Skip to content

build(deps): bump go-sdk to 1.7.0-pre.2 and migrate OAuth to multi-round-trip elicitation - #2870

Merged
SamMorrowDrums merged 3 commits into
mainfrom
sammorrowdrums-go-sdk-upgrade-fix
Jul 15, 2026
Merged

SamMorrowDrums merged 3 commits into
mainfrom
sammorrowdrums-go-sdk-upgrade-fix

Conversation

@SamMorrowDrums

Copy link
Copy Markdown
Collaborator

Why

Supersedes the Dependabot bump #2869. Bumping modelcontextprotocol/go-sdk to v1.7.0-pre.2 alone fails CI (TestSessionPrompterPromptActions) and would break OAuth for real clients.

Root cause: pre.2 defaults to MCP protocol 2026-07-28, which (per SEP-2322) forbids the server from initiating JSON-RPC requests — including elicitation/create — while serving a request. The OAuth login flow presents its authorization prompt via ServerSession.Elicit(...) during tools/call, so on 2026-07-28 sessions it now errors:

"elicitation/create" cannot be sent while serving a request on protocol version 2026-07-28: return an InputRequests map instead (multi round-trip requests, SEP-2322)

The new model requires returning an InputRequests map from the tool call; the client fulfills it and retries (multi-round-trip / MRTR).

This is not transport-specific: the legacy initialize handshake is capped at 2025-11-25, but the new server/discover (SEP-2575) path — attempted by pre.2 clients on any transport, stdio included — negotiates 2026-07-28, where Elicit is unconditionally blocked.

What

Migrate the OAuth middleware to MRTR, without changing behavior for pre-2026-07-28 clients:

  • Legacy clients (< 2026-07-28): unchanged — the server presents the prompt via server-initiated elicitation and blocks until the token arrives.
  • Modern clients (≥ 2026-07-28): the first tools/call returns the authorization prompt as an InputRequests elicitation; the client presents it (keeping the auth URL out of the model's context) and retries with the response, at which point the middleware awaits the token and proceeds. Clients without elicitation capability fall back to the existing tool-result instructions.

The branch is required because our OAuth middleware is outermost while the SDK's serverMultiRoundTripMiddleware (which transparently services legacy clients) is innermost, so it can't fulfill our middleware's InputRequests — legacy clients therefore keep the direct Elicit path.

Changes

  • go.mod/go.sum + third-party-licenses.*.md: bump to v1.7.0-pre.2.
  • internal/oauth/manager.go: add AwaitToken (resume half of MRTR) and Cancel (tear down on decline); extract outcomeAfterFlow shared with joinWait. Existing flow behavior is unchanged.
  • internal/ghmcp/oauth.go: branch createOAuthMiddleware on negotiated protocol version; add the MRTR handler; keep the legacy handler identical.
  • internal/ghmcp/oauth_test.go: assert server-initiated elicitation is undeliverable on 2026-07-28; add MRTR middleware tests (accept / decline / no elicitation capability).

No tool schemas change, so no toolsnap/README regeneration.

Validation

script/lint and script/test (race) pass. The MRTR round trip (elicit → fulfill → retry → proceed) was validated end-to-end against a real in-memory 2026-07-28 client.

…und-trip elicitation

The go-sdk 1.7.0-pre.2 bump defaults to MCP protocol 2026-07-28, which per
SEP-2322 forbids the server from initiating JSON-RPC requests (including
`elicitation/create`) while serving a request. The OAuth login flow presents
the authorization prompt via `ServerSession.Elicit`, so on 2026-07-28 sessions
it now errors ("cannot be sent while serving a request ... return an
InputRequests map instead"), which broke TestSessionPrompterPromptActions and
would break real 2026-07-28 clients (stdio included, since server/discover is
transport-agnostic).

Migrate the OAuth middleware to multi-round-trip requests (MRTR) while keeping
pre-2026-07-28 clients unchanged:

- Legacy clients (< 2026-07-28) keep presenting the prompt via server-initiated
  elicitation exactly as before.
- Modern clients (>= 2026-07-28) receive the authorization prompt as an
  `InputRequests` elicitation returned from the tool call; the client fulfills
  it and retries, and the middleware then awaits the token and proceeds. This
  keeps the authorization URL out of the model context.

oauth.Manager gains AwaitToken (resume half of MRTR) and Cancel (tear down on
decline). Tests cover the accept/decline/no-capability MRTR paths and assert
that server-initiated elicitation is reported undeliverable on 2026-07-28.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 18e70efa-1b2d-4290-ba51-b82998db4ff8
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner July 13, 2026 21:15
Copilot AI review requested due to automatic review settings July 13, 2026 21:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates go-sdk and adapts OAuth for MCP 2026-07-28 multi-round-trip elicitation.

Changes:

  • Bumps go-sdk to v1.7.0-pre.2.
  • Adds OAuth resume/cancellation lifecycle support.
  • Adds protocol-aware OAuth middleware and MRTR tests.
Show a summary per file
File Description
go.mod Updates go-sdk dependency.
go.sum Updates dependency checksums.
internal/oauth/manager.go Adds token awaiting and flow cancellation.
internal/ghmcp/oauth.go Implements protocol-specific MRTR authorization.
internal/ghmcp/oauth_test.go Adds modern-protocol OAuth tests.
third-party-licenses.linux.md Updates Linux license reference.
third-party-licenses.darwin.md Updates macOS license reference.
third-party-licenses.windows.md Updates Windows license reference.

Review details

  • Files reviewed: 7/8 changed files
  • Comments generated: 4
  • Review effort level: Medium

Comment thread internal/ghmcp/oauth.go
Comment thread internal/ghmcp/oauth.go Outdated
Comment thread internal/ghmcp/oauth.go Outdated
Comment thread internal/oauth/manager.go Outdated
SamMorrowDrums and others added 2 commits July 14, 2026 00:18
Move OAuth interception into tool-handler middleware so go-sdk finalizes
multi-round-trip results with resultType input_required. Correlate responses to
a per-flow ID, retire cancellations synchronously, and ignore late completions
from stale flows.

Also preserve actionable URLs for form-only clients and add wire-level,
concurrency, and real manager lifecycle coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 18e70efa-1b2d-4290-ba51-b82998db4ff8
@SamMorrowDrums
SamMorrowDrums merged commit 05dc8a6 into main Jul 15, 2026
19 checks passed
@SamMorrowDrums
SamMorrowDrums deleted the sammorrowdrums-go-sdk-upgrade-fix branch July 15, 2026 13:35
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
github-mcp-server 1.7.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## Highlights
- Server to Server auth is now supported for GitHub apps via stdio so enterprise/cloud workloads can be supported
- Projects tools improved pagination 
- The latest changes for the MCP 2026-07-28 spec are included via `go-sdk to 1.7.0-pre.3`
- Lockdown mode improvements
 
## What's Changed
* build(deps): bump go-sdk to 1.7.0-pre.2 and migrate OAuth to multi-round-trip elicitation by @SamMorrowDrums in github/github-mcp-server#2870
* build(deps): bump github.com/go-chi/chi/v5 from 5.3.0 to 5.3.1 by @dependabot[bot] in github/github-mcp-server#2824
* build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 by @dependabot[bot] in github/github-mcp-server#2825
* build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0 by @dependabot[bot] in github/github-mcp-server#2826
* build(deps): bump docker/login-action from 4.2.0 to 4.4.0 by @dependabot[bot] in github/github-mcp-server#2827
* build(deps): bump golang from 1.25.11-alpine to 1.25.12-alpine by @dependabot[bot] in github/github-mcp-server#2867
* build(deps): bump distroless/base-debian12 from `e7e678c` to `9c05cfd` by @dependabot[bot] in github/github-mcp-server#2868
* Centralise lockdown author checks by @kerobbi in github/github-mcp-server#2881
* build(deps): bump actions/cache from 5 to 6 by @dependabot[bot] in github/github-mcp-server#2794
* build(deps): bump node from `a2dc166` to `e88a35b` by @dependabot[bot] in github/github-mcp-server#2792
* perf(octicons): embed precomputed data URIs by @SamMorrowDrums in github/github-mcp-server#2895
* fix(labels): add DestructiveHint to label_write tool by @syf2211 in github/github-mcp-server#2763
* build(deps): bump go-sdk to 1.7.0-pre.3 by @SamMorrowDrums in github/github-mcp-server#2907
* build(deps): bump distroless/base-debian12 from `9c05cfd` to `348dac1` by @dependabot[bot] in github/github-mcp-server#2915
* Paginate project item lookup across memberships by @zwick in github/github-mcp-server#2914
* Add opt-in intent-aware Copilot issue assignment tool by @boazreicher in github/github-mcp-server#2909
* Add node IDs to project resolver results by @zwick in github/github-mcp-server#2922
* Extract aliased project mutation primitive by @zwick in github/github-mcp-server#2923
* build: use patched Go toolchain and UI dependency by @loganrosen in github/github-mcp-server#2927
* feat(auth): add GitHub App server-to-server authentication for stdio by @SamMorrowDrums in github/github-mcp-server#2797
* build(deps): bump actions/setup-go from 6 to 7 by @dependabot[bot] in github/github-mcp-server#2916
* build(deps): bump actions/setup-node from 6 to 7 by @dependabot[bot] in github/github-mcp-server#2917
* build(deps): bump golang.org/x/oauth2 from 0.35.0 to 0.36.0 by @dependabot[bot] in github/github-mcp-server#2793
* Add MCP App form deferral opt-out by @connor4312 in github/github-mcp-server#2921
* build(deps): bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in github/github-mcp-server#2932

## New Contributors
* @loganrosen made their first contribution in github/github-mcp-server#2927

**Full Changelog**: https://github.com/github/github-mcp-server/compare/v1.6.0...v1.7.0</pre>
  <p>View the full release notes at <a href="https://github.com/github/github-mcp-server/releases/tag/v1.7.0">https://github.com/github/github-mcp-server/releases/tag/v1.7.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!14967
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants