Skip to content

fix(analytics): redact MCP client telemetry buckets - #505

Merged
JSONbored merged 1 commit into
mainfrom
codex/propose-fix-for-mcp-telemetry-vulnerability
Jun 10, 2026
Merged

fix(analytics): redact MCP client telemetry buckets#505
JSONbored merged 1 commit into
mainfrom
codex/propose-fix-for-mcp-telemetry-vulnerability

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Motivation

  • A privacy gap allowed attacker-controlled MCP header values like x-gittensory-mcp-client-version containing build metadata (e.g. 0.3.0+alice) to be stored and returned in aggregate byClientVersion analytics without actor redaction.
  • The adoption summary grouped by the raw clientVersion, permitting per-actor identifiers to appear in supposedly aggregate-only operator analytics.

Description

  • Redact top-level product-usage clientName and clientVersion with the existing actor redaction pipeline before persisting events by applying redactProductUsageActor in recordProductUsageEvent (src/db/repositories.ts).
  • Canonicalize MCP client-version buckets for aggregation by adding aggregateMcpClientVersion which strips build metadata (+...) and returns the semver core/prerelease portion for mcpClientVersionForEvent (src/db/repositories.ts).
  • Add regression coverage to ensure top-level telemetry redaction and canonicalized version buckets do not leak actor identifiers by updating test/unit/product-usage.test.ts and extending test/unit/product-usage-mcp-adoption.test.ts.

Testing

  • Ran npx vitest run test/unit/product-usage.test.ts test/unit/product-usage-mcp-adoption.test.ts and all tests passed.
  • Ran npm run typecheck (tsc --noEmit) and the typecheck succeeded.

Codex Task

@dosubot dosubot Bot added the size:S label Jun 9, 2026
@github-actions github-actions Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jun 9, 2026
@ghost

ghost commented Jun 9, 2026

Copy link
Copy Markdown

Note

Gittensory Gate skipped

PR closed before full evaluation. No late first comment was created.

Signal Result Evidence Action
Gate result ⚠️ Skipped #505 is no longer open. No action.

Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.

@ghost ghost added the gittensory:reviewed label Jun 9, 2026
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 9, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
gittensory-ui 90a9846 Commit Preview URL

Branch Preview URL
Jun 10 2026, 07:48 AM

@JSONbored
JSONbored force-pushed the codex/propose-fix-for-mcp-telemetry-vulnerability branch from 870af70 to 90a9846 Compare June 10, 2026 07:47
@JSONbored
JSONbored merged commit 7caf3f4 into main Jun 10, 2026
10 checks passed
@JSONbored
JSONbored deleted the codex/propose-fix-for-mcp-telemetry-vulnerability branch June 10, 2026 07:49
@github-project-automation github-project-automation Bot moved this from Todo to Done in gittensory - v1 roadmap Jun 10, 2026
@JSONbored JSONbored added the gittensor:feature Gittensor-scored feature linked to a feature issue — scores a 0.25x multiplier. label Jun 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. gittensor:feature Gittensor-scored feature linked to a feature issue — scores a 0.25x multiplier.

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant