Repository navigation
feat(server): MCP OAuth sign-in for outside agents (port upstream #16335, #16336, #16718) - #446
Merged
Merged
Conversation
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 2f85686)
…(#16336) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 2c8be58)
…rver (#16718) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 10f39eb)
Cherry-picking #16335, #16336 and #16718 touches 38 upstream files and adds 15 unprefixed upstream modules. Record them in the additive guard's allowlists with a reason per group in the whitelist document; no existing entry is changed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Contributor
Thread transfer impact
This comment will update automatically after the next completed run. |
Owner
Author
|
🤖 Box e2e passed. Server: this branch at
CI: Typecheck (full server program), Lint, Additive guard and Check all pass. |
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Ports upstream's MCP OAuth sign-in for outside agents so agents that Nexi Work did not start (Claude Code/Codex in a terminal, NexiWork Sync, ChatGPT/hosted bots) can connect to
/mcp. Phil approves each sign-in himself, with a pairing code or a signed-in admin browser, and picks Read only or a mode ceiling. Access lasts 30 days and can be revoked in Settings → Connections.The per-thread bearer tokens that thread agents use are unchanged. The
/mcpauth middleware runsMcpSessionRegistry.resolve(token)first, and only falls back to the OAuth client authenticator when that finds nothing.Upstream commits (cherry-picked with
-x, upstream authorship kept)McpToolAccess)No other upstream prerequisites were needed.
Conflicts and resolutions
#16335 (7 files)
preview/{tools,handlers}.ts,previewControls/{tools.ts,handlers.test.ts}: these conflicted only because of the #15328 server-browser tools, which are not in the fork (preview_dialog/hover/select/drag/upload). I kept the fork side, so those tools stay out, but applied #16335's own changes:PreviewToolFailure, theThreadManagementServicedependency and the access declarations.toolkits/thread/handlers.ts,toolkits/core.test.ts: took upstream's structure (McpToolAccess.writesThreads). It uses the fork'sunavailablebecausedispatchFailuredoesn't exist in the fork'sthreadAccess.ts.McpHttpServer.ts: kept the fork'sPreviewBrowserprovide under upstream's newtoolkitRegistration/imageToolRegistrationhelpers. I dropped the registration blocks the merge had duplicated.T3TeamToolkitRegistrationLivenow goes throughtoolkitRegistration.T3TeamToolkittools are now built withMcpToolAccess.toLayer, and every tool is declaredreadsAsCaller. That means a thread caller is required and nothing more is checked: no liveness or mode check, so behaviour is the same as today. The fork's own in-handler gates still run (requireOrchestrationScope,mayCallT3TeamBrokerTool,workflowAuthorMcpScope). OAuth clients can't use the t3team tools. Thefailure:schemas were widened withOrchestratorMcpFailure.#16336 (3 files, simple unions)
McpHttpServer.ts: kept the fork'sT3_MCP_PROTOCOL(the deprecatedt3team_*alias names) and exportedlayerMcpTransport.server.ts: the t3team delegated-task and mailbox layers are provided together withMcpOAuth.layerMcpClientAuthenticator.__root.tsx: added/connect-agentto the fork's list of chrome-less paths.#16718: applied cleanly.
Notes for later
actsAsCallerand putPreviewAutomationBrokerback intopreviewControls/tools.ts's dependencies.actsAsCallerlater. That would be a behaviour change, because the hidden workflow-author thread has no live run, so it's left as a separate decision.Test plan
-p apps/serverrun OOMs on the box (tsgo needs ~9 GB), so CI runs it.vp test run apps/server/src/mcp apps/server/src/auth: 46 files / 434 tests pass.node t3team-additive-guard.mjs: pass./oauth/mcp/*with a pairing code, theninitialize,tools/listandt3_thread_list. A per-thread bearer token also still works, checked with a local ACP agent that calls/mcpwith the token its thread session got.