Skip to content

fix(auth): accept Cursor's registration with a cursor:// callback until November - #240

Closed
mattzcarey wants to merge 2 commits into
mainfrom
fix/allow-cursor-private-use-redirect
Closed

mattzcarey wants to merge 2 commits into
mainfrom
fix/allow-cursor-private-use-redirect

Conversation

@mattzcarey

@mattzcarey mattzcarey commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Some Cursor versions register three callbacks:

cursor://anysphere.cursor-mcp/oauth/callback
https://www.cursor.com/agents/mcp/oauth/callback
http://localhost:<port>/callback

workers-oauth-provider 1.2 (#236) refuses the whole registration because of the cursor:// one. The dcr_refused logging from #237 counted 66 refused Cursor registrations in the first 77 minutes, from the IDE (node), the agent daemon (Cursor/1.0.0) and Cursor 3.3.30 on Linux. On 0.10 those registrations went through and Cursor signed in with its loopback callback, so this is a regression.

allowPrivateUseRedirectUris: true restores 0.10's behavior:

0.10 1.2 (main) This PR
Cursor's three-callback registration 201 400 201
Sign in with its loopback callback consent page (no client) consent page
Authorize with cursor://… refused locally by our own check (no client) refused locally by our own check
Register with a remote http callback 201, refused at /authorize 400 400

Our own /authorize check (isAllowedOAuthRedirectUri) still only allows https or loopback. So a custom scheme can sit in a registration, but it never receives a code. Clients that register only a custom scheme (Claude Code's claude://, CodeBuddy, WorkBuddy, Warp) now register, then fail at /authorize exactly as they did on 0.10.

There's a TODO to remove this in November, once people have upgraded Cursor. Cursor 3.22.7 registers only the https and loopback callbacks.

tests/auth/private-use-redirects.test.ts runs end to end through the worker. Without the option, Cursor's registration gets 400.

In cimd.test.ts, the ftp:// and com.example.client:/ cases are now refused by our own check instead of the provider, so they expect its message. They still get a 400, no redirect and no grant.

…il November

Some Cursor versions register cursor://anysphere.cursor-mcp/oauth/callback next
to their https and loopback callbacks. workers-oauth-provider 1.2 refuses the
whole registration for it: 66 Cursor registrations in 77 minutes in production.
On 0.10 the registration went through and Cursor signed in with the loopback
callback. allowPrivateUseRedirectUris restores that. Our own /authorize check
still refuses a request that uses a custom scheme, and remote http stays
refused. TODO to remove in November, once people have upgraded Cursor.
… now

With allowPrivateUseRedirectUris the provider no longer refuses ftp:// or a
private-use scheme on /authorize; isAllowedOAuthRedirectUri does, with its own
message. Still 400, no redirect, no grant.
@mattzcarey

Copy link
Copy Markdown
Contributor Author

Replaced by #241: workers-oauth-provider 1.2.1 accepts Cursor's registration without allowPrivateUseRedirectUris (cloudflare/workers-oauth-provider#391), and #241 drops our duplicate redirect check.

@mattzcarey mattzcarey closed this Sep 28, 2026
@mattzcarey
mattzcarey deleted the fix/allow-cursor-private-use-redirect branch September 28, 2026 16:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant