Found in the 2026-09-28 code audit (finding N-6).
Where: internal/mcp/oauth_store.go:26-32 (StoredToken), internal/mcp/network_client.go:842-847 (config()), :860-869 (Refresh), internal/mcp/oauth.go:334-340, :449-463; internal/oauth/flow.go:167-169.
Problem: Login discovers TokenEndpoint (RFC 9728 / 8414) and obtains ClientID/ClientSecret through dynamic registration, but none of it is persisted. On a 401, Refresh reads only the config-file OAuthConfig, whose TokenEndpoint is empty for the standard auth: oauth setup, giving "no token endpoint configured for refresh". Users must re-run zero mcp oauth login each time the access token expires. No test covers refresh after a discovery-based login.
Suggested fix: add TokenEndpoint, ClientID, ClientSecret to StoredToken, fall back to them in Refresh, and re-validate the stored endpoint with ValidateEndpointURL / validateProtectedDiscoveredEndpoints before use.
Found in the 2026-09-28 code audit (finding N-6).
Where:
internal/mcp/oauth_store.go:26-32(StoredToken),internal/mcp/network_client.go:842-847(config()),:860-869(Refresh),internal/mcp/oauth.go:334-340,:449-463;internal/oauth/flow.go:167-169.Problem:
LogindiscoversTokenEndpoint(RFC 9728 / 8414) and obtainsClientID/ClientSecretthrough dynamic registration, but none of it is persisted. On a 401,Refreshreads only the config-fileOAuthConfig, whoseTokenEndpointis empty for the standardauth: oauthsetup, giving "no token endpoint configured for refresh". Users must re-runzero mcp oauth logineach time the access token expires. No test covers refresh after a discovery-based login.Suggested fix: add
TokenEndpoint,ClientID,ClientSecrettoStoredToken, fall back to them inRefresh, and re-validate the stored endpoint withValidateEndpointURL/validateProtectedDiscoveredEndpointsbefore use.