From 41f873da6e83caa727f82eaa1fe5819828726efb Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Wed, 2 Sep 2026 16:28:35 -0700 Subject: [PATCH] refactor(mcp): HermesProviderMixin reuses HermesTokenStorage._coerce_secret_auth_method for the in-memory client-secret coercion --- tools/mcp_oauth_provider.py | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/tools/mcp_oauth_provider.py b/tools/mcp_oauth_provider.py index 80224338b6..60b34b8607 100644 --- a/tools/mcp_oauth_provider.py +++ b/tools/mcp_oauth_provider.py @@ -49,16 +49,17 @@ class HermesProviderMixin: return request def _coerce_client_secret_post(self) -> None: + """Same rule as ``HermesTokenStorage._coerce_secret_auth_method``, applied + to the in-memory client info right before a token-endpoint request.""" info = self.context.client_info - if not info or not getattr(info, "client_secret", None): - return - if getattr(info, "token_endpoint_auth_method", None) not in (None, "none", ""): + if not info: return from mcp.shared.auth import OAuthClientInformationFull + from tools.mcp_oauth import HermesTokenStorage data = info.model_dump(mode="json", exclude_none=True) - data["token_endpoint_auth_method"] = "client_secret_post" - self.context.client_info = OAuthClientInformationFull.model_validate(data) + if HermesTokenStorage._coerce_secret_auth_method(data): + self.context.client_info = OAuthClientInformationFull.model_validate(data) async def _exchange_token_authorization_code(self, *args: Any, **kwargs: Any): self._coerce_client_secret_post()