fix(mcp): redact URL paths in logs
This commit is contained in:
@@ -170,7 +170,8 @@ def _redact_url(url: str) -> str:
|
|||||||
"""Strip credentials and query/fragment before logging an MCP URL.
|
"""Strip credentials and query/fragment before logging an MCP URL.
|
||||||
|
|
||||||
Server URLs may embed secrets (``https://user:token@host/sse`` or a
|
Server URLs may embed secrets (``https://user:token@host/sse`` or a
|
||||||
``?token=`` query); only scheme, host, port, and path are safe to log.
|
``?token=`` query). Some deployments also put opaque tokens in the path, so
|
||||||
|
log only the origin and a path placeholder.
|
||||||
"""
|
"""
|
||||||
try:
|
try:
|
||||||
parts = urllib.parse.urlsplit(url)
|
parts = urllib.parse.urlsplit(url)
|
||||||
@@ -178,7 +179,8 @@ def _redact_url(url: str) -> str:
|
|||||||
netloc = f"[{hostname}]" if ":" in hostname else hostname
|
netloc = f"[{hostname}]" if ":" in hostname else hostname
|
||||||
if parts.port:
|
if parts.port:
|
||||||
netloc = f"{netloc}:{parts.port}"
|
netloc = f"{netloc}:{parts.port}"
|
||||||
return urllib.parse.urlunsplit((parts.scheme, netloc, parts.path, "", ""))
|
path = "/..." if parts.path and parts.path != "/" else parts.path
|
||||||
|
return urllib.parse.urlunsplit((parts.scheme, netloc, path, "", ""))
|
||||||
except Exception:
|
except Exception:
|
||||||
return "<redacted-url>"
|
return "<redacted-url>"
|
||||||
|
|
||||||
|
|||||||
@@ -1245,10 +1245,12 @@ async def test_connect_mcp_servers_enabled_tools_matches_sanitized_name(
|
|||||||
@pytest.mark.parametrize(
|
@pytest.mark.parametrize(
|
||||||
"url, expected",
|
"url, expected",
|
||||||
[
|
[
|
||||||
("https://user:secret@host.example/sse", "https://host.example/sse"),
|
("https://user:secret@host.example/sse", "https://host.example/..."),
|
||||||
("https://host.example:8443/mcp?token=abc#frag", "https://host.example:8443/mcp"),
|
("https://host.example:8443/mcp?token=abc#frag", "https://host.example:8443/..."),
|
||||||
("https://user:secret@[::1]:8443/sse?token=abc", "https://[::1]:8443/sse"),
|
("https://user:secret@[::1]:8443/sse?token=abc", "https://[::1]:8443/..."),
|
||||||
("https://host.example/sse", "https://host.example/sse"),
|
("https://host.example/sse", "https://host.example/..."),
|
||||||
|
("https://host.example", "https://host.example"),
|
||||||
|
("https://host.example/", "https://host.example/"),
|
||||||
],
|
],
|
||||||
)
|
)
|
||||||
def test_redact_url_strips_credentials_and_query(url: str, expected: str) -> None:
|
def test_redact_url_strips_credentials_and_query(url: str, expected: str) -> None:
|
||||||
|
|||||||
Reference in New Issue
Block a user