{"record":{"id":"6229f52294ddbe33","repo":"siyuan-note/siyuan","slug":"parse-oauth-challenge-w","errorCode":null,"errorMessage":"parse OAuth challenge: %w","messagePattern":"parse OAuth challenge: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":189,"sourceCode":"\treturn credentialToken(refreshed), nil\n}\n\nfunc credentialToken(credential oauthCredential) *oauth2.Token {\n\treturn &oauth2.Token{\n\t\tAccessToken:  credential.AccessToken,\n\t\tTokenType:    credential.TokenType,\n\t\tRefreshToken: credential.RefreshToken,\n\t\tExpiry:       credential.Expiry,\n\t}\n}\n\nfunc (h *mcpOAuthHandler) Authorize(ctx context.Context, req *http.Request, resp *http.Response) (retErr error) {\n\tdefer resp.Body.Close()\n\tdefer io.Copy(io.Discard, io.LimitReader(resp.Body, 1<<20))\n\n\tchallenges, err := oauthex.ParseWWWAuthenticate(resp.Header.Values(\"WWW-Authenticate\"))\n\tif err != nil {\n\t\treturn fmt.Errorf(\"parse OAuth challenge: %w\", err)\n\t}\n\tif !hasBearerChallenge(challenges) {\n\t\treturn fmt.Errorf(\"server returned %s without an OAuth Bearer challenge\", resp.Status)\n\t}\n\tchallengeError := bearerChallengeParam(challenges, \"error\")\n\tif resp.StatusCode == http.StatusForbidden && challengeError != \"insufficient_scope\" {\n\t\treturn fmt.Errorf(\"server returned %s\", resp.Status)\n\t}\n\tinteractive := h.interactive.Load()\n\tif interactive {\n\t\tdefer func() {\n\t\t\tif retErr != nil && !errors.Is(retErr, context.Canceled) {\n\t\t\t\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"authorization_required\", 0, retErr.Error(), \"\")\n\t\t\t}\n\t\t}()\n\t}\n\n\tprm, err := discoverProtectedResource(ctx, challenges, req.URL.String(), h.client)","sourceCodeStart":171,"sourceCodeEnd":207,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L171-L207","documentation":"In mcpOAuthHandler.Authorize, the WWW-Authenticate headers of the server's 401/403 response are parsed with oauthex.ParseWWWAuthenticate; if that parsing fails, the error is wrapped as 'parse OAuth challenge: %w'. It means the server sent a malformed RFC 6750/9449 challenge that the client cannot interpret, so the OAuth flow cannot proceed.","triggerScenarios":"An HTTP MCP server returns an auth-challenge response whose WWW-Authenticate header values cannot be parsed by oauthex (malformed parameters, invalid quoting, non-standard syntax).","commonSituations":"Non-conformant or beta MCP server implementations emitting broken WWW-Authenticate headers; a proxy/gateway mangling or duplicating the header; custom auth middleware producing non-RFC challenge syntax.","solutions":["Inspect the server's WWW-Authenticate headers (curl -v) and fix the server's challenge formatting if you control it","Check for a proxy/gateway rewriting the header and bypass or fix it","Update the server to a version emitting RFC-compliant Bearer challenges","Report the malformed challenge to the MCP server vendor if it is third-party"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"err := handler.Authorize(ctx, req, resp)\nif err != nil && strings.HasPrefix(err.Error(), \"parse OAuth challenge: \") {\n    // server sent a malformed WWW-Authenticate header\n    logging.LogWarnf(\"non-RFC OAuth challenge from %s: %s\", server.URL, err)\n    // fail over: report to user / try alternative auth (e.g. static headers)\n}","preventionTips":["Test the server's 401 response headers (curl -v) before integrating it","Keep oauthex and the MCP client library updated for parser fixes","Avoid proxies that rewrite or split WWW-Authenticate headers","Prefer servers with standards-compliant OAuth metadata endpoints"],"tags":["mcp","oauth","http-headers","parsing"],"backgroundTag":"unexpected-response-shape","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}