Skip to content

oauthex: accept an empty quoted-string auth-param value - #1344

Merged
guglielmo-san merged 1 commit into
modelcontextprotocol:mainfrom
akshita317:oauthex-empty-quoted-param
Oct 6, 2026
Merged

guglielmo-san merged 1 commit into
modelcontextprotocol:mainfrom
akshita317:oauthex-empty-quoted-param

Conversation

@akshita317

Copy link
Copy Markdown
Contributor

parseSingleChallenge rejected any auth-param with an empty value, including a quoted-string such as realm="". RFC 9110, section 5.6.4, allows a quoted-string to be empty; only a token must be non-empty.

ParseWWWAuthenticate fails the whole header when one challenge is malformed, so a server sending

WWW-Authenticate: Bearer realm="", resource_metadata="https://example.com/.well-known/oauth-protected-resource"

made AuthorizationCodeHandler.Authorize (and the extauth client-credentials handler) return failed to parse WWW-Authenticate header. The client never reached resource_metadata and could not authorize. The same happens with an empty error_description="".

This moves the empty-value check into the unquoted (token) branch, so realm= and realm=, … are still rejected.

Tests:

  • TestParseSingleChallenge: an empty quoted param parses; an empty unquoted value before a comma is still an error.
  • TestParseWWWAuthenticateEmptyQuotedValue: empty realm and error_description no longer hide the resource_metadata that follows.

AI assistance: prepared with Claude Code.

parseSingleChallenge rejected any auth-param whose value was empty,
including a quoted-string such as realm="". RFC 9110, section 5.6.4,
allows a quoted-string to be empty; only a token must be non-empty.

Because ParseWWWAuthenticate fails the whole header on one bad
challenge, a server that sent realm="" or error_description="" made
AuthorizationCodeHandler.Authorize and the client-credentials handler
return "failed to parse WWW-Authenticate header", so the client never
reached the resource_metadata parameter and could not authorize.

Only reject an empty value when it is unquoted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@guglielmo-san
guglielmo-san merged commit 172aebf into modelcontextprotocol:main Oct 6, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants