Reported issues for abap-adt-mcp
Pod holds 5 of 5 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to abap-adt-mcp.
Most discussed
authType cert: X.509 client-certificate logon for technical users (no password, no browser)
Why
tls.cert / tls.key / tls.pfx exist per destination, but only as transport material under basic, sso or oauth. An on-premise system that maps X.509 certificates to users (CERTRULE / VUSREXTID) can log a user on with the certificate alone, and a technical user with a certificate on disk is the on-premise equivalent of the OAuth client-credentials mode: unattended, no password, no browser. Today that setup is impossible: basic demands a password and sso opens a browser.
##…
Read the thread · 2026-09-14 · open · 1 comment
SLC path: validate and harden browser SSO against on-premise systems with client certificates and Kerberos
Why
SAP Secure Login Client (SLC) puts a short-lived X.509 user certificate into the OS key store (Windows certificate store, macOS Keychain) with a non-exportable private key. Chromium already uses that store for TLS client authentication, so the existing sso mode is the natural SLC path: the browser presents the certificate, the ABAP system logs the user on, and the server harvests the session cookies. The private key never leaves the OS store and the server only holds cookies in…
Read the thread · 2026-09-14 · open · 1 comment
VS Code rejects every chat request: five tool schemas declare arrays without items
Found while running Phase 1 of #17 (#18) on Windows 11, VS Code with Copilot agent mode, MCP_TOOLSETS=focused, abap-adt-mcp 2.1.1 from npm.
Symptom
The server starts ("Running, 114 tools, 6 prompts"), but the first chat request fails before any tool runs:
Failed to validate tool mcp_abap-adt-mcp_nodeContents: Error: tool parameters array type must have items. Please open an issue for the MCP server or extension which provides this tool
VS Code refuses the whole request, so the…
Read the thread · 2026-09-28 · open · 0 comments
Make the certificate error teach the fix instead of printing a Node code
When a destination fails TLS verification the caller sees the raw Node code (UNABLE_TO_VERIFY_LEAF_SIGNATURE, SELF_SIGNED_CERT_IN_CHAIN, ERR_TLS_CERT_ALTNAME_INVALID, CERT_HAS_EXPIRED). Someone meeting an on-prem system for the first time has no way to know what to do next, and the search results all say to turn verification off. That is the real reason insecureTls gets used: it is the only option people find.
classifyAdtError should recognise these codes and answer with the fix,…
Read the thread · 2026-09-04 · closed · 0 comments
Add tls.servername so systems reached by IP keep certificate verification
A destination whose url is an IP address, or a short hostname, fails verification even when tls.ca is correct. The CA answers "who signed this certificate"; the failure here is the other question, "is this certificate for the name I asked for".
Measured against a live tenant:
| Connection | Result |
|---|---|
| by IP, verification on | fails, ERR_TLS_CERT_ALTNAME_INVALID |
| by IP, with the correct CA | fails the same way |
by IP, with servername |
passes, verification still on |
Read the thread · 2026-09-04 · closed · 0 comments
Most recent
The remaining reports are on the project's issue tracker.