mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-07 23:42:21 +02:00
fix(mcp): reject malformed Args on Add MCP Server instead of defaulting to []
`add_server` wrapped `json.loads(args)` in a bare `except` that fell back to `[]`, so an Args value that is not JSON — a bare path, which is what the form's placeholder invites people to type — registered the server and spawned the stdio subprocess with an empty argv. Nothing surfaced the loss: the POST returned 200 and the row persisted with `"args": []`. The route now returns 400 for an unparseable value, and also for valid JSON of the wrong shape: `args=5` reached `StdioServerParameters(args=5)` and raised an unhandled TypeError in the error formatter's `" ".join(...)`. Both form clients mirror the guard instead of leaving the user to read a 400 they cannot see. `settings.js` stops silently defaulting a bad Args value, and `admin.js` gains the same client-side parse check plus a `res.ok` branch so a server-side rejection is not reported as a connection failure. Ported from public `dev` (`9d5c0319`, #6215 upstream, fixing #6211), with its test. The `admin.js` hunks are inert on `lab` — `initMcpForm` early-returns because that form's markup is not in this build — and are carried anyway to keep the two lines from diverging further.
This commit is contained in:
@@ -5102,7 +5102,11 @@ async function initUnifiedIntegrations() {
|
||||
fd.append('transport', transport);
|
||||
if (transport === 'stdio') {
|
||||
fd.append('command', el('uf-mcp-cmd').value);
|
||||
let args = '[]'; try { args = JSON.stringify(JSON.parse(el('uf-mcp-args').value || '[]')); } catch (_) {}
|
||||
// Unlike env below, an unparseable args value is not silently
|
||||
// defaulted: it would spawn the subprocess with an empty argv.
|
||||
let args;
|
||||
try { args = JSON.stringify(JSON.parse(el('uf-mcp-args').value || '[]')); }
|
||||
catch (_) { el('uf-mcp-msg').textContent = 'Args must be valid JSON, e.g. ["-y", "pkg"]'; return; }
|
||||
let env = '{}'; try { env = JSON.stringify(JSON.parse(el('uf-mcp-env').value || '{}')); } catch (_) {}
|
||||
fd.append('args', args);
|
||||
fd.append('env', env);
|
||||
|
||||
Reference in New Issue
Block a user