Redact URL query secrets in error text displayed by the web and TUI clients
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 65/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
Línea de trabajo
Start by examining core/mcp/fetchTracking.ts to understand redactUrlQuery and the existing redaction logic. Look at clients/cli/src/error-handler.ts to see the current redactUrlsInText implementation. Then, review the web client's error display in clients/web/src/App.tsx and the TUI client's error display in the mentioned files (App.tsx, ResourcesTab, etc.). The goal is to move the redaction logic to core, create a shared helper, and apply it at the display boundary in each client. Testing will involve the existing tests and potentially adding new ones in clients/web/src/test/core/.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Raised in review of #2488 (which closes #2423) and declined there as out of scope.
Background
#2423 asked the CLI/TUI to match the web client's URL redaction. The web client redacts query secrets (code, access_token, client_secret, …) through redactUrlQuery in exactly two places: the recorded Network log (core/mcp/fetchTracking.ts) and OAuthRequestTimeoutError's message (core/auth/requestTimeout.ts). #2488 extends the same guarantee to the CLI's stderr JSON envelope, which is written to terminals, CI logs and pipes.
The gap
Neither interactive client redacts error text it displays on screen.
- Web:
clients/web/src/App.tsxputserr.messagestraight into toasts in several places (e.g. ~L138, ~L1304, ~L1417, ~L1634). - TUI: about 20 sites across
App.tsx,ResourcesTab,PromptsTab,SkillsTab,AuthTaband the*TestModals rendererr.message/String(err)as-is.
So a server or SDK error whose text contains https://…?code=… is shown verbatim. The risk is lower than the CLI case: this is the user's own screen, not a serialized or piped artifact. It is still a screenshot or screen-share away from leaking.
Suggested shape
- Move the CLI's
redactUrlsInText(added in #2488,clients/cli/src/error-handler.ts) intocore/mcp/fetchTracking.tsnext toredactUrlQuery, with its tests underclients/web/src/test/core/. - Have the CLI import it from core.
- Apply it at one display boundary per client rather than at each call site, e.g. a shared
errorMessage(err)helper in each client (web already hasutils/errorFormat).
- Lenguaje dominante
- TypeScript
- Estrellas
- 11k
- Forks
- 1.5k
- Merge medio
- 5 h 49 min
- PR fusionados (30 d)
- 133
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de modelcontextprotocol/inspector
-
Plain HTTP 403 without `WWW-Authenticate` starts OAuth discovery in the Inspector web clientAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
modelcontextprotocol/inspector#2515 ·
Los mantenedores suelen responder en 1 día
-
enhancement v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
modelcontextprotocol/inspector#2438 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 3/5 1-2 días Aptitud para principiantes 62/100
modelcontextprotocol/inspector#2518 ·
Los mantenedores suelen responder en 1 día
-
bug v2
Dificultad 3/5 1-2 días Aptitud para principiantes 78/100
modelcontextprotocol/inspector#2517 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 3/5 1-2 días Aptitud para principiantes 65/100
modelcontextprotocol/inspector#2516 ·
Los mantenedores suelen responder en 1 día
Todos los issues de modelcontextprotocol/inspector
Issues similares
-
triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
mermaid-js/mermaid-live-editor#2053 ·
Los mantenedores suelen responder en 1 día
-
factory
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
jessepollak/home#1455 ·
Los mantenedores suelen responder en 1 día
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
lingdojo/kana-dojo#31227 · 1 comentario · 5 reacciones ·
Los mantenedores suelen responder en 1 día
-
mobile: device viewer shows dark status bar icons on its dark backdrop in light mode (Android)Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
appandflow/stim#1838 ·
Los mantenedores suelen responder en 1 día