Skip to content

[ENG-1118] Fix MCP OAuth identity by reporting plugin versions in headers - #272

Closed
liwenXtrace wants to merge 1 commit into
mainfrom
codex/eng-1118-stable-mcp-oauth
Closed

liwenXtrace wants to merge 1 commit into
mainfrom
codex/eng-1118-stable-mcp-oauth

Conversation

@liwenXtrace

@liwenXtrace liwenXtrace commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Refs https://linear.app/xtrace/issue/ENG-1118/mcp-login-is-broken
Companion backend validation: https://github.com/XTraceAI/MemHub-Backend/pull/1354 (targets staging; shared header parser already exists there).

Codex hashes the complete MCP endpoint URL to derive its CIMD OAuth client ID. Adding ?memhub_plugin_version=0.76.0 changed production's registered YzZcYxKAiT6g identity to -ugMLRSp9raH, which Auth0 rejected as Unknown client before login. This PR restores the canonical production/staging URLs and moves the loaded package version to headers.X-MemHub-Plugin-Version in both shipped MCP formats. Backend minimum-version checks still receive the version on requests.

  • Prepare 0.76.1 manifests and matching connection headers for production and the separately published staging package. Leave the existing Claude marketplace tag/pin unchanged.
  • Require exact canonical endpoints and package/header parity in the release guard. Regression coverage reproduces the incident hash and rejects versioned URLs, stale/missing headers, and ambiguous header names.
  • Document the backend-first compatibility verification, host restart/reconnect, fresh OAuth/protected read/refresh checks, and separate package publishing steps.

Validation:

  • Focused manifest, OAuth identity, and test-registration checks passed.
  • TMPDIR=/private/tmp uv run --python 3.12 --with 'mcp<2' bash scripts/check-plugin.sh — passed: all 73 suites in both bare-Python and MCP-SDK environments, plus both shell hook runs.
  • An earlier non-isolated full run passed 72/73 suites; session_title_test.py inspected local user transcripts and failed an unrelated fallback assertion. The CI wrapper isolates account state and that suite passes there.
  • Codex's public Agent Plugins loader maps headers to HTTP headers. A live native-host OAuth/refresh test and the required Real agent evidence check remain release prerequisites; this PR does not claim those ran.

Draft — release planned September 22, 2026. Do not merge, tag, move marketplace pins, or deploy today. A merge to main publishes immediately to Codex/Cursor. Verify the backend version-header contract in the target environment, publish the packages via RELEASING.md, and then run fresh login and protected-operation checks. Keep compatibility floors and enforcement flags unchanged. No new Auth0 client registration is needed for the restored canonical production URL.

@liwenXtrace
liwenXtrace deployed to production-plugin-release September 21, 2026 21:41 — with GitHub Actions Active
@xtrace-memhub-staging

xtrace-memhub-staging Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

🧠 Session context

1 session behind this pull request.

Team rules that fired while building this

  • Delegate big file reads to a cheaper model (gate, 1×)
  • fetch-before-origin-read (advise, 1×)
  • Run agent-plugins tests via run_all.py on Python 3.12 (advise, 1×)

Effort
1 session · 32m agent time · 10.6M tokens · 125 turns

Sessions

@liwenXtrace

Copy link
Copy Markdown
Contributor Author

Superseded by XTraceAI/agent-plugins-internal#42, now merged. The OAuth fix will reach production through promotion of the tested internal commit. Public #277 updates the CI guard to accept that export. This original PR should not be merged directly.

This branch was successfully deployed

1 active deployment
production-plugin-release — 8771275e Deployed Sep 21, 2026 by liwenXtrace via production #161
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant