League\OAuth2\Server\Exception\OAuthServerException with a status below 500 (invalid/missing/expired bearer tokens, invalid_grant, etc.) represents a client error, not an application failure, but Passport's TokenGuard explicitly calls report() on every failed bearer-token check. This was flooding Nightwatch with 401 noise from bots probing the public MCP endpoint. Actual server_error (500) responses are still reported. |
||
|---|---|---|
| .. | ||
| cache | ||
| app.php | ||
| providers.php | ||