open-webui/backend/open_webui/routers
Classic298 f7ce4024d6
fix: keep requested MCP OAuth scope when DCR response omits it (#30384)
MCP tool servers using OAuth 2.1 with dynamic client registration authorized without any scope when the authorization server left scope out of its registration response, which RFC 7591 allows (Atlassian and Notion do). Consent completed and the tool showed as connected, but the issued token lacked the scopes the resource requires, so every tool call was refused. Discovered scopes and the custom OAuth Scopes field were both affected.

The stored client now falls back to the scope sent in the registration request when the response has none. A scope the server does return is kept as is.

Connections registered before this fix already have a null scope stored. The protected resource metadata recovery that static-credential clients already use now also runs for dynamically registered clients, so those connections pick up the discovered scopes on the next load without registering again.

Fixes #29967
2026-09-23 23:52:29 -04:00
..
analytics.py refac 2026-06-29 01:38:41 -05:00
audio.py fix: keep the speech-to-text extension allowlist when the Audio settings are saved (#30208) 2026-09-19 17:36:38 -04:00
auths.py refac 2026-09-21 10:44:37 -04:00
automations.py refac 2026-09-21 08:59:39 -04:00
calendar.py refac 2026-09-21 08:59:39 -04:00
channels.py refac: sync channel room on member removal (#30446) 2026-09-23 23:43:20 -04:00
chats.py fix: restore tag rows after unarchiving all chats and remove unused ones after deleting all chats (#30453) 2026-09-23 23:32:54 -04:00
configs.py fix: keep requested MCP OAuth scope when DCR response omits it (#30384) 2026-09-23 23:52:29 -04:00
evaluations.py fix: load the leaderboard activity chart for model ids that contain a slash (#30456) 2026-09-23 23:32:42 -04:00
files.py refac 2026-09-21 10:19:59 -04:00
folders.py refac: folder file checks (#30442) 2026-09-23 23:36:15 -04:00
functions.py fix: drop a deleted plugin's source from the content cache (#29983) 2026-09-13 20:21:40 -04:00
groups.py refac 2026-06-29 05:47:21 -05:00
images.py fix: detect the real image type of bare base64 generated images (#30359) 2026-09-22 11:35:59 -04:00
knowledge.py refac 2026-09-21 10:19:59 -04:00
memories.py refac 2026-09-16 00:34:24 -04:00
models.py refac 2026-09-21 10:25:20 -04:00
notes.py refac 2026-09-22 13:13:22 -04:00
notifications.py refac 2026-07-27 19:39:36 -04:00
ollama.py fix: stop forwarding upstream Server and Date headers from the OpenAI and Ollama proxies (#29843) 2026-09-09 16:35:48 -04:00
openai.py fix: convert forced tool_choice and non-streaming tool calls for Responses API connections (#30095) 2026-09-18 19:18:26 -04:00
pipelines.py perf: skip pipeline filter session setup when no filters exist (#29146) 2026-08-28 12:22:23 -04:00
prompts.py refac 2026-08-31 00:39:16 -04:00
retrieval.py fix: send the configured USER_AGENT on the Attach Webpage pre-check (#30385) 2026-09-23 23:50:08 -04:00
scim.py refac 2026-09-17 20:11:05 -04:00
skills.py perf: stop scanning every skill on each listing and chat turn (#28798) 2026-08-19 11:07:33 -07:00
tasks.py refac 2026-08-11 01:15:05 -06:00
terminals.py refac 2026-09-21 10:30:53 -04:00
tools.py refac 2026-09-21 08:31:27 -04:00
users.py refac 2026-09-07 14:46:52 -04:00
utils.py refac 2026-09-06 17:27:30 -04:00