Files
sim/apps
Waleed 418722559d fix(mcp): bound and tear down one-shot OAuth fetches so auth can't hang (#5789)
The SSRF-guarded fetch used for MCP OAuth (discovery, DCR, token exchange/
refresh, RFC 7009 revocation) created a fresh pinned undici Agent per request
and never tore it down, and returned the live response so the SDK's lazy body
read happened outside any deadline. The MCP SDK sets no timeout on OAuth legs,
so a stalled body read or a leaked keep-alive socket could leave the flow — and
the browser waiting on it — pending indefinitely ("Connecting… forever").

- Buffer the (always-small) OAuth JSON body inside the guard, under the composed
  deadline/caller AbortSignal, then return a detached in-memory Response. undici's
  bodyTimeout only measures idle gaps between chunks and cannot bound a slow-drip
  body; the AbortSignal is the only true wall-clock deadline over the body read.
- Destroy (not close) the per-request pinned Agent on every path so a one-shot
  leg can't strand its keep-alive socket, and teardown itself can't hang.
- Fix the same per-request Agent leak in the auth-type probe.
- Returning a normalized global Response also surfaces provider token-endpoint
  errors cleanly instead of the SDK's opaque parse failure.
2026-07-20 18:55:33 -07:00
..