Redact URL query secrets in error text displayed by the web and TUI clients
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 65/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
Hướng nghiên cứu
Start by examining core/mcp/fetchTracking.ts to understand redactUrlQuery and the existing redaction logic. Look at clients/cli/src/error-handler.ts to see the current redactUrlsInText implementation. Then, review the web client's error display in clients/web/src/App.tsx and the TUI client's error display in the mentioned files (App.tsx, ResourcesTab, etc.). The goal is to move the redaction logic to core, create a shared helper, and apply it at the display boundary in each client. Testing will involve the existing tests and potentially adding new ones in clients/web/src/test/core/.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Raised in review of #2488 (which closes #2423) and declined there as out of scope.
Background
#2423 asked the CLI/TUI to match the web client's URL redaction. The web client redacts query secrets (code, access_token, client_secret, …) through redactUrlQuery in exactly two places: the recorded Network log (core/mcp/fetchTracking.ts) and OAuthRequestTimeoutError's message (core/auth/requestTimeout.ts). #2488 extends the same guarantee to the CLI's stderr JSON envelope, which is written to terminals, CI logs and pipes.
The gap
Neither interactive client redacts error text it displays on screen.
- Web:
clients/web/src/App.tsxputserr.messagestraight into toasts in several places (e.g. ~L138, ~L1304, ~L1417, ~L1634). - TUI: about 20 sites across
App.tsx,ResourcesTab,PromptsTab,SkillsTab,AuthTaband the*TestModals rendererr.message/String(err)as-is.
So a server or SDK error whose text contains https://…?code=… is shown verbatim. The risk is lower than the CLI case: this is the user's own screen, not a serialized or piped artifact. It is still a screenshot or screen-share away from leaking.
Suggested shape
- Move the CLI's
redactUrlsInText(added in #2488,clients/cli/src/error-handler.ts) intocore/mcp/fetchTracking.tsnext toredactUrlQuery, with its tests underclients/web/src/test/core/. - Have the CLI import it from core.
- Apply it at one display boundary per client rather than at each call site, e.g. a shared
errorMessage(err)helper in each client (web already hasutils/errorFormat).
- Ngôn ngữ chính
- TypeScript
- Star
- 11k
- Fork
- 1.5k
- Merge trung bình
- 5 giờ 13 phút
- Pull request đã merge (30 ngày)
- 132
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của modelcontextprotocol/inspector
-
bug v2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
modelcontextprotocol/inspector#2525 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement v2
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 76/100
modelcontextprotocol/inspector#2524 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
modelcontextprotocol/inspector#2523 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Plain HTTP 403 without `WWW-Authenticate` starts OAuth discovery in the Inspector web clientĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
modelcontextprotocol/inspector#2515 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement v2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
modelcontextprotocol/inspector#2438 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của modelcontextprotocol/inspector
Issue tương tự
-
Mend: dependency security vulnerability untriaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
opensearch-project/security-dashboards-plugin#2545 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add: Dream TR SDĐang mởcheck:passed streams:add
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 1 ngày
-
doctor integrity sample scans soft-deleted pages on Postgres (batch path has no deleted_at filter)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
SocialGouv/egapro#4672 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
area:agents area:tui bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
anthropics/claude-code#98358 ·
Maintainer thường phản hồi trong vòng 1 ngày