Skip to content

Fix Canva MCP connect after OAuth succeeds - #419

Merged
TheGreatAxios merged 10 commits into
mainfrom
cl-7083-fix-canva-mcp-connect-oauth-succeeds-then-the-connection
Aug 30, 2026
Merged

TheGreatAxios merged 10 commits into
mainfrom
cl-7083-fix-canva-mcp-connect-oauth-succeeds-then-the-connection

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

Summary

  • Pins Canva MCP connect probes to the same origins later tool calls allow, without following redirects
  • Sends Canva's advertised OAuth scopes at DCR and maps client-registration rejections to a distinct Plugins error
  • Shows the callback tool count on the Plugins row and raises MCP tool-call timeout above the SDK 60s default

Verification

Touched-package tests pass in the worktree. Live Canva-account connect is not verified on this branch.

Linear: CL-7083

Closes CL-7083

@TheGreatAxios TheGreatAxios left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review · Comment

Pins Canva MCP connect to the same origins later calls allow, sends advertised DCR scopes, and surfaces client-registration failures and tool count on the Plugins row.

Findings

  • packages/connections/src/mcp-oauth-routes.ts:84 — CLIENT_REJECTED_OAUTH_CODES includes invalid_redirect_uri, but SDK 1.30.0 parseErrorResponse maps that unmapped RFC 7591 code to ServerError (errorCode server_error). Set membership never fires; classification depends on description substrings. A DCR 400 {error: "invalid_redirect_uri"} with empty or unrelated error_description yields discovery_failed, not client_rejected.

Notes

  • Live Canva-account connect is not verified on this branch. Linear outcome boxes stay unchecked until that repro lands on main.

@TheGreatAxios TheGreatAxios left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Critic · Comment

Connect probes pin to the same origins later tool calls allow; DCR sends Canva scopes; Plugins maps client_rejected and hydrates tool count; MCP tool calls wait 2 minutes.

Findings

  • packages/connections/src/mcp-oauth-routes.ts:84 — invalid_redirect_uri in CLIENT_REJECTED_OAUTH_CODES is dead: SDK 1.30.0 maps it to ServerError. Classification falls through to description substrings. Untested path: DCR 400 {error: "invalid_redirect_uri"} with empty error_description yields discovery_failed.

Notes

  • packages/connections/src/mcp-oauth-routes.ts:116 — substring matching on Error.message can misclassify a discovery/network throw as client_rejected.
  • packages/plugins-ui/src/mcp-preset-cards.tsx:258 — toolCounts is seeded only from the OAuth return query; a later /plugins load without toolCount falls back to a bare Connected.
  • packages/mcp-tools/src/mcp-client.ts:28 — the 2 minute timeout also applies to listMcpTools, so a hung post-auth tools/list can block the callback for 2 minutes.
  • packages/credential-providers/src/mcp-origin-pinned-fetch.ts:13 — extras allow https://canva.ai when pinned to https://mcp.canva.com; canva.com remains refused.
  • packages/connections/src/mcp-oauth.ts:142 — refreshMcpOAuthTokens still constructs the provider without scope.

@TheGreatAxios
TheGreatAxios force-pushed the cl-7083-fix-canva-mcp-connect-oauth-succeeds-then-the-connection branch 5 times, most recently from 0e32828 to c9ad47f Compare August 29, 2026 17:42
Connect used an unpinned fetch that followed redirects, so a
handshake could succeed while later tool calls refused Canva's
https://canva.ai first hop. Extra origins are an explicit map;
3xx is never followed.
Canva's protected-resource metadata advertises the scopes its
MCP tools need. Including them in dynamic client registration
keeps the authorize request explicit instead of relying on
server-side defaults.
/start now maps DCR and client-metadata rejections to
code=client_rejected so Plugins can say the app refused
Workbench as a client, instead of a generic discovery
failure.
The callback already sends toolCount; the Plugins card
ignored it and showed a bare Connected.
The SDK times out at 60s, which is the documented duration
of long tools. Two minutes sits under the 5 minute chat
turn so a slow call can finish without outliving the turn.
SDK 1.30.0 maps unknown codes such as invalid_redirect_uri onto
ServerError and drops the original error. Capture the HTTP body's
error field before that mapping so an empty description still
redirects as client_rejected.
Launch already knows the ref is missing (resolveRef returns null) and
then called through to listAssetBlobs, which throws and kills every
agent on the tenant. The tarball REST list already returns [] for the
same not_found. Pins against a missing tarball still fail as unknown
package.
@TheGreatAxios
TheGreatAxios force-pushed the cl-7083-fix-canva-mcp-connect-oauth-succeeds-then-the-connection branch from 5f51710 to 6ec8741 Compare August 30, 2026 00:39

@TheGreatAxios TheGreatAxios left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critique · approve

Canva MCP connect path matches the brief: shared origin pin (mcp.canva.com plus canva.ai first hop, no 3xx follow), DCR scopes, client_rejected for RFC 7591 4xx, toolCount on return, 120s tool timeout, empty package-registry catalog. mcp-tools 0.0.10 matches the timeout source change. No DATABASE_URL leak.

Live Canva OAuth is still unverified (docs already say so) — not a code defect.

GitHub will not accept approve on the author's own PR; this comment is the review.

@TheGreatAxios
TheGreatAxios merged commit a235d17 into main Aug 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant