fix(mcp): do not persist authorization_url from the DCR path; the build hook is the provenance-guarded writer

This commit is contained in:
Tin Chi Lo 2026-07-14 18:08:55 -07:00
parent 55a9f1917c
commit a0d5df21da
2 changed files with 1 additions and 2 deletions

View file

@ -1133,7 +1133,6 @@ async def _persist_dcr_client_registration(
credentials=credentials,
oauth2_flow="authorization_code",
**({"token_url": mcp_server.token_url} if mcp_server.token_url else {}),
**({"authorization_url": mcp_server.authorization_url} if mcp_server.authorization_url else {}),
),
touched_by="mcp_oauth_dcr",
)

View file

@ -657,7 +657,7 @@ async def test_register_client_persists_dcr_client_identity():
update_data = mock_update.call_args.kwargs["data"]
assert update_data.server_id == "remote_server"
assert update_data.token_url == "https://provider.example/oauth/token"
assert update_data.authorization_url == "https://provider.example/oauth/authorize"
assert "authorization_url" not in update_data.fields_set()
assert update_data.credentials["client_id"] == "generated-client"
assert update_data.credentials["client_secret"] == "generated-secret"
assert update_data.credentials["token_endpoint_auth_method"] == "client_secret_basic"