Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Server logs full JSON-RPC payloads, tool arguments included, at info level

Đang mở
#524 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
74/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
php

Hướng nghiên cứu

Start in src/Server/Protocol.php and inspect the four info-level logging paths for received messages, requests, responses, and notifications. Compare them with CallToolHandler's debug logging and the Logger example in docs/run/server-builder.md. Done means info logs retain method/ID-level details without payloads, full payloads are available at debug, and the relevant logging tests pass.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Protocol passes every incoming message to the PSR-3 logger as context at info level:

// src/Server/Protocol.php (main @ 3175614b)
$this->logger->info('Received message to process.', ['message' => $input]);          // raw JSON input
$this->logger->info('Handling request.', ['request' => $request]);                   // whole request object
$this->logger->info('Handling response from client.', ['response' => $response]);    // sampling/elicitation replies
$this->logger->info('Handling notification.', ['notification' => $notification]);

For a tools/call, that's the tool arguments twice, at the level most production setups keep. A sampling or elicitation reply puts what the user typed in the log the same way.

The builder docs (docs/run/server-builder.md, "Logger") show:

$logger = new Logger('mcp-server');
$logger->pushHandler(new StreamHandler('mcp.log', Logger::INFO));

Monolog's default LineFormatter writes the full context with each record. So a server set up as documented stores every tool argument in mcp.log. Tool calls can carry content an application wouldn't otherwise log, such as personal data, document text, or credentials a user pastes into a prompt.

CallToolHandler already keeps payloads at debug (Executing tool with arguments, Tool executed successfully with structured_content). That seems like the right split, and Protocol doesn't follow it.

Proposal: at info, log the method and ID only, and move the full payload to debug. For example:

$this->logger->info('Handling request.', ['method' => $request::getMethod(), 'id' => $request->getId()]);
$this->logger->debug('Request payload.', ['request' => $request]);

"Received message to process." could drop the raw input at info entirely, since the per-message lines that follow already name the method.

Downstream, the Drupal integration filters payloads out of the context in its logger decorator, because its database log is readable by site administrators: https://git.drupalcode.org/project/mcp_server/-/work_items/3585937. Fixing the levels in the SDK would let every integration control this with a normal log level.

Ngôn ngữ chính
PHP
Star
1.6k
Fork
173
Merge trung bình
19 giờ 19 phút
Pull request đã merge (30 ngày)
8

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của modelcontextprotocol/php-sdk

Tất cả issue của modelcontextprotocol/php-sdk

Issue tương tự

Thêm issue về PHP

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.