Skip to content

chore: rollup of #2569 web sub-issue PRs (CI check — do not merge) - #2596

Closed
cliffhall wants to merge 16 commits into
v2/mainfrom
v2/chore/2569-rollup-web-v2.10.0
Closed

cliffhall wants to merge 16 commits into
v2/mainfrom
v2/chore/2569-rollup-web-v2.10.0

Conversation

@cliffhall

Copy link
Copy Markdown
Member

Refs #2569

Rollup check — DO NOT MERGE. This draft PR merges the branches of every open PR for tracker #2569's sub-issues (web client, v2.10.0) onto the current v2/main. It exists only to show that they merge together cleanly and that CI passes on the combined result. Each PR is reviewed and merged on its own; close this once they land.

Sub-issue PR Branch Head
#2429 deep-link token compare is not constant-time #2577 v2/fix/2429-deeplink-constant-time-compare 679c5ce3
#2438 web backend health/readiness endpoint #2585 v2/feat/2438-web-healthz c22de805
#2524 show OAuth redirect URI (with copy) in Server Settings #2586 v2/feat/2524-oauth-redirect-uri-display d513efd8
#2490 redact URL query secrets in web + TUI error text #2588 v2/fix/2490-redact-displayed-error-urls 55a1fe84
#2525 Tools Results panel double scrollbar #2593 v2/fix/2525-results-double-scrollbar a95c905f

All five merged into v2/main (9393237c) with no conflicts, in the order above, as signed-off --no-ff merge commits.

The individual PRs record that a full local:gate could not run cleanly in the sandbox they were built in: HTTP-proxy 502s on local integration tests, a bind-mount-specific isOnMountPoint failure, and gate-lease queue timeouts. This PR's CI is the combined check for those.

🤖 Generated with Claude Code

cliffhall and others added 16 commits October 5, 2026 01:20
…clients

Move the CLI's redactUrlsInText into core/mcp/fetchTracking.ts beside
redactUrlQuery and import it from there in the CLI. Route on-screen error
text through it at one display boundary per client: the web client's
utils/errorFormat errorMessage/formatErrorDetails (now used by every toast
and inline error that rendered err.message), and a new TUI
utils/errorText helper used by App, the tabs and the test modals.

Closes #2490

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…2524)

A pre-registered OAuth client must register the Inspector's redirect URI
at its authorization server before connecting, but the OAuth Settings
panel never showed it. Add a read-only Redirect URI field with a copy
button, read from the same redirectUrlProvider the connect path uses so
it cannot drift from the value actually sent, with a description noting
it follows the origin the Inspector is opened from.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Orchestrators (Docker, Kubernetes, process managers) had no cheap way to
check the web backend is up without exercising a real proxy/connect flow.
Both the prod Hono server and the dev Vite backend now answer GET/HEAD
/healthz with 200, a fixed {"status":"ok"} body and Cache-Control:
no-store.

The route sits outside /api/*, so the bearer-token and origin checks do
not apply (a probe cannot learn a per-start token), and it discloses
nothing beyond "up" -- no version, uptime, servers or config.

Closes #2438

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
parseDeepLink() checked the autoConnect and autoOpen params against the
session API token with plain ===/!==, which returns at the first
mismatched character and so leaks, in principle, how long a correct
prefix a guessed token has.

Add constantTimeEqual() beside parseDeepLink in the pure utils module: a
synchronous XOR accumulator that visits every code unit of the secret
and folds a length mismatch into the result instead of returning early.
The browser has no crypto.timingSafeEqual, and crypto.subtle is async
and unavailable on non-secure origins, so neither fits this sync path.

Closes #2429

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
constantTimeEqual's comment claimed the secret's length is fixed by the
launch-time token format, but MCP_INSPECTOR_API_TOKEN / --auth-token
accept a user-supplied value of any length. Say so, and name what the
helper does remove: the prefix leak.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Every file in the repo carries a header explaining its purpose (AGENTS.md,
Project Structure); the new health.test.ts was missing one. Copilot review
on #2585.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Under enterprise-managed authorization the authorization request that
carries the redirect URI goes to the enterprise IdP, so the URI is
registered on the IdP client from Client Settings, not on the Resource
AS client named by the adjacent fields. Give the field EMA-specific
copy and qualify the docs paragraph the same way (Copilot review).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
A JSON result past ContentViewer's 200-row Ace cap scrolled inside the
editor while the Results panel's ScrollArea also scrolled the whole
result, so two vertical scrollbars sat side by side.

Add an optional `jsonMaxLines` prop to ContentViewer (defaulting to the
existing cap, so the Protocol/Network lists keep it) and pass Infinity
from ToolResultPanel, whose scroll regions already scroll a block whole.
Adds a LongJsonResult story whose play function asserts on real
geometry that Ace's vertical scrollbar stays hidden while the panel's
viewport overflows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
The dev Vite middleware wrote the health response inline, in a file that
is excluded from coverage, so its headers and HEAD handling had no test.
Move it into handleNodeHealthRequest() in health.ts and drive that from a
real node:http server in health.test.ts. health.ts stays at 100% on all
four dimensions. Copilot review on #2585.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Redact the TUI's nested OAuth failure and skills-list error, the web
skills-list alert, the failed step-up outcome and the pagination
ServerListReloadError toast. Classify the deep-link 409 on the raw
message and redact only the recorded copy, with a regression test.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…eview

Redact the TUI's interactive-reauth and standard step-up OAuth catches
and the failed-revocation detail in both clients' clear warnings, with
regression tests for each.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…rollup

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…ollup

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…ollup

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall

Copy link
Copy Markdown
Member Author

Closing as intended: this rollup was proof only. All five #2569 sub-issue PRs (#2577, #2585, #2586, #2588, #2593) merged together onto v2/main with no conflicts, and CI (build, coverage) passed on the combined result here. Each has now been merged into v2/main individually.

@cliffhall cliffhall closed this Oct 5, 2026
@cliffhall
cliffhall deleted the v2/chore/2569-rollup-web-v2.10.0 branch October 5, 2026 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant