fix(hub): never echo credential material and only use active credentials - #17
Merged
Conversation
TheGreatAxios
added this pull request to stack #12
September 27, 2026 02:23
TheGreatAxios
force-pushed
the
cl-9453-mcp-never-echo-credential-material-and-only-use-active
branch
from
September 27, 2026 02:44
ff68c73 to
c195f06
Compare
TheGreatAxios
force-pushed
the
cl-9453-mcp-never-echo-credential-material-and-only-use-active
branch
from
September 27, 2026 02:44
c195f06 to
2927246
Compare
TheGreatAxios
force-pushed
the
cl-9453-mcp-never-echo-credential-material-and-only-use-active
branch
from
September 27, 2026 18:35
2927246 to
df1d2c7
Compare
A secret that is not a valid header value is refused with a fixed message before any request, and the discovery route reports non-McpError causes, to the caller and to onError, as a generic handshake error. readCredential returns only active, unexpired credentials.
TheGreatAxios
force-pushed
the
cl-9453-mcp-never-echo-credential-material-and-only-use-active
branch
from
September 27, 2026 18:49
df1d2c7 to
9b3600e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A stored secret containing CR, LF or NUL made fetch throw a header error that quoted the secret, and the route put that message in the 422 and in
onError. Revoked, expired or errored credentials were still decrypted and sent.Changes
discoverMcpServerrefuses a secret that is not a valid header value (anything outside tab and printable ASCII) with a fixed message, before any request.McpErrormessages; any other cause becomes "the handshake failed", in the response and inonError. The package's own refusals (no API origin, off-origin target, redirect) areMcpErrors. The off-origin check now runs indiscoverMcpServerbefore the pinned fetch, with the same message credential-http uses.readCredentialreturns onlystatus: "active"credentials that have not expired; anything else reads as absent (404).onError; a fetch failure reads as a generic handshake error; revoked, errored and expired credentials read as absent.Checks
bun run check,bun run buildand the Node pack smoke pass locally.Closes CL-9453