Skip to content

gl(mcp): tools ignore HTTP status, turning node denials into successful results #505

Description

@PierrunoYT

Most gl mcp tools (crates/gl/src/mcp.rs) ignore the HTTP status, so a node denial comes back as a successful tool result. This violates the client rule in AGENTS.md (never render a denial as an empty list or a silent success). Only webhook_list was fixed; #397 is closed. They also interpolate tool args into request paths without URL-encoding, so dot-segment input can reach sibling endpoints; task_list shows the correct encoding. #493 covers the encoding for gl generally; this issue is the MCP surface and the status handling.

Fix: check the status in one shared MCP request helper and return an error result with the sanitized node message, and encode every path segment through the same helper.

Found in the Oct 2 2026 audit (A15) at bfc44f9.

Activity

  1. added
    kind:securityVulnerability fix or hardening
    sev:highMajor break or real security/trust risk, no easy workaround
    subsystem:apiNode REST API request/response surface
    crate:glgl — the contributor CLI
    on Oct 2, 2026
  2. beardthelion commented on Oct 2, 2026

    @beardthelion
    Collaborator

    The missing HTTP status checks duplicate #123 (fix open at #186), and the unencoded-path half is tracked in #493. Closing as covered by those; reopen if an MCP-specific case survives both.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:glgl — the contributor CLIkind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surface

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions