Skip to content

fix(auth): workers-oauth-provider 1.2.1 accepts Cursor's registration; drop our own redirect check - #241

Merged
mattzcarey merged 2 commits into
mainfrom
refactor/redirect-policy-from-provider
Sep 28, 2026
Merged

mattzcarey merged 2 commits into
mainfrom
refactor/redirect-policy-from-provider

Conversation

@mattzcarey

@mattzcarey mattzcarey commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Replaces #240. Fixes Cursor sign-in on 1.2 in the library instead of turning on allowPrivateUseRedirectUris, and removes our own redirect check, which duplicates the library's.

Cursor

Some Cursor versions register cursor://anysphere.cursor-mcp/oauth/callback next to their https and loopback callbacks. 1.2.0 refused the whole registration (66 in 77 minutes in production), although Cursor signs in with the loopback callback. On 0.10.2, 0 of Cursor's /authorize requests used cursor://, 14 used localhost:8787 and 4 used the https agents callback. 1.2.1 accepts a registration with at least one compliant callback and still refuses any request that uses a refused one.

Our redirect check

isAllowedOAuthRedirectUri() repeated what 1.2 enforces on every request:

Our check What the provider already does
GET /authorize after parseAuthRequest() refuses a non-compliant redirect URI, locally
error path: may the error go to error.redirectUri? sets redirectUri only when it may
after approveConsent() / finishUpstream() the request comes from storage, already checked
redirectTo from completeAuthorization() checks the redirect URI again

Removed it, isLoopbackHostname(), invalidRedirectUriResponse() and their unit tests (−83 lines). End-to-end coverage stays:

  • cimd.test.ts: remote http, ftp:// and a private-use scheme are refused locally, with no redirect and no grant.
  • cursor-redirects.test.ts (new, from fix(auth): accept Cursor's registration with a cursor:// callback until November #240): Cursor's three-callback registration succeeds and signs in through its loopback callback. cursor:// itself is still refused locally, and a registration with a remote http callback is still refused. On 1.2.0 the Cursor tests fail with a 400 at registration; on 1.2.1 they pass.

…; drop our own redirect check

Some Cursor versions register cursor://anysphere.cursor-mcp/oauth/callback next
to their https and loopback callbacks. 1.2.0 refused the whole registration;
1.2.1 accepts a registration with at least one compliant redirect URI and still
refuses a request that uses a refused one (cloudflare/workers-oauth-provider#391).

The provider now enforces the redirect policy on every request (parseAuthRequest,
completeAuthorization, and redirectUri on an AuthorizationError only when safe),
so isAllowedOAuthRedirectUri, isLoopbackHostname and invalidRedirectUriResponse
duplicated it. Removed, with their unit tests; end-to-end coverage stays in
cimd.test.ts and the new cursor-redirects.test.ts.
@mattzcarey
mattzcarey marked this pull request as ready for review September 28, 2026 17:06
@mattzcarey
mattzcarey merged commit 259b2af into main Sep 28, 2026
5 checks passed
@mattzcarey
mattzcarey deleted the refactor/redirect-policy-from-provider branch September 28, 2026 17:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant