A race no longer wipes working MCP OAuth discovery data during a concurrent save.
What's wrong with this entry?
Invalidating stored OAuth discovery data now bails out instead of clearing it when the stored entry has no authorization server metadata, which is the signature of another save writing just the URL at the same time. This prevents a race that could throw away working discovery state.
- Invalidating discovery no longer clears the step-up scope along with it.
invalidateCredentials('discovery') preserved: concurrent URL-only re-save
Strings lifted out of the shipped bundle, so the claim above can be checked against them.