Repository navigation
feat(models): forward MCP OAuth scopes in claude_code and codex_cli generators - #647
ikenwan-dev wants to merge 3 commits into
Conversation
|
/gcbrun |
|
fix pycodestyle |
|
Claude (claude_code.py#L294-L310) accepts oauth: {scopes: [...]}, oauth: [...], oauth: "...", a top-level scopes, and comma-separated strings. Codex (codex_cli.py#L611-L614) calls oauth.get(...), which raises AttributeError for oauth: [...] or oauth: "...". Strings aren't split or stripped either ("a, b" becomes ["a, b"]). Three code paths read the same mcp_servers block, and Claude's extra shapes work in only one of them. The documented contract (Gemini CLI schema) is oauth.scopes: string[]. I suggest one shared helper (in agent_cli.py or mcp_client.py) that accepts only the canonical shape and is used by both generators, ideally by auth_headers too |
|
Done! I've put scope extraction into a shared extract_mcp_oauth_scopes helper in mcp_client.py that follows the canonical oauth.scopes contract, and updated Claude Code, Codex CLI, and auth_headers to use it.
|
|
/gcbrun |
|
linting error is till there |
Summary
oauth.scopesand forwards them togcloud auth application-default print-access-token --scopes=...in both static header and dynamicheadersHelpertoken refresh.oauth.scopesacross configured MCP servers, forwards them when fetching the GCloud bearer token, and refreshes the token with scopes per turn.