Repository navigation
Conversation
…clients Move the CLI's redactUrlsInText into core/mcp/fetchTracking.ts beside redactUrlQuery and import it from there in the CLI. Route on-screen error text through it at one display boundary per client: the web client's utils/errorFormat errorMessage/formatErrorDetails (now used by every toast and inline error that rendered err.message), and a new TUI utils/errorText helper used by App, the tabs and the test modals. Closes #2490 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
…2524) A pre-registered OAuth client must register the Inspector's redirect URI at its authorization server before connecting, but the OAuth Settings panel never showed it. Add a read-only Redirect URI field with a copy button, read from the same redirectUrlProvider the connect path uses so it cannot drift from the value actually sent, with a description noting it follows the origin the Inspector is opened from. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Orchestrators (Docker, Kubernetes, process managers) had no cheap way to
check the web backend is up without exercising a real proxy/connect flow.
Both the prod Hono server and the dev Vite backend now answer GET/HEAD
/healthz with 200, a fixed {"status":"ok"} body and Cache-Control:
no-store.
The route sits outside /api/*, so the bearer-token and origin checks do
not apply (a probe cannot learn a per-start token), and it discloses
nothing beyond "up" -- no version, uptime, servers or config.
Closes #2438
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
parseDeepLink() checked the autoConnect and autoOpen params against the session API token with plain ===/!==, which returns at the first mismatched character and so leaks, in principle, how long a correct prefix a guessed token has. Add constantTimeEqual() beside parseDeepLink in the pure utils module: a synchronous XOR accumulator that visits every code unit of the secret and folds a length mismatch into the result instead of returning early. The browser has no crypto.timingSafeEqual, and crypto.subtle is async and unavailable on non-secure origins, so neither fits this sync path. Closes #2429 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
constantTimeEqual's comment claimed the secret's length is fixed by the launch-time token format, but MCP_INSPECTOR_API_TOKEN / --auth-token accept a user-supplied value of any length. Say so, and name what the helper does remove: the prefix leak. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Every file in the repo carries a header explaining its purpose (AGENTS.md, Project Structure); the new health.test.ts was missing one. Copilot review on #2585. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Under enterprise-managed authorization the authorization request that carries the redirect URI goes to the enterprise IdP, so the URI is registered on the IdP client from Client Settings, not on the Resource AS client named by the adjacent fields. Give the field EMA-specific copy and qualify the docs paragraph the same way (Copilot review). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
A JSON result past ContentViewer's 200-row Ace cap scrolled inside the editor while the Results panel's ScrollArea also scrolled the whole result, so two vertical scrollbars sat side by side. Add an optional `jsonMaxLines` prop to ContentViewer (defaulting to the existing cap, so the Protocol/Network lists keep it) and pass Infinity from ToolResultPanel, whose scroll regions already scroll a block whole. Adds a LongJsonResult story whose play function asserts on real geometry that Ace's vertical scrollbar stays hidden while the panel's viewport overflows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
The dev Vite middleware wrote the health response inline, in a file that is excluded from coverage, so its headers and HEAD handling had no test. Move it into handleNodeHealthRequest() in health.ts and drive that from a real node:http server in health.test.ts. health.ts stays at 100% on all four dimensions. Copilot review on #2585. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Redact the TUI's nested OAuth failure and skills-list error, the web skills-list alert, the failed step-up outcome and the pagination ServerListReloadError toast. Classify the deep-link 409 on the raw message and redact only the recorded copy, with a regression test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
…eview Redact the TUI's interactive-reauth and standard step-up OAuth catches and the failed-revocation detail in both clients' clear warnings, with regression tests for each. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
…rollup Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
…ollup Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
…ollup Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
This was referenced Oct 5, 2026
Member
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #2569
Rollup check — DO NOT MERGE. This draft PR merges the branches of every open PR for tracker #2569's sub-issues (web client, v2.10.0) onto the current
v2/main. It exists only to show that they merge together cleanly and that CI passes on the combined result. Each PR is reviewed and merged on its own; close this once they land.v2/fix/2429-deeplink-constant-time-compare679c5ce3v2/feat/2438-web-healthzc22de805v2/feat/2524-oauth-redirect-uri-displayd513efd8v2/fix/2490-redact-displayed-error-urls55a1fe84v2/fix/2525-results-double-scrollbara95c905fAll five merged into
v2/main(9393237c) with no conflicts, in the order above, as signed-off--no-ffmerge commits.The individual PRs record that a full
local:gatecould not run cleanly in the sandbox they were built in: HTTP-proxy 502s on local integration tests, a bind-mount-specificisOnMountPointfailure, and gate-lease queue timeouts. This PR's CI is the combined check for those.🤖 Generated with Claude Code