Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Redact URL query secrets in error text displayed by the web and TUI clients

Abierto
#2,490 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
65/100
Tipo de issue
Nueva funcionalidad
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
typescript

Línea de trabajo

Start by examining core/mcp/fetchTracking.ts to understand redactUrlQuery and the existing redaction logic. Look at clients/cli/src/error-handler.ts to see the current redactUrlsInText implementation. Then, review the web client's error display in clients/web/src/App.tsx and the TUI client's error display in the mentioned files (App.tsx, ResourcesTab, etc.). The goal is to move the redaction logic to core, create a shared helper, and apply it at the display boundary in each client. Testing will involve the existing tests and potentially adding new ones in clients/web/src/test/core/.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

enhancement v2

Raised in review of #2488 (which closes #2423) and declined there as out of scope.

Background

#2423 asked the CLI/TUI to match the web client's URL redaction. The web client redacts query secrets (code, access_token, client_secret, …) through redactUrlQuery in exactly two places: the recorded Network log (core/mcp/fetchTracking.ts) and OAuthRequestTimeoutError's message (core/auth/requestTimeout.ts). #2488 extends the same guarantee to the CLI's stderr JSON envelope, which is written to terminals, CI logs and pipes.

The gap

Neither interactive client redacts error text it displays on screen.

  • Web: clients/web/src/App.tsx puts err.message straight into toasts in several places (e.g. ~L138, ~L1304, ~L1417, ~L1634).
  • TUI: about 20 sites across App.tsx, ResourcesTab, PromptsTab, SkillsTab, AuthTab and the *TestModals render err.message / String(err) as-is.

So a server or SDK error whose text contains https://…?code=… is shown verbatim. The risk is lower than the CLI case: this is the user's own screen, not a serialized or piped artifact. It is still a screenshot or screen-share away from leaking.

Suggested shape

  • Move the CLI's redactUrlsInText (added in #2488, clients/cli/src/error-handler.ts) into core/mcp/fetchTracking.ts next to redactUrlQuery, with its tests under clients/web/src/test/core/.
  • Have the CLI import it from core.
  • Apply it at one display boundary per client rather than at each call site, e.g. a shared errorMessage(err) helper in each client (web already has utils/errorFormat).
Lenguaje dominante
TypeScript
Estrellas
11k
Forks
1.5k
Merge medio
5 h 49 min
PR fusionados (30 d)
133

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de modelcontextprotocol/inspector

Todos los issues de modelcontextprotocol/inspector

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.