Resolved unrelated-history merge using e1fc955464 (the original base of upstream PR #28008) as the 3-way merge base.
Conflict resolutions:
- discoverable_endpoints.py: kept PR's _OAUTH_METADATA_CACHE / prune helpers and PR's inline redirect_uri extraction in /callback; took staging's callback comment that mentions the ops-allowlist code path served by validate_trusted_redirect_uri.
- oauth_utils.py: took staging's version (strict superset: adds MCP_TRUSTED_REDIRECT_ORIGINS ops allowlist, userinfo/backslash netloc rejection, rejection diagnostics).
- server.py: kept both PR's _raise_preemptive_401_for_unauthenticated_servers and staging's _get_forwarded_auth_from_scope / _probe_upstream_auth / _check_passthrough_upstream_auth additions (independent helpers).
- mcp_management_endpoints.py: took staging's verify_exp=False JWT decode option and staging's delegate_auth_to_upstream PKCE bypass block.
- proxy_server.py: took staging's restructured 4-case dynamic_mcp_route, and ported PR's scope['_original_path'] preservation into _mcp_forward_as_path so server.py's OAuth-challenge URL selection still has the public request path.
- types/mcp_server/mcp_server_manager.py: kept both PR's is_oauth_passthrough and staging's has_token_exchange_config properties (additive).
- test_image_edits.py: took staging's _make_test_images() per fix(image_edits).
- test_realtime_guardrails_openai.py: took staging's unicode-punctuation normalization.
- test_fireworks_ai_translation.py: took staging's mocked-payload test_document_inlining_example.
- test_openapi_compliance.py: kept PR's removal of 'steps' per fix(interactions).
- test_discoverable_endpoints.py: took staging's tests (PR's tests assumed the removed get_proxy_base_url import path).
- test_mcp_server.py: took staging's pre-flight upstream-auth tests (cover the helpers we kept).
- test_mcp_management_endpoints.py: took staging's verify_exp=False / delegate_auth_to_upstream tests, and also kept PR's test_mcp_oauth_authorize_token_routes_use_browser_auth_dependency (independent route-wiring assertion).
Co-authored-by: Claude <claude@anthropic.com>