Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

🎃 Add "Copy as cURL" to an audit log entry to replay the MCP tool call

Aperta
#850 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
72/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
playwright, typescript

Direzione di ricerca

Start with the expanded row in packages/frontend/src/app/logs/page.tsx:382-419, then read the server.info() usage in packages/frontend/src/lib/api.ts:964-977 and the clipboard helper in mcp-server/[id]/page.tsx:210-245. Build the command in packages/frontend/src/lib/curl.ts and test it, including auth modes and disabled cases; add the requested Playwright coverage and the note in docs/api-reference.md. Done means the copied command replays a local tool call without exposing credentials and the requested tests pass.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement good first issue hacktoberfest help wanted

Part of the October Challenge #846.

Why

When a tool call fails, the first step in debugging is to run it again outside the AI client. The log row already has the tool name, the arguments and the MCP server it came through, but rebuilding a valid MCP JSON-RPC request by hand (headers, protocol version, envelope) is slow and easy to get wrong. Browser DevTools, Postman and Insomnia all have "Copy as cURL". This issue adds that button to each entry on the Audit Log page.

What the log actually stores: tool_invocations.input holds the MCP tool arguments, saved before env vars are injected (dynamic-mcp-tools.ts:412-421). It does not hold the upstream HTTP request (URL, headers, body sent to the vendor API). So this feature replays the MCP tools/call against AnythingMCP. It does not replay the upstream API call. That is deliberate: upstream requests carry the connector's credentials.

Self-hosted vs Cloud

  • Self-hosted: enabled in Community and Business. No ee/ code.
  • Cloud (DEPLOYMENT_MODE=cloud): enabled. The command targets https://cloud.anythingmcp.com/mcp/<serverId>, which the user can already reach with their own credentials. Nothing instance-wide is exposed, and the button is client-side only with no new endpoint.
  • Who can use it: any role that can see /logs today. The command only contains data already shown in the expanded row, plus a placeholder for the credential.

What to build

  1. A "Copy as cURL" button in the expanded row (logs/page.tsx:382-419), next to the User/Server meta line.
  2. Put a pure builder in packages/frontend/src/lib/curl.ts: buildToolCallCurl({ origin, serverId, toolName, args, authMode }). Output:
    curl -sS -X POST "https://host/mcp/<serverId>" \
      -H "Content-Type: application/json" \
      -H "Accept: application/json, text/event-stream" \
      -H "MCP-Protocol-Version: 2025-06-18" \
      -H "X-API-Key: $AMCP_MCP_API_KEY" \
      --data-binary @- <<'JSON'
    {"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"<tool>","arguments":{...}}}
    JSON
    
    The quoted heredoc means no shell escaping is needed for the JSON. Before you finalize the headers, check that a bare tools/call (no initialize) is accepted by the stateless per-server endpoint on a local instance. If it is not, emit an initialize call first and say so in a comment.
  3. The credential is always a placeholder env var. Never put a real secret in the command. The auth header follows MCP_AUTH_MODE from server.info(): legacy/both gives X-API-Key: $AMCP_MCP_API_KEY (per-user mcp_… keys work in every mode on /mcp/<id>, see mcp-combined-auth.guard.ts:64), and oauth2 gives Authorization: Bearer $AMCP_ACCESS_TOKEN. Never insert the dashboard session token (amcp_token in localStorage). The MCP guard accepts app JWTs (mcp-combined-auth.guard.ts:89-100), so pasting one would leak a full-account credential into shell history and tickets.
  4. Origin: reuse the logic in mcp-server/[id]/page.tsx:98-102 (localhost → :4000, otherwise window.location.origin). Move it into lib/ rather than copying it.
  5. Disable the button, with a tooltip explaining why, when:
    • log.mcpServer is null. The call came through the shared /mcp endpoint, which on Cloud only exposes the eight anythingmcp_* tools (shared-toolset.ts:26-55), so a direct call by tool name would not work there.
    • log.input._amcp_truncated is present. The stored arguments are an excerpt (bound-payload.ts:16), so a replay would not be faithful.
  6. Reuse the clipboard fallback from mcp-server/[id]/page.tsx:210-245 (it handles plain-HTTP LAN installs). Moving it into lib/clipboard.ts is welcome.

Where to look

  • packages/frontend/src/app/logs/page.tsx:382-419: expanded row (log.input, log.mcpServer, log.tool.name).
  • packages/backend/src/audit/audit.service.ts:204-224: fields returned per row (mcpServer.id/slug, tool.name).
  • packages/backend/src/mcp-server/dynamic-mcp-tools.ts:412-421: input: params (pre-env-injection args).
  • packages/backend/src/mcp-server/mcp-endpoint.controller.ts:1042-1048: stateless handler, legacy: 'stateless'.
  • packages/frontend/src/lib/api.ts:964-977: server.info() → mcpAuthMode.

Acceptance criteria

  • The copied command runs against a local instance with a real key exported as AMCP_MCP_API_KEY and returns the tool result (describe the manual check in the PR).
  • Args containing ', ", $, backticks and newlines survive unchanged (heredoc).
  • No token, key or cookie value ever appears in the output. The test asserts the placeholder is present.
  • The button is disabled for shared-endpoint rows and truncated inputs.
  • Playwright test in packages/frontend/tests/e2e/ (stub /api/audit/invocations and /health/server-info like redesign.spec.ts, grant clipboard permission, assert the copied text). Run with cd packages/frontend && npm run test:e2e.
  • Short "Replay a tool call" note added to docs/api-reference.md near the Audit section (line 219).

Out of scope

  • Replaying the upstream vendor HTTP request (it is not stored, and it carries credentials).
  • PowerShell/HTTPie variants, HAR export.
  • A "Run again" button that executes from the browser.

Size

S (a few hours)

How to claim

Comment "I'd like to work on this" and we'll assign you. Rules in #846.

Lingua principale
TypeScript
Stelle
856
Fork
82
Merge medio
8h 27m
PR unite (30g)
104

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di HelpCode-ai/anythingmcp

Tutte le issue di HelpCode-ai/anythingmcp

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.