Skip to content

fix(client): surface invalid protected resource metadata - #2869

Open
1fanwang wants to merge 1 commit into
modelcontextprotocol:mainfrom
1fanwang:1fannnw/surface-prm-validation-errors
Open

1fanwang wants to merge 1 commit into
modelcontextprotocol:mainfrom
1fanwang:1fannnw/surface-prm-validation-errors

Conversation

@1fanwang

Copy link
Copy Markdown

Malformed protected-resource metadata returned with HTTP 200 used to disappear inside auth discovery. Users then saw a later Dynamic Client Registration failure instead of the invalid metadata.

AI disclosure: GitHub Copilot CLI helped implement and validate this bug fix under human direction.

Motivation and Context

This keeps the RFC 9728 fallback for missing metadata. A 200 response is now authoritative: invalid metadata stops auth with the schema error.

Fixes #2866

How Has This Been Tested?

Before: a local Node server returned malformed metadata with HTTP 200 through auth. The SDK reported Dynamic Client Registration instead of validation.

After: the same path raises Invalid OAuth protected resource metadata. Client auth tests pass.

Raw logs
$ pnpm --filter @modelcontextprotocol/client test -- auth.prmValidation.test.ts
AssertionError: expected [Function] to throw error matching /Invalid OAuth protected resource meta…/ but got 'Dynamic Client Registration rejected …'
+ Received:
"Dynamic Client Registration rejected (HTTP 404): not found"
Test Files  1 failed | 38 passed (39)
Tests  1 failed | 891 passed (892)

$ pnpm --filter @modelcontextprotocol/client exec vitest run test/client/auth.prmValidation.test.ts test/client/streamableHttp.test.ts
Test Files  2 passed (2)
Tests  76 passed (76)

$ pnpm --filter @modelcontextprotocol/client test
Test Files  39 passed (39)
Tests  892 passed (892)

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue): before/after auth regression test above.
  • New feature: not applicable.
  • Breaking change: not applicable.
  • Documentation update: not applicable.

Checklist

  • I have read the MCP Documentation: docs site responded.
  • My code follows the repository's style guidelines: package and repo lint completed.
  • New and existing tests pass locally: see raw logs above.
  • I have added appropriate error handling: 200 validation errors surface; missing metadata still falls back.
  • I have added or updated documentation as needed: changeset added; no docs needed.

Additional context

Client and repo typecheck, lint, and build completed locally.

Malformed protected resource metadata returned with HTTP 200 now fails the auth flow with the schema error instead of falling back to legacy discovery.

Signed-off-by: 1fanwang <1fannnw@gmail.com>
@1fanwang
1fanwang requested a review from a team as a code owner September 25, 2026 06:34
@changeset-bot

changeset-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1c676b3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
Name Type
@modelcontextprotocol/client Patch
@modelcontextprotocol/codemod Patch
@modelcontextprotocol/core Patch
@modelcontextprotocol/server-legacy Patch
@modelcontextprotocol/server Patch
@modelcontextprotocol/core-internal Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Sep 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/@modelcontextprotocol/client@2869

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/@modelcontextprotocol/codemod@2869

@modelcontextprotocol/core

npm i https://pkg.pr.new/@modelcontextprotocol/core@2869

@modelcontextprotocol/server

npm i https://pkg.pr.new/@modelcontextprotocol/server@2869

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/@modelcontextprotocol/server-legacy@2869

@modelcontextprotocol/express

npm i https://pkg.pr.new/@modelcontextprotocol/express@2869

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/@modelcontextprotocol/fastify@2869

@modelcontextprotocol/hono

npm i https://pkg.pr.new/@modelcontextprotocol/hono@2869

@modelcontextprotocol/node

npm i https://pkg.pr.new/@modelcontextprotocol/node@2869

commit: 1c676b3

@claude claude Bot added the v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes label Sep 25, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

discoverOAuthProtectedResourceMetadata validation errors are silently swallowed, leaving no signal when PRM is malformed

1 participant