(body: string)
| 102 | * GraphQL `{errors: [...]}` envelope, which a non-MCP OAuth-protected |
| 103 | * GraphQL API would return, is explicitly excluded. */ |
| 104 | const isOAuthErrorBody = (body: string): boolean => { |
| 105 | const obj = asObject(body); |
| 106 | if (!obj) return false; |
| 107 | if (Array.isArray(obj.errors)) return false; |
| 108 | return typeof obj.error === "string"; |
| 109 | }; |
| 110 | |
| 111 | /** RFC 9728 protected-resource-metadata document. We only need the two |
| 112 | * fields that prove the document genuinely describes an OAuth-protected |