Skip to content

fix(registries): catalog matching, namespace owner, Verified wording and doc drift - #1508

Merged
Dumbris merged 2 commits into
mainfrom
fix/issues-b11-backend-registries
Oct 5, 2026
Merged

Dumbris merged 2 commits into
mainfrom
fix/issues-b11-backend-registries

Conversation

@Dumbris

@Dumbris Dumbris commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

Fixed catalog matching for namespace owner verification by using token-based cache invalidation and restricting ccTLD handling to second-level suffixes only. Corrected specification drift in health vocabulary and MCP tools documentation across catalog and UX surfaces.

Changes

  • Catalog namespace matching: Implemented token-based cached match for owner verification, restricting ccTLD (country-code top-level domain) identification to second-level suffixes only to reduce false owner attribution
  • Documentation drift: Corrected health-vocabulary.md, mcp-tools.md contracts and catalog-commands documentation to reflect current specification
  • Test coverage: Added tests for telemetry command output and catalog hit signals under various conditions

Open Findings (review findings, not regressions)

F1.1 — ccTLD guard allows unexpected owner (low-deferred)
With the ccTLD guard, an id like com.org.evil/x now has owner org (labels[1]), and domainLabelMatchesOwner accepts org as a whole token of repo owner acme-org, so Verified can be true for a namespace the publisher does not own. Before, the owner was evil. The same weakness already existed for the 2-label form com.org/x. This needs the publisher to control a subdomain of org.com on an official registry, and the PR's own acceptance (com.org.github/x is not owner github) mandates this owner choice. Consider rejecting suffix words (org/com/net/gov/edu) as owners.

F1.2 — TestRunTelemetryStatus test missing MCPPROXY_OUTPUT env pin (low-deferred)
TestRunTelemetryStatus_ReportsEnvOverride asserts text output but does not pin MCPPROXY_OUTPUT. If it is set to json or yaml, the expected strings are missing and the test fails.

F1.3 — TestStatus_ReportsListenAddr weak oracle (low-deferred)
TestStatus_ReportsListenAddr only checks the mock controller's hard-coded :8080. It can fail only if the handler drops the listen_addr key, so it cannot catch regressions in how the real listen address is derived.

Refs #1466
Closes #1432

@Dumbris
Dumbris enabled auto-merge (squash) October 5, 2026 12:58
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: bda76b5
Status: ✅  Deploy successful!
Preview URL: https://5c3374a5.mcpproxy-docs.pages.dev
Branch Preview URL: https://fix-issues-b11-backend-regis.mcpproxy-docs.pages.dev

View logs

@Dumbris Dumbris changed the title fix(registries)+docs: catalog matching and namespace owner, Verified wording, spec/contract doc drift fix(registries): catalog matching, namespace owner, Verified wording and doc drift Oct 5, 2026
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 88.23529% with 2 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/registries/catalog.go 75.00% 1 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@Dumbris
Dumbris merged commit b1c5e8b into main Oct 5, 2026
45 of 46 checks passed
Dumbris added a commit that referenced this pull request Oct 6, 2026
… PRs (#1521)

## Summary

Low-severity follow-ups from review of the catalog (#1508), telemetry
and e2e cleanup PRs (#1514).

- L1 (catalog review): `domainLabelMatchesOwner` rejects TLD and
second-level suffix words (com, org, net, gov, edu, co, ac, io), so
`com.org.evil/x` no longer verifies as owner `org` against `acme-org`.
Test: `TestDomainLabelMatchesOwner_RejectsTLDWords`.
- L2 (telemetry review): `TestStatus_ReportsListenAddr` pinned `:8080`
from a shared default. It now sets an explicit listen address on the
scope controller (`127.0.0.1:18765`) and asserts it. Test:
`TestStatus_ReportsListenAddr`.
- L3 (telemetry review): `TestRunTelemetryStatus_ReportsEnvOverride`
clears `MCPPROXY_OUTPUT` so an ambient value cannot change the output
format under test.
- L4 (e2e cleanup review): `scripts/test-api-e2e.sh` replaces BSD-only
`sed -i ''` with a portable write-and-move, so it also runs with GNU
sed.
- L5 (e2e cleanup review): `scripts/test-api-e2e-cleanup-check.sh`
sources the shared `scripts/descendant-pids.sh` helper instead of
carrying its own recursive copy.

## Review status

Clean. Unresolved findings: [].

Refs #1466
Refs #1388
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Follow-ups from Spec 109 leftovers review (#1428)

2 participants