Repository navigation
Final done-check residuals (Spec 108/109 UX effort) #1466
Description
Activity
- addedkind/bugSomething isn't workingSomething isn't workingpriority/lowNice to have; address when bandwidth allowsNice to have; address when bandwidth allowstriage/acceptedTriaged and accepted for the backlogTriaged and accepted for the backlog
on Oct 2, 2026 Remaining lows from #1467:
-
frontend/src/views/Activity.vue:2062(showBlockedOffer): "Show N blocked attempts" does nothing when an explicit type override excludespolicy_decision. -
frontend/src/views/Home.vue:47: on a fresh instance the usage strip flashes before the servers store loads. -
frontend/src/views/ServerDetail.vue:1931/1963: after an optimistic disable or quarantine, the Health tile still reads "Online" until the next refresh. -
native/macos/MCPProxy/MCPProxyTests/HomeTokenSavingsBadgeTests.swift:54: the test checks the whole source file, so it can't detect the card losing its shared estimate label. - Opening
/servers/<disabled server>logs a console error from a 500 ("Failed to get logs: server not found").
-
Remaining lows from catalog ranking PR #1469:
-
internal/registries/listing_cache.go:146matchCachedEntrymatches literal substrings only, so a multi-word query like "github actions" misses hyphenated names in the cached fallback. -
internal/registries/catalog.go:585namespaceOwnerskips second-level suffixes without checking the first label is a country code (com.org.github/x→ owner "github"). This feeds Verified and stars. -
internal/registries/catalog.go:496: residual Verified-badge spoofing via generic domain labels (labs/tools/mcp). Narrower than before the PR, and not a regression. -
docs/api/rest-api.md:1004anddocs/cli/catalog-commands.md:37: the "verified" wording doesn't cover the trusted Docker/reference exception. -
specs/109-ux-navigation-consistency/quickstart.md:130: the recipe says 3 official requests per typed search, but its multi-word step makes 4.
-
Remaining lows from review-screen PR #1470:
-
internal/runtime/review.go:341-347withinternal/server/review_capture.go:49: coverage matches scan to record by tool name only. A server serving a benign definition to the scanner and a poisoned one at capture can read "clean". Fix: store per-tool definition hashes (or export time) inScanContext. The approval gate re-scans independently, so this is a documented residual. -
cmd/mcpproxy/review_cmd.go:259-264: with noscan.coverage(older core), the CLI prints no Scan line, while Web and macOS read it as "none". -
specs/109-ux-navigation-consistency/contracts/mcp-tools.md:8: theserver_summary.scancoverage sentence only holds on the captured branch ofinspect_quarantined/inspect_tools. -
frontend/src/components/ReviewScreen.vue:95-98,131: an in-flight rescan error from server A can overwrite server B's state after switching servers. Fix: capture the server name at call time.
-
Remaining lows from CLI/security PR #1472:
-
cmd/mcpproxy/registry_cmd.go:632:loadRegistryConfigswallows load errors. An explicit global-cpointing at a missing file isn't reported as CONFIG_NOT_FOUND for registry or catalog commands. -
cmd/mcpproxy/cli_config.go:30-35: the "data-dir given, no config anywhere" branch usesDefaultConfig()and skips theMCPPROXY_LISTEN/TLS env overrides. -
cmd/mcpproxy/doctor_redact.go:23:doctorURLPatternstops at an apostrophe, so a percent-encoded credential parameter after an apostrophe in the same URL escapes redaction (?label=Bob's&%74oken=...).
-
Remaining lows from Web user-test PR #1473:
-
frontend/src/components/OnboardingWizard.vue:901-904andutils/onboardingServersStep.ts:44-47: "including the N you just imported" assumes this session's imports were quarantined, which isn't true when the quarantine box was unchecked. -
frontend/src/components/ImportServers.vue:267: paste/file import emitsnames.lengthrather thansummary.imported, so re-applying already-existing servers counts as new imports. -
internal/httpapi/import.go:300-313: a{}config previewed without aformathint still returns 400, while the swagger text promises 200. Only the paste-mode Quick-import button hits this path.
-
Remaining lows from telemetry/macOS PR #1471:
-
frontend/src/components/TelemetryBanner.vue:116-118: the effective telemetry state is fetched only on mount, so a notice left open can show an obsolete mode. -
specs/109-ux-navigation-consistency/parity-matrix.json:1566: row 28a citestelemetry_cmd_test.gofortelemetry status, but that file doesn't assert it. -
specs/109-ux-navigation-consistency/parity-matrix.json:1673: row 29a citesstatus_telemetry_test.go, which never assertsstatus.listen_addr.
-
From live QA of #1468: a nested
call_toolto a server outside a profile-bound agent token's scope is refused by the token server check ("token does not have access to server 'fx'", ACCESS_DENIED). Its childtool_callrecord has noblock_reason. A nested tier refusal correctly recordsblock_reason=profile_tier. Server-scope refusals for profile-bound callers should probably carry a profile scope reason too, for consistent Activity filtering and the "Why?" view.- Add a
block_reasonfor nested server-scope refusals of profile-bound tokens and client credentials.
- Add a
Remaining lows from telemetry/macOS PR #1471:
-
frontend/src/utils/telemetryState.ts:55andinternal/httpapi/server.go:5675-5710: the Raw JSON telemetry lock is enforced only in the client. A duplicate case-variant key can storetelemetry.enabled; at runtime the env override still forces it off. Enforce the lock on the server, or reject case-variant duplicates of locked keys. -
native/macos/MCPProxy/MCPProxy/Settings/ConfigSettingsView.swift:121-126:adoptRunningListenIfBlankrefills a deliberately cleared listen field on the next status refresh. It can also mark an unsaved typed value as clean when it happens to match the running address.
-
- From fix(review): review screen starts fail-closed with exact-count approve (Spec fix-review-defaults) #1481 QA:
mcpproxy review approve --allon a re-quarantined server prints "Allowing 14 of 14 tools; blocking none" while previously blocked tools stay blocked (cmd/mcpproxy/review_cmd.go:289). Reword it the same way as the UI and docs: pending or changed tools are allowed, and previously blocked tools stay blocked.
- From fix(review): review screen starts fail-closed with exact-count approve (Spec fix-review-defaults) #1481 QA:
- added 16 commits that reference this issue
on Oct 5, 2026
Low-severity residuals from the final definition-of-done check on main d7efa80 (Spec 108/109 UX effort). The medium items are being fixed in dedicated PRs.
PATCH /configandretrieve_tools:PATCH /configreturns "No configuration changes detected" even when the change was applied.retrieve_toolsreturnsprofile: nullwhen nothing is hidden.connect codexwrites the credential as?apikey=in the URL. Check whether Codex supports a header and use that instead.test-api-e2e.shlauncher-test reconnect check fails intermittently (also at baseline 638fa80).mcp.go:541); verify it and close it.