fix(mcp): _extract_bearer_token returns None for non-Bearer auth schemes

Previously returned the full auth header value (including scheme prefix
like 'token abc') when no 'Bearer ' prefix was found, causing that
verbatim value to be sent to the IDP as the subject_token. Now returns
None, which correctly skips OBO token exchange for non-Bearer callers.
This commit is contained in:
Ishaan Jaffer 2026-05-01 11:24:58 -07:00
parent ba95b204c7
commit 4800446b2f
No known key found for this signature in database

View file

@ -1179,7 +1179,7 @@ class MCPServerManager:
auth_value = normalized.get("authorization")
if auth_value and auth_value.startswith("Bearer "):
return auth_value[len("Bearer "):]
return auth_value
return None
def _build_stdio_env(
self,