fix(mcp-oauth2): apply _extract_access_token in _check_byok_credential

_check_byok_credential wrote the raw credential from DB directly to
_byok_cred_cache without calling _extract_access_token. When the OAuth2
callback stores a JSON blob {"access_token": "...", "refresh_token": "..."},
a subsequent call that went through _check_byok_credential first (rather
than _get_byok_credential) would populate the cache with the blob. The
next _get_byok_credential call would return the blob as the Bearer token,
causing silent HTTP 401s on every upstream API call.

Fix: extract the access_token before writing to cache, consistent with
how _get_byok_credential already handles it.
This commit is contained in:
Ishaan Jaffer 2026-03-07 09:26:06 -08:00
parent 19ab870f32
commit 12880bf760

View file

@ -1651,11 +1651,16 @@ if MCP_AVAILABLE:
if prisma_client is None:
return
credential = await get_user_credential(
raw_credential = await get_user_credential(
prisma_client=prisma_client,
user_id=user_id,
server_id=mcp_server.server_id,
)
# Apply _extract_access_token so the cache always stores a plain token
# string. Without this, a JSON blob {"access_token": ..., "refresh_token": ...}
# stored by the OAuth2 callback would be returned as-is by _get_byok_credential
# on the next request, causing Bearer-header corruption and silent 401s.
credential = _extract_access_token(raw_credential)
_write_byok_cred_cache(user_id, mcp_server.server_id, credential)
if credential is None:
raise HTTPException(