What did you do?
Parsed a WWW-Authenticate header that has whitespace around the = of an auth-param after the first one. RFC 9110 section 11.2 allows this (auth-param = token BWS "=" BWS ( token / quoted-string )):
cs, err := oauthex.ParseWWWAuthenticate([]string{
`Bearer realm="mcp", scope = "files:read"`,
})
fmt.Printf("%+v %v\n", cs, err)
What did you see?
[] failed to parse challenge " scope = \"files:read\"": malformed auth parameter: expected key=value, but got "= \"files:read\""
splitChallenges decides whether the text after a comma starts a new challenge by checking that everything before the next = is one token with no whitespace. With scope = ... the candidate is scope (trailing space), so it is taken for a new challenge named scope, which then fails to parse. ParseWWWAuthenticate returns the error, and AuthorizationCodeHandler.Authorize (and extauth.ClientCredentialsHandler) stop with failed to parse WWW-Authenticate header, so the client cannot authorize against such a server at all.
A space only before the first parameter (Bearer realm = "mcp") already works, because parseSingleChallenge trims around the key and value; only the splitter is affected.
What did you expect to see?
One bearer challenge with realm and scope.
What version of the Go MCP SDK are you using?
v1.8.0, and main at the time of writing.
What version of Go are you using (go version)?
go1.25.3 windows/amd64 (also reproduced with the go1.26 toolchain).
I have a fix with tests ready and will link the PR here.
What did you do?
Parsed a
WWW-Authenticateheader that has whitespace around the=of an auth-param after the first one. RFC 9110 section 11.2 allows this (auth-param = token BWS "=" BWS ( token / quoted-string )):What did you see?
splitChallengesdecides whether the text after a comma starts a new challenge by checking that everything before the next=is one token with no whitespace. Withscope = ...the candidate isscope(trailing space), so it is taken for a new challenge namedscope, which then fails to parse.ParseWWWAuthenticatereturns the error, andAuthorizationCodeHandler.Authorize(andextauth.ClientCredentialsHandler) stop withfailed to parse WWW-Authenticate header, so the client cannot authorize against such a server at all.A space only before the first parameter (
Bearer realm = "mcp") already works, becauseparseSingleChallengetrims around the key and value; only the splitter is affected.What did you expect to see?
One
bearerchallenge withrealmandscope.What version of the Go MCP SDK are you using?
v1.8.0, and
mainat the time of writing.What version of Go are you using (
go version)?go1.25.3 windows/amd64 (also reproduced with the go1.26 toolchain).
I have a fix with tests ready and will link the PR here.