From 84bc93a0ff23f8f0d1269860ca768207b8dbaf8f Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Sun, 13 Sep 2026 12:20:58 -0700 Subject: [PATCH] fix(mcp): read the OAuth auth type by name, not by tuple position The salvaged refactor tested `ident[-1] == "oauth"`; once the mTLS fields were appended to `_connection_identity()` the last element became the frozen `client_key` and the cross-profile OAuth refusal silently stopped firing (the live probe showed B adopting A's OAuth session again). Name the auth-type accessor so the tuple can grow without moving the check. --- tools/mcp_tool_registration.py | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/tools/mcp_tool_registration.py b/tools/mcp_tool_registration.py index 88c946536f..a9a4d02280 100644 --- a/tools/mcp_tool_registration.py +++ b/tools/mcp_tool_registration.py @@ -411,8 +411,11 @@ def _connection_identity(config: dict) -> tuple: return json.dumps(value or {}, sort_keys=True, default=str) return (config_fingerprint(config), _frozen(config.get("env")), _frozen(config.get("headers")), - (config.get("auth") or "").lower().strip(), _frozen(config.get("client_cert")), - _frozen(config.get("client_key"))) + _auth_type(config), _frozen(config.get("client_cert")), _frozen(config.get("client_key"))) + + +def _auth_type(config: dict) -> str: + return (config.get("auth") or "").lower().strip() def _same_server_route(server: Any, config: dict, *, cross_profile: bool = False) -> bool: @@ -421,11 +424,10 @@ def _same_server_route(server: Any, config: dict, *, cross_profile: bool = False OAuth credentials live in the owning profile's token storage rather than the static config, so identical OAuth configs cannot prove that two profiles authenticate as the same account. """ - ident = _connection_identity(getattr(server, "_config", {}) or {}) - if ident != _connection_identity(config): + if _connection_identity(getattr(server, "_config", {}) or {}) != _connection_identity(config): return False - # The normalised auth type is the identity's last element, so one side suffices here. - return not (cross_profile and ident[-1] == "oauth") + # Identities match, so both sides carry the same normalised auth type. + return not (cross_profile and _auth_type(config) == "oauth") def register_connected_into_current_scope(servers: dict) -> int: