Skip to content

fix(hub): never echo credential material and only use active credentials - #17

Merged
TheGreatAxios merged 1 commit into
cl-9452-mcp-bound-discovery-time-and-stream-sizefrom
cl-9453-mcp-never-echo-credential-material-and-only-use-active
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
cl-9452-mcp-bound-discovery-time-and-stream-sizefrom
cl-9453-mcp-never-echo-credential-material-and-only-use-active

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

A stored secret containing CR, LF or NUL made fetch throw a header error that quoted the secret, and the route put that message in the 422 and in onError. Revoked, expired or errored credentials were still decrypted and sent.

Changes

  • discoverMcpServer refuses a secret that is not a valid header value (anything outside tab and printable ASCII) with a fixed message, before any request.
  • The route passes on only McpError messages; any other cause becomes "the handshake failed", in the response and in onError. The package's own refusals (no API origin, off-origin target, redirect) are McpErrors. The off-origin check now runs in discoverMcpServer before the pinned fetch, with the same message credential-http uses.
  • readCredential returns only status: "active" credentials that have not expired; anything else reads as absent (404).
  • Tests (each fails before the fix): CRLF, LF and NUL secrets are refused with no request and no secret in the response or onError; a fetch failure reads as a generic handshake error; revoked, errored and expired credentials read as absent.
  • README documents the 404 and 422 cases.

Checks

bun run check, bun run build and the Node pack smoke pass locally.

Closes CL-9453

@TheGreatAxios
TheGreatAxios added this pull request to stack #12 September 27, 2026 02:23
@TheGreatAxios
TheGreatAxios force-pushed the cl-9453-mcp-never-echo-credential-material-and-only-use-active branch from ff68c73 to c195f06 Compare September 27, 2026 02:44
@TheGreatAxios
TheGreatAxios force-pushed the cl-9453-mcp-never-echo-credential-material-and-only-use-active branch from c195f06 to 2927246 Compare September 27, 2026 02:44
@TheGreatAxios
TheGreatAxios force-pushed the cl-9453-mcp-never-echo-credential-material-and-only-use-active branch from 2927246 to df1d2c7 Compare September 27, 2026 18:35
A secret that is not a valid header value is refused with a fixed message
before any request, and the discovery route reports non-McpError causes, to
the caller and to onError, as a generic handshake error. readCredential
returns only active, unexpired credentials.
@TheGreatAxios
TheGreatAxios force-pushed the cl-9453-mcp-never-echo-credential-material-and-only-use-active branch from df1d2c7 to 9b3600e Compare September 27, 2026 18:49
@TheGreatAxios
TheGreatAxios merged commit e1b0b54 into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant