build(deps): bump go-sdk to 1.7.0-pre.2 and migrate OAuth to multi-round-trip elicitation - #2870
Merged
Merged
Conversation
…und-trip elicitation
The go-sdk 1.7.0-pre.2 bump defaults to MCP protocol 2026-07-28, which per
SEP-2322 forbids the server from initiating JSON-RPC requests (including
`elicitation/create`) while serving a request. The OAuth login flow presents
the authorization prompt via `ServerSession.Elicit`, so on 2026-07-28 sessions
it now errors ("cannot be sent while serving a request ... return an
InputRequests map instead"), which broke TestSessionPrompterPromptActions and
would break real 2026-07-28 clients (stdio included, since server/discover is
transport-agnostic).
Migrate the OAuth middleware to multi-round-trip requests (MRTR) while keeping
pre-2026-07-28 clients unchanged:
- Legacy clients (< 2026-07-28) keep presenting the prompt via server-initiated
elicitation exactly as before.
- Modern clients (>= 2026-07-28) receive the authorization prompt as an
`InputRequests` elicitation returned from the tool call; the client fulfills
it and retries, and the middleware then awaits the token and proceeds. This
keeps the authorization URL out of the model context.
oauth.Manager gains AwaitToken (resume half of MRTR) and Cancel (tear down on
decline). Tests cover the accept/decline/no-capability MRTR paths and assert
that server-initiated elicitation is reported undeliverable on 2026-07-28.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 18e70efa-1b2d-4290-ba51-b82998db4ff8
Contributor
There was a problem hiding this comment.
Pull request overview
Updates go-sdk and adapts OAuth for MCP 2026-07-28 multi-round-trip elicitation.
Changes:
- Bumps go-sdk to
v1.7.0-pre.2. - Adds OAuth resume/cancellation lifecycle support.
- Adds protocol-aware OAuth middleware and MRTR tests.
Show a summary per file
| File | Description |
|---|---|
go.mod |
Updates go-sdk dependency. |
go.sum |
Updates dependency checksums. |
internal/oauth/manager.go |
Adds token awaiting and flow cancellation. |
internal/ghmcp/oauth.go |
Implements protocol-specific MRTR authorization. |
internal/ghmcp/oauth_test.go |
Adds modern-protocol OAuth tests. |
third-party-licenses.linux.md |
Updates Linux license reference. |
third-party-licenses.darwin.md |
Updates macOS license reference. |
third-party-licenses.windows.md |
Updates Windows license reference. |
Review details
- Files reviewed: 7/8 changed files
- Comments generated: 4
- Review effort level: Medium
Move OAuth interception into tool-handler middleware so go-sdk finalizes multi-round-trip results with resultType input_required. Correlate responses to a per-flow ID, retire cancellations synchronously, and ignore late completions from stale flows. Also preserve actionable URLs for form-only clients and add wire-level, concurrency, and real manager lifecycle coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 18e70efa-1b2d-4290-ba51-b82998db4ff8
13 tasks
social4hyq
pushed a commit
to social4hyq/homebrew-core
that referenced
this pull request
Sep 20, 2026
github-mcp-server 1.7.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>## Highlights - Server to Server auth is now supported for GitHub apps via stdio so enterprise/cloud workloads can be supported - Projects tools improved pagination - The latest changes for the MCP 2026-07-28 spec are included via `go-sdk to 1.7.0-pre.3` - Lockdown mode improvements ## What's Changed * build(deps): bump go-sdk to 1.7.0-pre.2 and migrate OAuth to multi-round-trip elicitation by @SamMorrowDrums in github/github-mcp-server#2870 * build(deps): bump github.com/go-chi/chi/v5 from 5.3.0 to 5.3.1 by @dependabot[bot] in github/github-mcp-server#2824 * build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 by @dependabot[bot] in github/github-mcp-server#2825 * build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0 by @dependabot[bot] in github/github-mcp-server#2826 * build(deps): bump docker/login-action from 4.2.0 to 4.4.0 by @dependabot[bot] in github/github-mcp-server#2827 * build(deps): bump golang from 1.25.11-alpine to 1.25.12-alpine by @dependabot[bot] in github/github-mcp-server#2867 * build(deps): bump distroless/base-debian12 from `e7e678c` to `9c05cfd` by @dependabot[bot] in github/github-mcp-server#2868 * Centralise lockdown author checks by @kerobbi in github/github-mcp-server#2881 * build(deps): bump actions/cache from 5 to 6 by @dependabot[bot] in github/github-mcp-server#2794 * build(deps): bump node from `a2dc166` to `e88a35b` by @dependabot[bot] in github/github-mcp-server#2792 * perf(octicons): embed precomputed data URIs by @SamMorrowDrums in github/github-mcp-server#2895 * fix(labels): add DestructiveHint to label_write tool by @syf2211 in github/github-mcp-server#2763 * build(deps): bump go-sdk to 1.7.0-pre.3 by @SamMorrowDrums in github/github-mcp-server#2907 * build(deps): bump distroless/base-debian12 from `9c05cfd` to `348dac1` by @dependabot[bot] in github/github-mcp-server#2915 * Paginate project item lookup across memberships by @zwick in github/github-mcp-server#2914 * Add opt-in intent-aware Copilot issue assignment tool by @boazreicher in github/github-mcp-server#2909 * Add node IDs to project resolver results by @zwick in github/github-mcp-server#2922 * Extract aliased project mutation primitive by @zwick in github/github-mcp-server#2923 * build: use patched Go toolchain and UI dependency by @loganrosen in github/github-mcp-server#2927 * feat(auth): add GitHub App server-to-server authentication for stdio by @SamMorrowDrums in github/github-mcp-server#2797 * build(deps): bump actions/setup-go from 6 to 7 by @dependabot[bot] in github/github-mcp-server#2916 * build(deps): bump actions/setup-node from 6 to 7 by @dependabot[bot] in github/github-mcp-server#2917 * build(deps): bump golang.org/x/oauth2 from 0.35.0 to 0.36.0 by @dependabot[bot] in github/github-mcp-server#2793 * Add MCP App form deferral opt-out by @connor4312 in github/github-mcp-server#2921 * build(deps): bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in github/github-mcp-server#2932 ## New Contributors * @loganrosen made their first contribution in github/github-mcp-server#2927 **Full Changelog**: https://github.com/github/github-mcp-server/compare/v1.6.0...v1.7.0</pre> <p>View the full release notes at <a href="https://github.com/github/github-mcp-server/releases/tag/v1.7.0">https://github.com/github/github-mcp-server/releases/tag/v1.7.0</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!14967
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Supersedes the Dependabot bump #2869. Bumping
modelcontextprotocol/go-sdktov1.7.0-pre.2alone fails CI (TestSessionPrompterPromptActions) and would break OAuth for real clients.Root cause: pre.2 defaults to MCP protocol 2026-07-28, which (per SEP-2322) forbids the server from initiating JSON-RPC requests — including
elicitation/create— while serving a request. The OAuth login flow presents its authorization prompt viaServerSession.Elicit(...)duringtools/call, so on 2026-07-28 sessions it now errors:The new model requires returning an
InputRequestsmap from the tool call; the client fulfills it and retries (multi-round-trip / MRTR).This is not transport-specific: the legacy
initializehandshake is capped at2025-11-25, but the newserver/discover(SEP-2575) path — attempted by pre.2 clients on any transport, stdio included — negotiates2026-07-28, whereElicitis unconditionally blocked.What
Migrate the OAuth middleware to MRTR, without changing behavior for pre-2026-07-28 clients:
tools/callreturns the authorization prompt as anInputRequestselicitation; the client presents it (keeping the auth URL out of the model's context) and retries with the response, at which point the middleware awaits the token and proceeds. Clients without elicitation capability fall back to the existing tool-result instructions.The branch is required because our OAuth middleware is outermost while the SDK's
serverMultiRoundTripMiddleware(which transparently services legacy clients) is innermost, so it can't fulfill our middleware'sInputRequests— legacy clients therefore keep the directElicitpath.Changes
go.mod/go.sum+third-party-licenses.*.md: bump tov1.7.0-pre.2.internal/oauth/manager.go: addAwaitToken(resume half of MRTR) andCancel(tear down on decline); extractoutcomeAfterFlowshared withjoinWait. Existing flow behavior is unchanged.internal/ghmcp/oauth.go: branchcreateOAuthMiddlewareon negotiated protocol version; add the MRTR handler; keep the legacy handler identical.internal/ghmcp/oauth_test.go: assert server-initiated elicitation is undeliverable on 2026-07-28; add MRTR middleware tests (accept / decline / no elicitation capability).No tool schemas change, so no toolsnap/README regeneration.
Validation
script/lintandscript/test(race) pass. The MRTR round trip (elicit → fulfill → retry → proceed) was validated end-to-end against a real in-memory 2026-07-28 client.