mirror of
https://github.com/openai/plugins.git
synced 2026-10-02 04:04:38 +08:00
Enable GitHub API OAuth and document public clients (#395)
Enable GitHub remote MCP OAuth with the tested public client credentials and callback, and add GitHub to the API marketplace. Add GitHub and Slack README warnings explaining public OAuth client identity. Validation: JSON/config checks passed; live OAuth was not rerun.
This commit is contained in:
@@ -652,6 +652,18 @@
|
||||
"interface": {
|
||||
"displayName": "Qodo"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "github",
|
||||
"source": {
|
||||
"source": "local",
|
||||
"path": "./plugins/github"
|
||||
},
|
||||
"policy": {
|
||||
"installation": "AVAILABLE",
|
||||
"authentication": "ON_INSTALL"
|
||||
},
|
||||
"category": "Developer Tools"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "github",
|
||||
"version": "0.1.11",
|
||||
"version": "0.1.12",
|
||||
"description": "Inspect repositories, triage pull requests and issues, debug CI, and publish changes through a hybrid GitHub connector and CLI workflow.",
|
||||
"author": {
|
||||
"name": "OpenAI",
|
||||
@@ -26,6 +26,7 @@
|
||||
"actions"
|
||||
],
|
||||
"apps": "./.app.json",
|
||||
"mcpServers": "./.mcp.json",
|
||||
"interface": {
|
||||
"displayName": "GitHub",
|
||||
"shortDescription": "Triage PRs, issues, CI, and publish flows",
|
||||
|
||||
@@ -3,7 +3,12 @@
|
||||
"github": {
|
||||
"type": "http",
|
||||
"url": "https://api.githubcopilot.com/mcp/",
|
||||
"bearer_token_env_var": "GITHUB_PAT_TOKEN"
|
||||
"oauth": {
|
||||
"client_id": "Iv23liZgMPSa3samkW2k",
|
||||
"client_secret": "824c9cd33b8de28213447789c7517ad720138be5",
|
||||
"callback_port": 12799,
|
||||
"callback_url": "http://127.0.0.1:12799/callback/ymAt1Jnt6ghN"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
# GitHub
|
||||
|
||||
**Warning: this plugin is a public OAuth client.** Its OAuth client ID and
|
||||
`client_secret` are intentionally distributed in [`.mcp.json`](.mcp.json).
|
||||
Anyone can copy these values, so they cannot prove that a request comes from this
|
||||
plugin. User access and refresh tokens must still be kept private.
|
||||
|
||||
For more context, see Okta's
|
||||
[The Identity of OAuth Public Clients](https://developer.okta.com/blog/2022/06/01/oauth-public-client-identity).
|
||||
@@ -0,0 +1,10 @@
|
||||
# Slack
|
||||
|
||||
**Warning: this plugin is a public OAuth client.** Its OAuth `client_id` is
|
||||
published in [`.mcp.json`](.mcp.json), and no client secret is included. The public
|
||||
ID can be copied to impersonate the client in OAuth requests; it cannot prove
|
||||
that a request comes from this plugin. Access to a Slack account still requires
|
||||
user authorization.
|
||||
|
||||
For more context, see Okta's
|
||||
[The Identity of OAuth Public Clients](https://developer.okta.com/blog/2022/06/01/oauth-public-client-identity).
|
||||
Reference in New Issue
Block a user