fix: stop reporting client-error OAuth exceptions to Nightwatch - #261
Merged
Conversation
League\OAuth2\Server\Exception\OAuthServerException with a status below 500 (invalid/missing/expired bearer tokens, invalid_grant, etc.) represents a client error, not an application failure, but Passport's TokenGuard explicitly calls report() on every failed bearer-token check. This was flooding Nightwatch with 401 noise from bots probing the public MCP endpoint. Actual server_error (500) responses are still reported.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
TokenGuardexplicitly callsreport()on every failed bearer-token check (League\OAuth2\Server\Exception\OAuthServerException), including plain 401s from invalid/expired/missing tokens. This was flooding Nightwatch with alerts for bot/scanner traffic hitting the public MCP endpoint, and applies equally to the public REST API.dontReportWheninbootstrap/app.phpto ignoreOAuthServerExceptionwithgetHttpStatusCode() < 500— i.e. client errors (401/400/etc.), consistent with how Laravel already treatsAuthenticationException/AuthorizationException/ValidationExceptionby default. Genuineserver_error(500) responses are still reported.Test plan
tests/Feature/Passport/OAuthServerExceptionReportingTest.php— asserts client-error variants (accessDenied,invalidGrant,invalidRequest) are not reported,serverError(500) is still reported, and unrelated exceptions are unaffected.vendor/bin/pint --dirty --format agentphp artisan test --compact --filter=Passportandtests/Feature/Mcp(179 tests passing)