fix(auth): forward User-Agent header to OAuth discovery and flow requests (#3531) - #3553
Theater-ahyeon wants to merge 1 commit into
Conversation
|
This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3531. If a maintainer assigns you to #3531, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take. You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way. CONTRIBUTING.md has the full reasoning, but in short:
Maintainers: reopen, remove |
Description
When
OAuthClientProvider(viaRedirectAwareAuth) issues OAuth metadata discovery and registration requests, they are sent as barehttpx2.Requestinstances that do not go throughclient.build_request(). Consequently, these requests omit theUser-Agentheader.When interacting with MCP servers protected by WAFs (such as Cloudflare bot protection), user-agent-less requests are rejected with
403 Forbidden, causing the OAuth flow to fail.This PR forwards the
User-Agentheader from the authenticated request to intermediate auth flow requests if not already set.Closes #3531
Verification
test_auth_flow_forwards_user_agent_headerintests/client/test_auth.py.pytest tests/client/test_auth.py(all 161 tests passed).ruff checkandruff format.