Server logs full JSON-RPC payloads, tool arguments included, at info level
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 74/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- php
- Lĩnh vực
- backend-api-design, security
Hướng nghiên cứu
Start in src/Server/Protocol.php and inspect the four info-level logging paths for received messages, requests, responses, and notifications. Compare them with CallToolHandler's debug logging and the Logger example in docs/run/server-builder.md. Done means info logs retain method/ID-level details without payloads, full payloads are available at debug, and the relevant logging tests pass.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Protocol passes every incoming message to the PSR-3 logger as context at info level:
// src/Server/Protocol.php (main @ 3175614b)
$this->logger->info('Received message to process.', ['message' => $input]); // raw JSON input
$this->logger->info('Handling request.', ['request' => $request]); // whole request object
$this->logger->info('Handling response from client.', ['response' => $response]); // sampling/elicitation replies
$this->logger->info('Handling notification.', ['notification' => $notification]);
For a tools/call, that's the tool arguments twice, at the level most production setups keep. A sampling or elicitation reply puts what the user typed in the log the same way.
The builder docs (docs/run/server-builder.md, "Logger") show:
$logger = new Logger('mcp-server');
$logger->pushHandler(new StreamHandler('mcp.log', Logger::INFO));
Monolog's default LineFormatter writes the full context with each record. So a server set up as documented stores every tool argument in mcp.log. Tool calls can carry content an application wouldn't otherwise log, such as personal data, document text, or credentials a user pastes into a prompt.
CallToolHandler already keeps payloads at debug (Executing tool with arguments, Tool executed successfully with structured_content). That seems like the right split, and Protocol doesn't follow it.
Proposal: at info, log the method and ID only, and move the full payload to debug. For example:
$this->logger->info('Handling request.', ['method' => $request::getMethod(), 'id' => $request->getId()]);
$this->logger->debug('Request payload.', ['request' => $request]);
"Received message to process." could drop the raw input at info entirely, since the per-message lines that follow already name the method.
Downstream, the Drupal integration filters payloads out of the context in its logger decorator, because its database log is readable by site administrators: https://git.drupalcode.org/project/mcp_server/-/work_items/3585937. Fixing the levels in the SDK would let every integration control this with a normal log level.
- Ngôn ngữ chính
- PHP
- Star
- 1.6k
- Fork
- 173
- Merge trung bình
- 19 giờ 19 phút
- Pull request đã merge (30 ngày)
- 8
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của modelcontextprotocol/php-sdk
-
[Server] Connections to Github Copilot CLI time out on subscriptions/listenCó thể đã có người làm @SammyTourani đã nhận 4 ngày trước. Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
modelcontextprotocol/php-sdk#516 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanĐang mởServer
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
modelcontextprotocol/php-sdk#468 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyCó thể đã có người làm @ousamabenyounes đã nhận 47 ngày trước. Đang mởneeds confirmation needs maintainer action Server
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
modelcontextprotocol/php-sdk#398 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
modelcontextprotocol/php-sdk#370 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 62/100
modelcontextprotocol/php-sdk#523 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của modelcontextprotocol/php-sdk
Issue tương tự
-
Bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày
-
0. Needs triage 35-feedback bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Notification e-mails are sent without Date and Message-ID headersCó thể đã có người làm @nofuturekid đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
unraid/webgui#2781 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 6 ngày
-
thrift: security issues < 0.25.0Đang mở1.severity: security
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
NixOS/nixpkgs#569828 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Use FormEvents constants when generating subscriberCó thể đã có người làm @GromNaN đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
symfony/maker-bundle#1841 ·
Maintainer thường phản hồi trong vòng 1 ngày