Repository navigation
fix(mcp_adapter): stop writing the caller's password to stderr and the log (ISSUE-121) - #425
Merged
dwolfson merged 2 commits intoOct 5, 2026
Conversation
…e log (ISSUE-121) run_report and _execute_egeria_call_blocking printed user_pass to stderr, and run_report also logged it via loguru. One _describe_call() helper now builds the diagnostic for all three sites: it keeps report, params, server and user, and says which kind of credential was supplied instead of its value. Also corrects the ISSUE-121 entry (three sites in two functions; the settings-fallback path never leaked). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Dan Wolfson <dan.wolfson@pdr-associates.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
run_reportand_execute_egeria_call_blockingwrote the caller'suser_passto stderr, andrun_reportalso logged it via loguru (three sites, two functions). A single_describe_call()helper now builds the diagnostic for all three: it keeps report/params/server/user and states the kind of credential (bearer token / explicit user/password / defaults from settings), never the value.Test plan
test_mcp_adapter_no_secret_logging.py(5 tests) asserts a sentinel password/token is absent from stderr and a loguru sink; fails on the old codetests/micro-testspasses🤖 Generated with Claude Code