Skip to content

v1.12.2 — Hotfix: don't forward 'resource' to the upstream IdP

Latest

Choose a tag to compare

@IkarusMK IkarusMK released this 12 Jul 19:51
· 4 commits to main since this release

Fixed — connector login, properly this time

v1.12.1's pin was not enough. Deeper finding: fastmcp 3.4.3 already contains the new authorize flow (CIMD, /consent interstitial, RFC 8707 resource forwarding). v1.11.0 only looked fine because existing connector sessions renew via refresh tokens — the last fresh login predated the 3.4.x flow, so the regression stayed invisible until a reconnect was needed.

The real, version-independent fix is in AICortex's own proxy construction:

  • forward_resource=False — the upstream IdP never sees the resource parameter it rejects (invalid_request — "The 'resource' or 'scope' parameter is invalid", e.g. Pocket ID)
  • require_authorization_consent="external" — no /consent interstitial; the IdP's own (passkey) login is the consent, restoring the familiar flow

Both are signature-checked, so a fastmcp version without these kwargs can never break boot. New guard tests (tests/test_oauth_upstream.py) pin the contract against the installed fastmcp — the full suite passes against 3.4.4 (which Dependabot bumped to in #32, now safe thanks to the config fix).

Deploy: git pull && docker compose pull && docker compose up -d, then reconnect the connector in the Claude app.