🎃 Add "Copy as cURL" to an audit log entry to replay the MCP tool call
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 72/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- playwright, typescript
- Ambito
- api, documentation, frontend
Direzione di ricerca
Start with the expanded row in packages/frontend/src/app/logs/page.tsx:382-419, then read the server.info() usage in packages/frontend/src/lib/api.ts:964-977 and the clipboard helper in mcp-server/[id]/page.tsx:210-245. Build the command in packages/frontend/src/lib/curl.ts and test it, including auth modes and disabled cases; add the requested Playwright coverage and the note in docs/api-reference.md. Done means the copied command replays a local tool call without exposing credentials and the requested tests pass.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Part of the October Challenge #846.
Why
When a tool call fails, the first step in debugging is to run it again outside the AI client. The log row already has the tool name, the arguments and the MCP server it came through, but rebuilding a valid MCP JSON-RPC request by hand (headers, protocol version, envelope) is slow and easy to get wrong. Browser DevTools, Postman and Insomnia all have "Copy as cURL". This issue adds that button to each entry on the Audit Log page.
What the log actually stores: tool_invocations.input holds the MCP tool arguments, saved before env vars are injected (dynamic-mcp-tools.ts:412-421). It does not hold the upstream HTTP request (URL, headers, body sent to the vendor API). So this feature replays the MCP tools/call against AnythingMCP. It does not replay the upstream API call. That is deliberate: upstream requests carry the connector's credentials.
Self-hosted vs Cloud
- Self-hosted: enabled in Community and Business. No
ee/code. - Cloud (
DEPLOYMENT_MODE=cloud): enabled. The command targetshttps://cloud.anythingmcp.com/mcp/<serverId>, which the user can already reach with their own credentials. Nothing instance-wide is exposed, and the button is client-side only with no new endpoint. - Who can use it: any role that can see
/logstoday. The command only contains data already shown in the expanded row, plus a placeholder for the credential.
What to build
- A "Copy as cURL" button in the expanded row (
logs/page.tsx:382-419), next to the User/Server meta line. - Put a pure builder in
packages/frontend/src/lib/curl.ts:buildToolCallCurl({ origin, serverId, toolName, args, authMode }). Output:
The quoted heredoc means no shell escaping is needed for the JSON. Before you finalize the headers, check that a barecurl -sS -X POST "https://host/mcp/<serverId>" \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -H "MCP-Protocol-Version: 2025-06-18" \ -H "X-API-Key: $AMCP_MCP_API_KEY" \ --data-binary @- <<'JSON' {"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"<tool>","arguments":{...}}} JSONtools/call(noinitialize) is accepted by the stateless per-server endpoint on a local instance. If it is not, emit aninitializecall first and say so in a comment. - The credential is always a placeholder env var. Never put a real secret in the command. The auth header follows
MCP_AUTH_MODEfromserver.info():legacy/bothgivesX-API-Key: $AMCP_MCP_API_KEY(per-usermcp_…keys work in every mode on/mcp/<id>, seemcp-combined-auth.guard.ts:64), andoauth2givesAuthorization: Bearer $AMCP_ACCESS_TOKEN. Never insert the dashboard session token (amcp_tokenin localStorage). The MCP guard accepts app JWTs (mcp-combined-auth.guard.ts:89-100), so pasting one would leak a full-account credential into shell history and tickets. - Origin: reuse the logic in
mcp-server/[id]/page.tsx:98-102(localhost→:4000, otherwisewindow.location.origin). Move it intolib/rather than copying it. - Disable the button, with a tooltip explaining why, when:
log.mcpServeris null. The call came through the shared/mcpendpoint, which on Cloud only exposes the eightanythingmcp_*tools (shared-toolset.ts:26-55), so a direct call by tool name would not work there.log.input._amcp_truncatedis present. The stored arguments are an excerpt (bound-payload.ts:16), so a replay would not be faithful.
- Reuse the clipboard fallback from
mcp-server/[id]/page.tsx:210-245(it handles plain-HTTP LAN installs). Moving it intolib/clipboard.tsis welcome.
Where to look
packages/frontend/src/app/logs/page.tsx:382-419: expanded row (log.input,log.mcpServer,log.tool.name).packages/backend/src/audit/audit.service.ts:204-224: fields returned per row (mcpServer.id/slug,tool.name).packages/backend/src/mcp-server/dynamic-mcp-tools.ts:412-421:input: params(pre-env-injection args).packages/backend/src/mcp-server/mcp-endpoint.controller.ts:1042-1048: stateless handler,legacy: 'stateless'.packages/frontend/src/lib/api.ts:964-977:server.info()→mcpAuthMode.
Acceptance criteria
- The copied command runs against a local instance with a real key exported as
AMCP_MCP_API_KEYand returns the tool result (describe the manual check in the PR). - Args containing
',",$, backticks and newlines survive unchanged (heredoc). - No token, key or cookie value ever appears in the output. The test asserts the placeholder is present.
- The button is disabled for shared-endpoint rows and truncated inputs.
- Playwright test in
packages/frontend/tests/e2e/(stub/api/audit/invocationsand/health/server-infolikeredesign.spec.ts, grant clipboard permission, assert the copied text). Run withcd packages/frontend && npm run test:e2e. - Short "Replay a tool call" note added to
docs/api-reference.mdnear the Audit section (line 219).
Out of scope
- Replaying the upstream vendor HTTP request (it is not stored, and it carries credentials).
- PowerShell/HTTPie variants, HAR export.
- A "Run again" button that executes from the browser.
Size
S (a few hours)
How to claim
Comment "I'd like to work on this" and we'll assign you. Rules in #846.
- Lingua principale
- TypeScript
- Stelle
- 856
- Fork
- 82
- Merge medio
- 8h 27m
- PR unite (30g)
- 104
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di HelpCode-ai/anythingmcp
-
good first issue hacktoberfest
Difficoltà 2/5 Mezza giornata Idoneità per principianti 70/100
HelpCode-ai/anythingmcp#996 ·
I maintainer di solito rispondono entro 1 giorno
-
good first issue hacktoberfest
Difficoltà 2/5 Mezza giornata Idoneità per principianti 72/100
HelpCode-ai/anythingmcp#995 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement good first issue hacktoberfest help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
HelpCode-ai/anythingmcp#982 ·
I maintainer di solito rispondono entro 1 giorno
-
good first issue hacktoberfest
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
HelpCode-ai/anythingmcp#745 ·
I maintainer di solito rispondono entro 1 giorno
-
🐣 Good first issue: contribute a new MCP adapterForse di nuovo libera @7k777 l’ha presa 20 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement good first issue hacktoberfest help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
HelpCode-ai/anythingmcp#150 · 18 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di HelpCode-ai/anythingmcp
Issue simili
-
submodule-pointer-regression
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
smith-horn/skillsmith#3061 ·
I maintainer di solito rispondono entro 1 giorno
-
area: ops type: test
Difficoltà 2/5 1-3 ore Idoneità per principianti 79/100
accensa/x402-facilitator-stellar#559 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
cosimochellini/one-piece-zero-spoiler#551 ·
I maintainer di solito rispondono entro 1 giorno
-
getWatched() omits __proto__ directories when cwd is setForse già presa @maxazure l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 79/100
-
area:web enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno