755194ffe9
A cached-but-unusable OAuth token (expired/revoked, or a refresh the IdP rejects) makes the MCP SDK fall through to the authorization-code flow even though build_oauth_auth's guard only checks token-file existence. In a non-interactive context (systemd gateway, cron, background MCP discovery) _redirect_handler then printed an auth URL / launched a browser flow no operator can complete, and _wait_for_callback bound a localhost listener and blocked for the full 300s timeout — gating gateway adapter startup and, on retry, colliding on the callback port (OSError: [Errno 98] Address already in use). Re-check interactivity at the redirect/callback boundary and raise an actionable OAuthNonInteractiveError before printing a URL, opening a browser, or binding a listener. The guard holds regardless of whether a token file exists (the point the token-file guard cannot cover), and only triggers on the authorization-code path, so valid/refreshable tokens keep working non-interactively. Both build_oauth_auth and MCPOAuthManager reuse these handlers, so the sibling construction path is covered too.