Skip to content

[Server] OIDC discovery fails for issuers with a trailing slash #507

Description

@karedum

OIDC discovery fails for issuers with a trailing slash

OidcDiscovery::fetchMetadata() strips the trailing slash from the issuer before discovery:

$issuer = rtrim($issuer, '/');

The normalized issuer is then used to validate the issuer returned in the discovery metadata.

This causes discovery to fail for providers that use a trailing slash in their canonical issuer, such as Authentik:

Expected: https://auth.example.com/application/o/mcp
Got:      https://auth.example.com/application/o/mcp/

The trailing slash should only be removed when building the discovery URL. The original issuer should be preserved for validation.

Related PR

Activity

  1. chr-hertel commented on Sep 14, 2026

    @chr-hertel
    Member

    Addressed with #506

  2. added
    ServerIssues & PRs related to the Server component
    on Sep 14, 2026
  3. changed the title [-]OIDC discovery fails for issuers with a trailing slash[/-] [+][Server]OIDC discovery fails for issuers with a trailing slash[/+] on Sep 14, 2026
  4. changed the title [-][Server]OIDC discovery fails for issuers with a trailing slash[/-] [+][Server] OIDC discovery fails for issuers with a trailing slash[/+] on Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ServerIssues & PRs related to the Server component

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions