open-webui/backend/open_webui
Classic298 f7ce4024d6
fix: keep requested MCP OAuth scope when DCR response omits it (#30384)
MCP tool servers using OAuth 2.1 with dynamic client registration authorized without any scope when the authorization server left scope out of its registration response, which RFC 7591 allows (Atlassian and Notion do). Consent completed and the tool showed as connected, but the issued token lacked the scopes the resource requires, so every tool call was refused. Discovered scopes and the custom OAuth Scopes field were both affected.

The stored client now falls back to the scope sent in the registration request when the response has none. A scope the server does return is kept as is.

Connections registered before this fix already have a null scope stored. The protected resource metadata recovery that static-credential clients already use now also runs for dynamically registered clients, so those connections pick up the discovered scopes on the next load without registering again.

Fixes #29967
2026-09-23 23:52:29 -04:00
..
data refac: mv backend files to /open_webui dir 2024-09-04 16:54:48 +02:00
internal refac 2026-09-06 17:13:32 -04:00
migrations chore: format 2026-08-25 16:53:53 -04:00
models fix: mark imported and cloned chats as read (#30754) 2026-09-23 23:32:14 -04:00
retrieval fix: page Chroma get() so hybrid search works on collections over 32k chunks (#30368) 2026-09-22 14:48:45 -04:00
routers fix: keep requested MCP OAuth scope when DCR response omits it (#30384) 2026-09-23 23:52:29 -04:00
socket refac: scope ydoc update save scheduling to note documents (#30395) 2026-09-23 23:30:21 -04:00
static refac 2026-09-06 17:27:30 -04:00
storage fix: read S3 files with long non-ASCII names (#30418) 2026-09-23 23:30:55 -04:00
tools refac 2026-09-21 08:59:39 -04:00
utils fix: keep requested MCP OAuth scope when DCR response omits it (#30384) 2026-09-23 23:52:29 -04:00
__init__.py refactor: use secrets module for generated secret key (#30441) 2026-09-23 23:36:26 -04:00
alembic.ini fix: Alembic CLI commands from failing 2025-08-15 04:17:47 -04:00
config.py refac 2026-09-21 11:09:09 -04:00
constants.py refac 2026-08-29 16:14:32 -04:00
env.py perf: per-room channel delivery for the socket.io Redis manager (#28818) 2026-09-22 14:48:56 -04:00
events.py refac 2026-08-16 23:21:00 -07:00
functions.py fix: honor bypass_system_prompt on the pipe route (#28739) 2026-08-19 11:08:02 -07:00
main.py fix: keep requested MCP OAuth scope when DCR response omits it (#30384) 2026-09-23 23:52:29 -04:00
tasks.py refac 2026-09-21 08:59:39 -04:00