Skip to content

Fix the v2.10.0 milestone-merge review findings: TUI error redaction bypass, mcpdo daemon stderr flush, CodeQL #78-#81 #2638

Description

@cliffhall

Problem

Found by Copilot and CodeQL on the v2.10.0 milestone merge, PR #2637 (#2623). Every item is in code this release ships.

  1. The TUI shows unredacted error text in three new places (security). Redact URL query secrets in error text displayed by the web and TUI clients #2490 routed the TUI's error display through clients/tui/src/utils/errorText.ts errorMessage(), which redacts URL query secrets. The Tasks tab, Subscriptions tab and Roots editor added by TUI has no UI for Tasks, resource subscriptions, or Roots #2432 still render err.message directly:

    • TasksTab.tsx:121, through its own unredacted errorMessage copy at line 50
    • SubscriptionsTab.tsx:119
    • RootsModal.tsx:92

    A server error quoting https://…?code=…&access_token=… is drawn on screen verbatim.

  2. The mcpdo daemon can exit before its startup error is written. clients/mcpdo/src/daemon/run.ts calls process.exit(1) straight after process.stderr.write(…). When stderr is a pipe, writes are asynchronous on macOS, so the diagnostic can be lost. The shared CLI error handler already exits from the write callback.

  3. CodeQL fix windows issue with bin/cli.js #78, clients/cli/src/completion.ts zshDescribeEntry: escapes : but not \. Flag names never contain either, so this is unreachable today, but the escaping is incomplete.

  4. CodeQL Fix launch issues on Windows #79–Respect custom server port #81, test-only: a URL substring check in clients/mcpdo/__tests__/connection-stored-auth.test.ts:147,193, and a first-occurrence replace("{", …) in clients/web/src/test/core/auth/oauth-namespace-ledger.test.ts:136. Both are intended, but rewriting them clears the alerts without a dismissal.

Expected

  • All three TUI sites use the shared errorMessage(), and tests prove a secret-bearing error is redacted on each.
  • The daemon exits from the stderr write callback.
  • zshDescribeEntry escapes backslashes before colons.
  • The tests are written so CodeQL reports nothing.

Priority

High (rubric total 10): Severity 4 (secrets on screen in a shipped client), Urgency 4 (blocks the release merge), +1 bug, +1 milestoned.

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingv2Issues and PRs for v2

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions