You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TasksTab.tsx:121, through its own unredacted errorMessage copy at line 50
SubscriptionsTab.tsx:119
RootsModal.tsx:92
A server error quoting https://…?code=…&access_token=… is drawn on screen verbatim.
The mcpdo daemon can exit before its startup error is written.clients/mcpdo/src/daemon/run.ts calls process.exit(1) straight after process.stderr.write(…). When stderr is a pipe, writes are asynchronous on macOS, so the diagnostic can be lost. The shared CLI error handler already exits from the write callback.
CodeQL fix windows issue with bin/cli.js #78, clients/cli/src/completion.tszshDescribeEntry: escapes : but not \. Flag names never contain either, so this is unreachable today, but the escaping is incomplete.
CodeQL Fix launch issues on Windows #79–Respect custom server port #81, test-only: a URL substring check in clients/mcpdo/__tests__/connection-stored-auth.test.ts:147,193, and a first-occurrence replace("{", …) in clients/web/src/test/core/auth/oauth-namespace-ledger.test.ts:136. Both are intended, but rewriting them clears the alerts without a dismissal.
Expected
All three TUI sites use the shared errorMessage(), and tests prove a secret-bearing error is redacted on each.
The daemon exits from the stderr write callback.
zshDescribeEntry escapes backslashes before colons.
The tests are written so CodeQL reports nothing.
Priority
High (rubric total 10): Severity 4 (secrets on screen in a shipped client), Urgency 4 (blocks the release merge), +1 bug, +1 milestoned.
Problem
Found by Copilot and CodeQL on the v2.10.0 milestone merge, PR #2637 (#2623). Every item is in code this release ships.
The TUI shows unredacted error text in three new places (security). Redact URL query secrets in error text displayed by the web and TUI clients #2490 routed the TUI's error display through
clients/tui/src/utils/errorText.tserrorMessage(), which redacts URL query secrets. The Tasks tab, Subscriptions tab and Roots editor added by TUI has no UI for Tasks, resource subscriptions, or Roots #2432 still rendererr.messagedirectly:TasksTab.tsx:121, through its own unredactederrorMessagecopy at line 50SubscriptionsTab.tsx:119RootsModal.tsx:92A server error quoting
https://…?code=…&access_token=…is drawn on screen verbatim.The mcpdo daemon can exit before its startup error is written.
clients/mcpdo/src/daemon/run.tscallsprocess.exit(1)straight afterprocess.stderr.write(…). When stderr is a pipe, writes are asynchronous on macOS, so the diagnostic can be lost. The shared CLI error handler already exits from the write callback.CodeQL fix windows issue with bin/cli.js #78,
clients/cli/src/completion.tszshDescribeEntry: escapes:but not\. Flag names never contain either, so this is unreachable today, but the escaping is incomplete.CodeQL Fix launch issues on Windows #79–Respect custom server port #81, test-only: a URL substring check in
clients/mcpdo/__tests__/connection-stored-auth.test.ts:147,193, and a first-occurrencereplace("{", …)inclients/web/src/test/core/auth/oauth-namespace-ledger.test.ts:136. Both are intended, but rewriting them clears the alerts without a dismissal.Expected
errorMessage(), and tests prove a secret-bearing error is redacted on each.zshDescribeEntryescapes backslashes before colons.Priority
High (rubric total 10): Severity 4 (secrets on screen in a shipped client), Urgency 4 (blocks the release merge), +1
bug, +1 milestoned.