fix(coding-agent): addressed review findings for runtime MCP support
- Removed unsafe OAuth endpoint extraction from error message text - Fixed PKCE verifier storage with typed #codeVerifier field - Fixed refresh token fallback using access token as refresh token - Enforced restrictive file permissions (0o700/0o600) for MCP configs - Fixed wizard buildConfig() to respect user-chosen env var and header names - Fixed reauth endpoint discovery for non-OAuth servers - Stored original config on connection, resolved config only for transport - Added runtime type validation for enabled/timeout in config loaders - Converted all TS private keywords to ES # private fields - Wrapped uncaught throws in /mcp add with try/catch error handling - Replaced new Promise with Promise.withResolvers() pattern - Sanitized TUI output with replaceTabs/truncateToWidth - Enforced http/https URL validation in add wizard - Fixed greedy /mcp prefix match in input controller - Corrected config filename references in MCP guide - Added server name validation to updateMCPServer - Fixed timeout timer leak in stdio transport
This commit is contained in:
@@ -301,7 +301,7 @@ Project-specific configuration (usually in project root).
|
||||
3. **Secure sensitive data**
|
||||
- Use OAuth when available
|
||||
- Use shell commands for API keys: `!op read op://vault/key`
|
||||
- Never commit `.mcp.json` files with plain API keys to version control
|
||||
- Never commit `.omp/mcp.json` files with plain API keys to version control
|
||||
|
||||
4. **Name servers descriptively**
|
||||
- Use purpose-based names: "github-tools", "docs-search"
|
||||
|
||||
Reference in New Issue
Block a user