ProxmoxMCP-Plus v0.5.25
Release date: 2026-10-07
OAuth browser callback fix
- Allow OAuth consent navigation to complete in Chromium when a registered
callback redirects through multiple origins. The consent page no longer sets
form-action, which was blocking the post-consent redirect chain even though
the server had accepted the API key and created an authorization code. - Return
303 See Otherafter a successful consent POST, explicitly switching
the callback request to GET. The SDK/authorizeredirect remains302. - Keep the form's POST target fixed to
/oauth/consent, HTML-escape client
details, and retain script/resource restrictions, anti-framing protections,
no-referrer/no-store headers and login-failure rate limiting. Invalid API keys
stay on the consent page without a callback redirect.
Includes PR #143.
Upgrade
Install proxmox-mcp-plus==0.5.25 or pull
ghcr.io/rekklesna/proxmoxmcp-plus:0.5.25, restart the MCP service and retry the
OAuth connection. No configuration or database migration is required. Registered
clients and issued OAuth credentials retain their existing lifecycle.
OAuth remains opt-in. Existing API-key mode and the v0.5.24 coordinated key-rotation
requirements are unchanged. Rolling back to v0.5.24 restores the consent policy
that can block browser callback navigation.
Validation
Independent real-Chromium testing with PostgreSQL and local callback services
reproduced the old provider's CSP-blocked navigation. The new provider completed
a three-origin redirect chain, authorization-code exchange and authenticated MCP
initialization. Cross-origin callback requests were GET with empty bodies and no
API key; invalid keys stayed on the consent page and HTML-like client names were
escaped. This test did not connect a live ChatGPT account.
Regression tests cover CSP headers, exact registered callback destinations,
303/302 behavior, state and issuer parameters, restart/multi-instance paths,
key rotation and failed authentication. CI checks Python 3.11/3.12, coverage,
Ruff, mypy, dependency auditing, build/release metadata and CodeQL.