Redact URL query secrets in error text displayed by the web and TUI clients
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 65/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
Direzione di ricerca
Start by examining core/mcp/fetchTracking.ts to understand redactUrlQuery and the existing redaction logic. Look at clients/cli/src/error-handler.ts to see the current redactUrlsInText implementation. Then, review the web client's error display in clients/web/src/App.tsx and the TUI client's error display in the mentioned files (App.tsx, ResourcesTab, etc.). The goal is to move the redaction logic to core, create a shared helper, and apply it at the display boundary in each client. Testing will involve the existing tests and potentially adding new ones in clients/web/src/test/core/.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Raised in review of #2488 (which closes #2423) and declined there as out of scope.
Background
#2423 asked the CLI/TUI to match the web client's URL redaction. The web client redacts query secrets (code, access_token, client_secret, …) through redactUrlQuery in exactly two places: the recorded Network log (core/mcp/fetchTracking.ts) and OAuthRequestTimeoutError's message (core/auth/requestTimeout.ts). #2488 extends the same guarantee to the CLI's stderr JSON envelope, which is written to terminals, CI logs and pipes.
The gap
Neither interactive client redacts error text it displays on screen.
- Web:
clients/web/src/App.tsxputserr.messagestraight into toasts in several places (e.g. ~L138, ~L1304, ~L1417, ~L1634). - TUI: about 20 sites across
App.tsx,ResourcesTab,PromptsTab,SkillsTab,AuthTaband the*TestModals rendererr.message/String(err)as-is.
So a server or SDK error whose text contains https://…?code=… is shown verbatim. The risk is lower than the CLI case: this is the user's own screen, not a serialized or piped artifact. It is still a screenshot or screen-share away from leaking.
Suggested shape
- Move the CLI's
redactUrlsInText(added in #2488,clients/cli/src/error-handler.ts) intocore/mcp/fetchTracking.tsnext toredactUrlQuery, with its tests underclients/web/src/test/core/. - Have the CLI import it from core.
- Apply it at one display boundary per client rather than at each call site, e.g. a shared
errorMessage(err)helper in each client (web already hasutils/errorFormat).
- Lingua principale
- TypeScript
- Stelle
- 10.9k
- Fork
- 1.5k
- Merge medio
- 5h 48m
- PR unite (30g)
- 143
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di modelcontextprotocol/inspector
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/inspector#2515 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement v2
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
modelcontextprotocol/inspector#2438 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug v2
Difficoltà 3/5 1-2 giorni Idoneità per principianti 78/100
modelcontextprotocol/inspector#2517 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
modelcontextprotocol/inspector#2516 ·
I maintainer di solito rispondono entro 1 giorno
-
Document our software factory approachForse già presa @BobDickinson l’ha presa 2 giorni fa. Apertadocumentation v2
modelcontextprotocol/inspector#2497 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di modelcontextprotocol/inspector
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
rohitg00/agentmemory#1428 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
boxlite-ai/boxlite#1729 ·
I maintainer di solito rispondono entro 1 giorno
-
detectors enhancement good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
SM260845/readme-gen#1 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
angular/angularfire#3774 ·
I maintainer di solito rispondono entro 2 giorni