Skip to main content

Technical~/notes/oauth-303-redirect.md

Two bugs, one OAuth handshake, and a 303 that saved me

oauthmcphttp

I wanted an AI chat app to talk to my site through MCP. Its custom connector always tries an OAuth handshake, so I built a tiny OAuth server. Then it broke. Twice

Bug 1: the login ate my redirect

After logging in, I sent people back to the full https:// URL. My CMS login page only accepts paths on the same site, and anything else quietly sends you to the admin dashboard. So you'd log in and just... land on the dashboard. No error

Bug 2: 307 vs 303

Clicking "approve" sends a form POST. I redirected back to the app with the default 307, which keeps it a POST. The app's callback only takes GET, so it said no

The fix was one number. A 303 always turns the next request into a GET