Skip to content

oauthex: GetAuthServerMeta accepts a server whose only PKCE method is plain, but clients always use S256 #1326

Description

@akshita317

What did you do?

Ran the client OAuth flow (auth.AuthorizationCodeHandler) against an authorization server whose metadata advertises PKCE with only the plain method:

"code_challenge_methods_supported": ["plain"]

What did you see?

oauthex.GetAuthServerMeta accepted the metadata: it only checks that code_challenge_methods_supported is non-empty. The handler then always sends an S256 challenge (oauth2.S256ChallengeOption in auth/authorization_code.go, and likewise in auth/extauth/oidc_login.go), so the server rejects the authorization request. The failure surfaces late, at the authorization endpoint in the user's browser, instead of during discovery with a clear message.

What did you expect to see?

Discovery to reject a server that cannot do S256, since that is the only method the SDK's clients use. The MCP authorization spec requires clients to use S256 (via OAuth 2.1 section 7.5.2), and the TypeScript SDK refuses such a server during discovery: packages/client/src/client/auth.ts throws Incompatible auth server: does not support code challenge method S256 when the list is present and lacks S256.

Real servers that also support plain are unaffected; Google's metadata in oauthex/testdata/google-auth-meta.json lists ["plain", "S256"].

What version of the Go MCP SDK are you using?

v1.8.0, and main at the time of writing.

What version of Go are you using (go version)?

go1.25.3 windows/amd64 (also reproduced with the go1.26 toolchain).

I have a fix with tests ready and will link the PR here. It tightens the check in GetAuthServerMeta, whose doc already says it "verifies that the authorization server supports PKCE"; if you'd rather keep oauthex permissive and put the check in the auth handlers instead, I'm happy to move it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions