fix(mcp): clear stale state cookie and mention trusted-proxy config in callback error

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
jesus 2026-09-17 02:25:38 +00:00
parent ccdd7b59ac
commit fdcdea0d37

View file

@ -2256,11 +2256,14 @@ async def callback(
description: Final = (
"The OAuth session cookie set when authorization started did not arrive at the callback. "
"This usually means the authorize and callback requests used different origins. "
"Ask the gateway operator to set PROXY_BASE_URL to the public URL of this gateway, then retry."
"Ask the gateway operator to set PROXY_BASE_URL to the public URL of this gateway "
"(or configure mcp_trusted_proxy_ranges), then retry."
if not cookie_present
else "The OAuth session could not be decoded. Start the authorization again."
)
return _render_oauth_error_html("invalid_request", description)
response = _render_oauth_error_html("invalid_request", description)
_clear_oauth_state_cookie(response, request, state)
return response
try:
original_state = state_data["original_state"]