Repository navigation
fix(registries): catalog matching, namespace owner, Verified wording and doc drift - #1508
Merged
Merged
Conversation
Dumbris
enabled auto-merge (squash)
October 5, 2026 12:58
Deploying mcpproxy-docs with
|
| Latest commit: |
bda76b5
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://5c3374a5.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://fix-issues-b11-backend-regis.mcpproxy-docs.pages.dev |
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
Dumbris
added a commit
that referenced
this pull request
Oct 6, 2026
… PRs (#1521) ## Summary Low-severity follow-ups from review of the catalog (#1508), telemetry and e2e cleanup PRs (#1514). - L1 (catalog review): `domainLabelMatchesOwner` rejects TLD and second-level suffix words (com, org, net, gov, edu, co, ac, io), so `com.org.evil/x` no longer verifies as owner `org` against `acme-org`. Test: `TestDomainLabelMatchesOwner_RejectsTLDWords`. - L2 (telemetry review): `TestStatus_ReportsListenAddr` pinned `:8080` from a shared default. It now sets an explicit listen address on the scope controller (`127.0.0.1:18765`) and asserts it. Test: `TestStatus_ReportsListenAddr`. - L3 (telemetry review): `TestRunTelemetryStatus_ReportsEnvOverride` clears `MCPPROXY_OUTPUT` so an ambient value cannot change the output format under test. - L4 (e2e cleanup review): `scripts/test-api-e2e.sh` replaces BSD-only `sed -i ''` with a portable write-and-move, so it also runs with GNU sed. - L5 (e2e cleanup review): `scripts/test-api-e2e-cleanup-check.sh` sources the shared `scripts/descendant-pids.sh` helper instead of carrying its own recursive copy. ## Review status Clean. Unresolved findings: []. Refs #1466 Refs #1388
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixed catalog matching for namespace owner verification by using token-based cache invalidation and restricting ccTLD handling to second-level suffixes only. Corrected specification drift in health vocabulary and MCP tools documentation across catalog and UX surfaces.
Changes
health-vocabulary.md,mcp-tools.mdcontracts and catalog-commands documentation to reflect current specificationOpen Findings (review findings, not regressions)
F1.1 — ccTLD guard allows unexpected owner (low-deferred)
With the ccTLD guard, an id like
com.org.evil/xnow has ownerorg(labels[1]), anddomainLabelMatchesOwneracceptsorgas a whole token of repo owneracme-org, so Verified can be true for a namespace the publisher does not own. Before, the owner wasevil. The same weakness already existed for the 2-label formcom.org/x. This needs the publisher to control a subdomain oforg.comon an official registry, and the PR's own acceptance (com.org.github/xis not owner github) mandates this owner choice. Consider rejecting suffix words (org/com/net/gov/edu) as owners.F1.2 — TestRunTelemetryStatus test missing MCPPROXY_OUTPUT env pin (low-deferred)
TestRunTelemetryStatus_ReportsEnvOverrideasserts text output but does not pinMCPPROXY_OUTPUT. If it is set tojsonoryaml, the expected strings are missing and the test fails.F1.3 — TestStatus_ReportsListenAddr weak oracle (low-deferred)
TestStatus_ReportsListenAddronly checks the mock controller's hard-coded:8080. It can fail only if the handler drops thelisten_addrkey, so it cannot catch regressions in how the real listen address is derived.Refs #1466
Closes #1432