Files
buzz/crates
npub1mn7jgtj4w2pd0g0zeuhxsa6jy6p0rewxz4kujt98my82ahfmp72sxjexk7andWill Pfleger b1ba455996 fix(desktop): address pass-1 review findings on MCP server configuration
F1: Extend env_secrets_from_request in backend.rs to harvest
mcp_servers[*].env[*].value alongside env_vars, so provider errors
that echo MCP env values are redacted from desktop-visible last_error.
Add two regression tests: one verifying harvest coverage, one verifying
end-to-end redaction.

F2: Extend validate_mcp_servers in types/mcp_servers.rs to mirror the
buzz-agent name grammar (1-128 bytes, ASCII alnum/_/-, no __) and
reserve the built-in buzz-dev-mcp name. Both checks fire at every IPC
save boundary, so names that would fail at spawn are rejected at edit
time. Add tests covering invalid chars, double-underscore, reserved
name, valid grammar.

F3: Restructure build_mcp_servers in buzz-acp/src/lib.rs so the
built-in server push is conditional on mcp_command being non-empty, but
configured_mcp_servers are always appended. Previously the early-return
on empty mcp_command silently discarded user-configured servers even
though they don't depend on the built-in slot. Update the test that
pinned the old drop behavior; add a complementary empty-with-no-servers
test.

F4: Add an enabled-server count check to validate_mcp_servers: a layer
with more than MAX_USER_MCP_SERVERS enabled servers is rejected at save
time rather than only at merge/spawn. Add boundary tests (15 passes,
16 fails).

MINOR: Add mcp_servers to the MUST NEVER list in agent_events.rs so
future edits don't miss the local-only invariant.

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
2026-07-14 17:34:04 -04:00
..