feat(mcp): add OAuth support to MCP install flow

Squash merge PR #1583.

This merge commit was created by an AI agent (OpenHands) on behalf of Graham Neubig.

Co-authored-by: openhands <openhands@all-hands.dev>
This commit is contained in:
Graham Neubig
2026-07-07 12:03:36 +02:00
committed by GitHub
co-authored by openhands
parent d2cfffb7ef
commit c552545926
85 changed files with 5713 additions and 835 deletions
+6 -6
View File
@@ -19,7 +19,7 @@
*
* Usage:
* node scripts/check-sdk-version-sync.mjs
* EXPECTED_SDK_VERSION=1.31.1 node scripts/check-sdk-version-sync.mjs
* EXPECTED_SDK_VERSION=1.32.0 node scripts/check-sdk-version-sync.mjs
* node scripts/check-sdk-version-sync.mjs --check-pypi
*
* Environment variables:
@@ -78,7 +78,7 @@ Triggering from other repos:
-H "Authorization: token \$GITHUB_TOKEN" \\
-H "Accept: application/vnd.github.v3+json" \\
https://api.github.com/repos/OpenHands/agent-canvas/dispatches \\
-d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.31.1"}}'
-d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.32.0"}}'
`);
process.exit(0);
}
@@ -260,9 +260,9 @@ async function fetchPyPIDependencies(packageName, version) {
* Parse PyPI requires_dist array and extract SDK package versions
*
* PyPI returns dependencies in PEP 508 format like:
* "openhands-sdk>=1.31.1,<2.0.0"
* "openhands-tools==1.31.1"
* "openhands-workspace (>=1.31.1)"
* "openhands-sdk>=1.32.0,<2.0.0"
* "openhands-tools==1.32.0"
* "openhands-workspace (>=1.32.0)"
*/
function parseSdkVersionsFromRequiresDist(requiresDist) {
const versions = {};
@@ -276,7 +276,7 @@ function parseSdkVersionsFromRequiresDist(requiresDist) {
}
// Extract the version number - look for patterns like:
// ">=1.31.1", "==1.31.1", "(>=1.31.1)", "~=1.31.1"
// ">=1.32.0", "==1.32.0", "(>=1.32.0)", "~=1.32.0"
// After the package name and before any comma or closing paren
const versionPattern = /[><=~!]+\s*([0-9]+(?:\.[0-9]+)*)/;
const match = dep.match(versionPattern);
@@ -38,7 +38,12 @@ const IDENTICAL_VALUE_ALLOWLIST = new Set([
'SETTINGS$CLOUD_SETTINGS_LINK',
'SETTINGS$GITHUB',
'SETTINGS$GITLAB',
'SETTINGS$MCP_AUTH_MODE_OAUTH',
'SETTINGS$MCP_DEFAULT_CONFIG',
'SETTINGS$MCP_HEADERS_PLACEHOLDER',
'SETTINGS$MCP_OAUTH_CLIENT_ID_PLACEHOLDER',
'SETTINGS$MCP_OAUTH_CLIENT_SECRET_PLACEHOLDER',
'SETTINGS$MCP_OAUTH_SCOPES_PLACEHOLDER',
'SETTINGS$MCP_SERVER_TYPE_SHTTP',
'SETTINGS$MCP_SERVER_TYPE_SSE',
'SETTINGS$MCP_SERVER_TYPE_STDIO',
+2 -2
View File
@@ -48,7 +48,7 @@ const LOCAL_AGENT_SERVER_SUBDIRS = [
"openhands-workspace",
];
const DEFAULT_AGENT_SERVER_VERSION = SHARED_DEFAULTS.versions.agentServer;
// Temporary transitive-dep pin: openhands-sdk 1.31.1 leaves agent-client-protocol
// Temporary transitive-dep pin: openhands-sdk 1.32.0 leaves agent-client-protocol
// unbounded (>=0.10.1), but acp 0.11.0 reordered the ACP prompt() args and breaks
// the SDK's ACP client. Hold acp <0.11 until a fixed SDK ships. See config/defaults.json.
const AGENT_CLIENT_PROTOCOL_CONSTRAINT =
@@ -399,7 +399,7 @@ export function validateFrontendDependencies(
* edits are picked up without a manual reinstall. The agent-server itself
* is rebuilt from local source on each invocation (--reinstall).
* - OH_AGENT_SERVER_GIT_REF: Git commit SHA or branch name
* - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.31.1")
* - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.32.0")
*
* If none are set, defaults to the released version specified by
* DEFAULT_AGENT_SERVER_VERSION. Set OH_AGENT_SERVER_GIT_REF to use a
+4
View File
@@ -748,6 +748,8 @@ function startAgentServer(config) {
const agentServerEnv = {
...buildAgentServerEnv(safeConfig),
...buildAgentServerAutomationEnv(config),
OPENHANDS_REMOTE_WS_READY_REQUIRED:
process.env.OPENHANDS_REMOTE_WS_READY_REQUIRED || "false",
// Ensure the agent-server uses the resolved key from config. This is
// LOCAL_BACKEND_API_KEY when set, or the auto-generated persisted key.
OH_SESSION_API_KEYS_0: config.sessionApiKey,
@@ -803,6 +805,8 @@ function startAutomationBackend(config) {
// Force UTF-8 for all Python file I/O (same reason as agent-server;
// see buildAgentServerEnv in dev-safe.mjs).
PYTHONUTF8: "1",
OPENHANDS_REMOTE_WS_READY_REQUIRED:
process.env.OPENHANDS_REMOTE_WS_READY_REQUIRED || "false",
// The URL the automation backend itself uses to call the
// agent-server's REST API (tarball upload + bash dispatch).
//