Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Redact URL query secrets in error text displayed by the web and TUI clients

Đang mở
#2,490 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
65/100
Loại issue
Tính năng
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
typescript
Lĩnh vực
cli, frontend, security, tooling

Hướng nghiên cứu

Start by examining core/mcp/fetchTracking.ts to understand redactUrlQuery and the existing redaction logic. Look at clients/cli/src/error-handler.ts to see the current redactUrlsInText implementation. Then, review the web client's error display in clients/web/src/App.tsx and the TUI client's error display in the mentioned files (App.tsx, ResourcesTab, etc.). The goal is to move the redaction logic to core, create a shared helper, and apply it at the display boundary in each client. Testing will involve the existing tests and potentially adding new ones in clients/web/src/test/core/.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement v2

Raised in review of #2488 (which closes #2423) and declined there as out of scope.

Background

#2423 asked the CLI/TUI to match the web client's URL redaction. The web client redacts query secrets (code, access_token, client_secret, …) through redactUrlQuery in exactly two places: the recorded Network log (core/mcp/fetchTracking.ts) and OAuthRequestTimeoutError's message (core/auth/requestTimeout.ts). #2488 extends the same guarantee to the CLI's stderr JSON envelope, which is written to terminals, CI logs and pipes.

The gap

Neither interactive client redacts error text it displays on screen.

  • Web: clients/web/src/App.tsx puts err.message straight into toasts in several places (e.g. ~L138, ~L1304, ~L1417, ~L1634).
  • TUI: about 20 sites across App.tsx, ResourcesTab, PromptsTab, SkillsTab, AuthTab and the *TestModals render err.message / String(err) as-is.

So a server or SDK error whose text contains https://…?code=… is shown verbatim. The risk is lower than the CLI case: this is the user's own screen, not a serialized or piped artifact. It is still a screenshot or screen-share away from leaking.

Suggested shape

  • Move the CLI's redactUrlsInText (added in #2488, clients/cli/src/error-handler.ts) into core/mcp/fetchTracking.ts next to redactUrlQuery, with its tests under clients/web/src/test/core/.
  • Have the CLI import it from core.
  • Apply it at one display boundary per client rather than at each call site, e.g. a shared errorMessage(err) helper in each client (web already has utils/errorFormat).
Ngôn ngữ chính
TypeScript
Star
11k
Fork
1.5k
Merge trung bình
5 giờ 13 phút
Pull request đã merge (30 ngày)
132

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của modelcontextprotocol/inspector

Tất cả issue của modelcontextprotocol/inspector

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.