mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-09 00:12:21 +02:00
fix(mcp): reject malformed Args on Add MCP Server instead of defaulting to []
`add_server` wrapped `json.loads(args)` in a bare `except` that fell back to `[]`, so an Args value that is not JSON — a bare path, which is what the form's placeholder invites people to type — registered the server and spawned the stdio subprocess with an empty argv. Nothing surfaced the loss: the POST returned 200 and the row persisted with `"args": []`. The route now returns 400 for an unparseable value, and also for valid JSON of the wrong shape: `args=5` reached `StdioServerParameters(args=5)` and raised an unhandled TypeError in the error formatter's `" ".join(...)`. Both form clients mirror the guard instead of leaving the user to read a 400 they cannot see. `settings.js` stops silently defaulting a bad Args value, and `admin.js` gains the same client-side parse check plus a `res.ok` branch so a server-side rejection is not reported as a connection failure. Ported from public `dev` (`9d5c0319`, #6215 upstream, fixing #6211), with its test. The `admin.js` hunks are inert on `lab` — `initMcpForm` early-returns because that form's markup is not in this build — and are carried anyway to keep the two lines from diverging further.
This commit is contained in:
@@ -181,10 +181,17 @@ def setup_mcp_routes(mcp_manager: McpManager):
|
||||
if transport == "http" and not url:
|
||||
raise HTTPException(400, "url is required for HTTP transport")
|
||||
|
||||
# Parse JSON fields
|
||||
try:
|
||||
parsed_args = json.loads(args) if args else []
|
||||
except json.JSONDecodeError:
|
||||
# Parse JSON fields. args is not defaulted on a parse failure: an
|
||||
# unparseable value is silently discarded downstream (stdio spawns
|
||||
# with an empty argv), so the caller must be told instead.
|
||||
if args:
|
||||
try:
|
||||
parsed_args = json.loads(args)
|
||||
except json.JSONDecodeError:
|
||||
raise HTTPException(400, "args must be valid JSON, e.g. [\"-y\", \"pkg\"]")
|
||||
if not isinstance(parsed_args, list):
|
||||
raise HTTPException(400, "args must be a JSON array, e.g. [\"-y\", \"pkg\"]")
|
||||
else:
|
||||
parsed_args = []
|
||||
try:
|
||||
parsed_env = json.loads(env) if env else {}
|
||||
|
||||
Reference in New Issue
Block a user