Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Redact URL query secrets in error text displayed by the web and TUI clients

オープン
#2,490 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
65/100
issue の種類
機能追加
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript

調査の方向性

Start by examining core/mcp/fetchTracking.ts to understand redactUrlQuery and the existing redaction logic. Look at clients/cli/src/error-handler.ts to see the current redactUrlsInText implementation. Then, review the web client's error display in clients/web/src/App.tsx and the TUI client's error display in the mentioned files (App.tsx, ResourcesTab, etc.). The goal is to move the redaction logic to core, create a shared helper, and apply it at the display boundary in each client. Testing will involve the existing tests and potentially adding new ones in clients/web/src/test/core/.

索引モデルが issue の本文から書いたものです。

説明

enhancement v2

Raised in review of #2488 (which closes #2423) and declined there as out of scope.

Background

#2423 asked the CLI/TUI to match the web client's URL redaction. The web client redacts query secrets (code, access_token, client_secret, …) through redactUrlQuery in exactly two places: the recorded Network log (core/mcp/fetchTracking.ts) and OAuthRequestTimeoutError's message (core/auth/requestTimeout.ts). #2488 extends the same guarantee to the CLI's stderr JSON envelope, which is written to terminals, CI logs and pipes.

The gap

Neither interactive client redacts error text it displays on screen.

  • Web: clients/web/src/App.tsx puts err.message straight into toasts in several places (e.g. ~L138, ~L1304, ~L1417, ~L1634).
  • TUI: about 20 sites across App.tsx, ResourcesTab, PromptsTab, SkillsTab, AuthTab and the *TestModals render err.message / String(err) as-is.

So a server or SDK error whose text contains https://…?code=… is shown verbatim. The risk is lower than the CLI case: this is the user's own screen, not a serialized or piped artifact. It is still a screenshot or screen-share away from leaking.

Suggested shape

  • Move the CLI's redactUrlsInText (added in #2488, clients/cli/src/error-handler.ts) into core/mcp/fetchTracking.ts next to redactUrlQuery, with its tests under clients/web/src/test/core/.
  • Have the CLI import it from core.
  • Apply it at one display boundary per client rather than at each call site, e.g. a shared errorMessage(err) helper in each client (web already has utils/errorFormat).
主要言語
TypeScript
スター
11k
フォーク
1.5k
平均マージ
5時間 49分
マージ済み PR(30日)
133

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

modelcontextprotocol/inspector のほかの issue

modelcontextprotocol/inspector の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。