Skip to content

web_fetch treats authentication redirects as successful page content #5002

Description

@mcodilla

Describe the bug

When web_fetch requests an authenticated URL, it follows the redirect to the identity provider and returns the sign-in page as if it were the requested content. The tool does not clearly report that authentication is required or expose the redirect as an authentication failure.

This can cause the model to mistake a login page for a successful fetch and prevents it from choosing an authenticated tool or asking the user to sign in

Affected version

GitHub Copilot CLI 1.0.89-7

Steps to reproduce the behavior

  1. Start GitHub Copilot CLI.
  2. Ask the agent to fetch a page that requires authentication, for example:
  3. Allow the agent to call web_fetch.
  4. Inspect the returned URL and content.

Expected behavior

web_fetch should return a structured result indicating that authentication is required, for example:

Authentication required.
The requested URL redirected to a sign-in page.

The result should include the original URL and redirect destination so the agent can select an authenticated integration or explain the limitation accurately.

Actual result

web_fetch followed the authentication redirect and returned the identity provider page as successful content

Additional context

  • OS: Microsoft Windows 11 Enterprise
  • OS version: 10.0.26100 (build 26100)
  • Architecture: AMD64
  • Shell: PowerShell Core 7.6.6

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:toolsBuilt-in tools: file editing, shell, search, LSP, git, and tool call behavior

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions