
402 | 464 | | |
403 | 465 | | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
404 | 496 | | |
405 | 497 | | |
406 | 498 | | |
| |||
0 commit comments