Files
hermes-agent/tools
teknium1 e166791f9f fix(mcp): treat a non-object client.json as corrupt instead of crashing auth init
_cached_redirect already degraded a list/str/number client.json to
(None, None), but one step later the MCP SDK calls
storage.get_client_info() while building OAuthClientProvider, and
_load_model ran the fixup (data.get) outside its try, so the same payload
still raised AttributeError out of the OAuth flow. Guard isinstance(dict)
in _load_model (warn + None, like any other corrupt file; also covers the
tokens fixup's data.pop) and make _cached_client_info return None for
non-object payloads so CIMD eligibility and redirect reuse see "no cached
registration" rather than a registration that can never load.

Part of #112568
2026-09-16 16:50:27 -07:00
..