| 1 | package config |
| 2 | |
| 3 | import ( |
| 4 | "strings" |
| 5 | "testing" |
| 6 | ) |
| 7 | |
| 8 | // The line a user approves shows everything that changes which code runs. |
| 9 | func TestLaunchLineShowsEnvThatChangesWhatRuns(t *testing.T) { |
| 10 | line := MCPLaunchLine(PluginEntry{ |
| 11 | Name: "repo", Command: "npx", Args: []string{"-y", "@modelcontextprotocol/server-filesystem", "."}, |
| 12 | Env: map[string]string{"NODE_OPTIONS": "--require ./x.js", "DYLD_INSERT_LIBRARIES": "./x.dylib", "API_TOKEN": "secret-value"}, |
| 13 | }) |
| 14 | for _, want := range []string{`NODE_OPTIONS="--require ./x.js"`, `DYLD_INSERT_LIBRARIES="./x.dylib"`, "API_TOKEN=", "npx -y @modelcontextprotocol/server-filesystem ."} { |
| 15 | if !strings.Contains(line, want) { |
| 16 | t.Fatalf("launch line %q lacks %q", line, want) |
| 17 | } |
| 18 | } |
| 19 | if strings.Contains(line, "secret-value") { |
| 20 | t.Fatalf("launch line %q shows a value that does not change what runs", line) |
| 21 | } |
| 22 | } |
| 23 | |
| 24 | func TestLaunchLineRedactsEndpointCredentials(t *testing.T) { |
| 25 | line := MCPLaunchLine(PluginEntry{ |
| 26 | Name: "repo", Type: "http", URL: "https://mcp.example/mcp?access_token=SECRET1&workspace=main", |
| 27 | Headers: map[string]string{"Authorization": "Bearer SECRET2"}, |
| 28 | Env: map[string]string{"npm_config_registry": "https://registry.example/"}, |
| 29 | }) |
| 30 | if strings.Contains(line, "SECRET") { |
| 31 | t.Fatalf("launch line leaks a credential: %s", line) |
| 32 | } |
| 33 | for _, want := range []string{"workspace=main", "headers:Authorization", `npm_config_registry="https://registry.example/"`} { |
| 34 | if !strings.Contains(line, want) { |
| 35 | t.Fatalf("launch line %q lacks %q", line, want) |
| 36 | } |
| 37 | } |
| 38 | } |
| 39 |