Repository navigation
fix(mcp): mask Unicode profile credentials without panicking - #1180
Open
joshrotenberg wants to merge 4 commits into
Open
joshrotenberg wants to merge 4 commits into
joshrotenberg wants to merge 4 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Fixes #1179. Leaves #1173 open.
The dedicated empty kickoff commit and visible draft preceded implementation. Current pushed checkpoint: e505bb3. Refreshed with main 1453352; the merge changes only the already-approved GitHub Actions dependency pin. Rust source/tests/manifests/lockfile are identical to implementation checkpoint 3a4a27b.
Change
The PR diff changes only crates/redisctl-mcp/src/tools/profile.rs. No profile storage, policy, target selection, migration, credential provisioning or release changes.
Evidence
The original masking expression panicked for synthetic emoji-prefixed/suffixed credentials; an ASCII control did not. No real credentials or customer services were used.
At implementation checkpoint 3a4a27b:
Fresh at final head e505bb3: formatting, diff checks and all-target/all-feature Clippy pass. The code-identical tests above were not redundantly rerun after a workflow-only merge.
Docker availability was refreshed and the daemon is unavailable. Existing ignored Docker/live tests were not run locally or counted as passing. The upstream proc-macro-error2 future-incompatibility warning remains; it is not a Clippy failure.
Final diff re-reviewed October 6 for ASCII compatibility, UTF-8 boundaries, suffix order, short-value masking and scope isolation. Current-head validation is complete at
e505bb30febbd8bb60bb332b5292b6b4cbf0b45e: 10 successful checks and 6 expected skips, no failed or pending checks. CI passed Quick Checks, all three unit jobs, hosted integration/Redis command-safety smoke tests, Linux all-feature workspace tests and Linux/macOS/Windows builds. Dist plan passed; release artifact/publication jobs and main-only coverage were skipped as expected, not claimed as release evidence. Cargo-deny/audit/docs workflows were not triggered by this source-only diff under their existing path filters; no gate is bypassed or changed.Implementation and intended validation are complete, so this PR is ready for human review. GitHub's required approval remains separate. No merge, release, credential storage, onboarding contract or migration default change is initiated.
Readiness reconciled October 6 at approximately 12:07 PDT. No code changes or redundant test reruns were needed after final-head CI completion.