Skip to content

oauthex: ParseWWWAuthenticate fails on whitespace around "=" in an auth-param #1321

Description

@akshita317

What did you do?

Parsed a WWW-Authenticate header that has whitespace around the = of an auth-param after the first one. RFC 9110 section 11.2 allows this (auth-param = token BWS "=" BWS ( token / quoted-string )):

cs, err := oauthex.ParseWWWAuthenticate([]string{
	`Bearer realm="mcp", scope = "files:read"`,
})
fmt.Printf("%+v %v\n", cs, err)

What did you see?

[] failed to parse challenge " scope = \"files:read\"": malformed auth parameter: expected key=value, but got "= \"files:read\""

splitChallenges decides whether the text after a comma starts a new challenge by checking that everything before the next = is one token with no whitespace. With scope = ... the candidate is scope (trailing space), so it is taken for a new challenge named scope, which then fails to parse. ParseWWWAuthenticate returns the error, and AuthorizationCodeHandler.Authorize (and extauth.ClientCredentialsHandler) stop with failed to parse WWW-Authenticate header, so the client cannot authorize against such a server at all.

A space only before the first parameter (Bearer realm = "mcp") already works, because parseSingleChallenge trims around the key and value; only the splitter is affected.

What did you expect to see?

One bearer challenge with realm and scope.

What version of the Go MCP SDK are you using?

v1.8.0, and main at the time of writing.

What version of Go are you using (go version)?

go1.25.3 windows/amd64 (also reproduced with the go1.26 toolchain).

I have a fix with tests ready and will link the PR here.

Activity

  1. akshita317 commented on Sep 30, 2026

    @akshita317
    ContributorAuthor

    Fix with tests in #1322.

  2. added a commit that references this issue on Oct 1, 2026
    53effc0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions