fix(oauth): allow generic RFC 7591 DCR + expand install snippets
All checks were successful
Deploy to Production / deploy (push) Successful in 1m28s

- /oauth/register: drop resource_required check, accept generic
  registrations (Claude Desktop omits resource in DCR body per spec).
  serverId stored as NULL; /authorize still enforces org-ownership
  + access-token aud claim still pinned to resource. Fixes Claude
  Desktop DCR failure (ofid_d7e39530c109fa7f).
- /oauth/authorize: skip strict server.id check when client.serverId
  is NULL (generic client); org check remains the security boundary.
- schema: oauth_clients.server_id no longer NOT NULL.
- migration 0002: ALTER COLUMN server_id DROP NOT NULL (already
  applied on prod).
- install-snippets: add Claude Code (CLI), VS Code, Codex, raw URL
  tabs. Claude Desktop now shows form-field values (Name / Remote MCP
  Server URL / OAuth Client ID / Secret) matching the new Custom
  Connector UI instead of the obsolete JSON config.
- types: InstallTarget enum extended.
- hero-video: clicking the audio toggle restarts the video from
  frame 0 so unmute aligns with the spoken opening.
- marketing: drop em-dashes from rendered copy.
This commit is contained in:
Marco Sadjadi
2026-05-28 17:20:01 +02:00
parent e75f9ad4fe
commit 3a05766f88
9 changed files with 172 additions and 38 deletions

View File

@@ -175,5 +175,13 @@ export type IterateServerInput = z.infer<typeof IterateServerInput>;
// ---- Install snippets ----
export const InstallTarget = z.enum(['claude-desktop', 'cursor', 'chatgpt']);
export const InstallTarget = z.enum([
'claude-desktop',
'claude-code',
'cursor',
'vscode',
'chatgpt',
'codex',
'raw-url',
]);
export type InstallTarget = z.infer<typeof InstallTarget>;