Technical~/notes/oauth-303-redirect.md
Two bugs, one OAuth handshake, and a 303 that saved me
oauthmcphttp
I wanted an AI chat app to talk to my site through MCP. Its custom connector always tries an OAuth handshake, so I built a tiny OAuth server. Then it broke. Twice
Bug 1: the login ate my redirect
After logging in, I sent people back to the full https:// URL. My CMS login page only accepts paths on the same site, and anything else quietly sends you to the admin dashboard. So you'd log in and just... land on the dashboard. No error
Bug 2: 307 vs 303
Clicking "approve" sends a form POST. I redirected back to the app with the default 307, which keeps it a POST. The app's callback only takes GET, so it said no
The fix was one number. A 303 always turns the next request into a GET