fix(tui_gateway): relay RFC 9207 iss through the oauth.callback RPC

The oauth.callback handler parsed `iss` but never passed it to deliver_callback_flow, and McpOauthCallbackParams (extra="forbid") had no `iss` field, so the desktop renderer sending `iss: null` was rejected with 4000 "unknown key" — breaking every Desktop→remote-gateway MCP OAuth login. Add the field, forward it, and regenerate the OpenRPC/TS contract artifacts via scripts/gen_gateway_contracts.py.

Also update tests/hermes_cli/test_mcp_dashboard_oauth.py for the 3-tuple callback shape introduced by the cherry-picked commit (it was red on the stack).
This commit is contained in:
kshitijk4poor
2026-09-15 11:58:01 +05:30
committed by kshitij
parent 1a6503a520
commit 1c243f86de
6 changed files with 35 additions and 2 deletions
@@ -201,6 +201,23 @@ def test_deliver_callback_forwards_iss():
assert flow._callback == ("abc", "s3cr3tstate", "https://as.example.com")
def test_oauth_callback_rpc_relays_iss():
"""The gateway ``mcp.servers.oauth.callback`` RPC accepts ``iss`` under the extra=forbid contract
and forwards it to the flow; the desktop renderer always sends the key (possibly null)."""
import tui_gateway.server as srv
from tui_gateway.contracts import registry as contracts
flow = _make_session()
contract = contracts.METHODS["mcp.servers.oauth.callback"]
params = {"session_id": "sess-relay-1", "name": "hosp", "code": "abc", "state": "s3cr3tstate",
"iss": "https://as.example.com"}
params, problem = contracts.validate_params(contract, params)
assert problem is None
out = srv._methods["mcp.servers.oauth.callback"](1, params)
assert out["result"]["ok"] is True
assert flow._callback == ("abc", "s3cr3tstate", "https://as.example.com")
def test_loopback_listener_forwards_iss():
"""The gateway-hosted loopback listener parses ``iss`` off the redirect rather than dropping it."""
import urllib.request