fix(auth): workers-oauth-provider 1.2.1 accepts Cursor's registration; drop our own redirect check - #241
Merged
Conversation
…; drop our own redirect check Some Cursor versions register cursor://anysphere.cursor-mcp/oauth/callback next to their https and loopback callbacks. 1.2.0 refused the whole registration; 1.2.1 accepts a registration with at least one compliant redirect URI and still refuses a request that uses a refused one (cloudflare/workers-oauth-provider#391). The provider now enforces the redirect policy on every request (parseAuthRequest, completeAuthorization, and redirectUri on an AuthorizationError only when safe), so isAllowedOAuthRedirectUri, isLoopbackHostname and invalidRedirectUriResponse duplicated it. Removed, with their unit tests; end-to-end coverage stays in cimd.test.ts and the new cursor-redirects.test.ts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces #240. Fixes Cursor sign-in on 1.2 in the library instead of turning on
allowPrivateUseRedirectUris, and removes our own redirect check, which duplicates the library's.Cursor
Some Cursor versions register
cursor://anysphere.cursor-mcp/oauth/callbacknext to their https and loopback callbacks. 1.2.0 refused the whole registration (66 in 77 minutes in production), although Cursor signs in with the loopback callback. On 0.10.2, 0 of Cursor's/authorizerequests usedcursor://, 14 usedlocalhost:8787and 4 used the https agents callback. 1.2.1 accepts a registration with at least one compliant callback and still refuses any request that uses a refused one.Our redirect check
isAllowedOAuthRedirectUri()repeated what 1.2 enforces on every request:GET /authorizeafterparseAuthRequest()error.redirectUri?redirectUrionly when it mayapproveConsent()/finishUpstream()redirectTofromcompleteAuthorization()Removed it,
isLoopbackHostname(),invalidRedirectUriResponse()and their unit tests (−83 lines). End-to-end coverage stays:cimd.test.ts: remotehttp,ftp://and a private-use scheme are refused locally, with no redirect and no grant.cursor-redirects.test.ts(new, from fix(auth): accept Cursor's registration with a cursor:// callback until November #240): Cursor's three-callback registration succeeds and signs in through its loopback callback.cursor://itself is still refused locally, and a registration with a remotehttpcallback is still refused. On 1.2.0 the Cursor tests fail with a 400 at registration; on 1.2.1 they pass.