9975180a59
Some MCP OAuth providers (notably Supabase) return a client_secret from dynamic client registration but omit token_endpoint_auth_method. The MCP SDK defaults the missing method to "none", so the token exchange omits client_secret and the server rejects it (HTTP 422 "Required parameter: client_secret"), looping the browser consent page. This resolves the whole class, not just one provider: - Storage layer (HermesTokenStorage): coerce secret-bearing client info with missing/none auth method to client_secret_post on both read and write, persisting the corrected shape. - Both live provider paths (tools/mcp_oauth.py HermesOAuthClientProvider and tools/mcp_oauth_manager.py HermesMCPOAuthProvider): coerce in-memory client info immediately before token exchange and refresh. - Accept the full 2xx range on token and refresh responses (Supabase returns 201 Created), instead of the SDK's exact-200 check. - Redact token response bodies from error messages and logs on malformed responses. The Figma-specific request-time default (apply_oauth_provider_defaults) remains; this generalizes the same bug class for every DCR provider. Fixes #29680. Supersedes #34274 and #35700 (201-only variants).