fix(coding-agent): addressed review findings for runtime MCP support

- Removed unsafe OAuth endpoint extraction from error message text
- Fixed PKCE verifier storage with typed #codeVerifier field
- Fixed refresh token fallback using access token as refresh token
- Enforced restrictive file permissions (0o700/0o600) for MCP configs
- Fixed wizard buildConfig() to respect user-chosen env var and header names
- Fixed reauth endpoint discovery for non-OAuth servers
- Stored original config on connection, resolved config only for transport
- Added runtime type validation for enabled/timeout in config loaders
- Converted all TS private keywords to ES # private fields
- Wrapped uncaught throws in /mcp add with try/catch error handling
- Replaced new Promise with Promise.withResolvers() pattern
- Sanitized TUI output with replaceTabs/truncateToWidth
- Enforced http/https URL validation in add wizard
- Fixed greedy /mcp prefix match in input controller
- Corrected config filename references in MCP guide
- Added server name validation to updateMCPServer
- Fixed timeout timer leak in stdio transport
This commit is contained in:
can1357
2026-02-10 14:31:19 +01:00
parent 7e4bedf18b
commit 4da2acbee4
11 changed files with 887 additions and 785 deletions
+1 -1
View File
@@ -301,7 +301,7 @@ Project-specific configuration (usually in project root).
3. **Secure sensitive data**
- Use OAuth when available
- Use shell commands for API keys: `!op read op://vault/key`
- Never commit `.mcp.json` files with plain API keys to version control
- Never commit `.omp/mcp.json` files with plain API keys to version control
4. **Name servers descriptively**
- Use purpose-based names: "github-tools", "docs-search"