Describe the bug
When web_fetch requests an authenticated URL, it follows the redirect to the identity provider and returns the sign-in page as if it were the requested content. The tool does not clearly report that authentication is required or expose the redirect as an authentication failure.
This can cause the model to mistake a login page for a successful fetch and prevents it from choosing an authenticated tool or asking the user to sign in
Affected version
GitHub Copilot CLI 1.0.89-7
Steps to reproduce the behavior
- Start GitHub Copilot CLI.
- Ask the agent to fetch a page that requires authentication, for example:
- Allow the agent to call
web_fetch.
- Inspect the returned URL and content.
Expected behavior
web_fetch should return a structured result indicating that authentication is required, for example:
Authentication required.
The requested URL redirected to a sign-in page.
The result should include the original URL and redirect destination so the agent can select an authenticated integration or explain the limitation accurately.
Actual result
web_fetch followed the authentication redirect and returned the identity provider page as successful content
Additional context
- OS: Microsoft Windows 11 Enterprise
- OS version:
10.0.26100 (build 26100)
- Architecture: AMD64
- Shell: PowerShell Core
7.6.6
Describe the bug
When
web_fetchrequests an authenticated URL, it follows the redirect to the identity provider and returns the sign-in page as if it were the requested content. The tool does not clearly report that authentication is required or expose the redirect as an authentication failure.This can cause the model to mistake a login page for a successful fetch and prevents it from choosing an authenticated tool or asking the user to sign in
Affected version
GitHub Copilot CLI
1.0.89-7Steps to reproduce the behavior
web_fetch.Expected behavior
web_fetchshould return a structured result indicating that authentication is required, for example:The result should include the original URL and redirect destination so the agent can select an authenticated integration or explain the limitation accurately.
Actual result
web_fetch followed the authentication redirect and returned the identity provider page as successful content
Additional context
10.0.26100(build26100)7.6.6