Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
|
@heymb thanks a lot for this! Would you please be able to accept the CLA so I can merge it? |
|
@Raibaz You're welcome! Unfortunately, I didn't consider the CLA. I need to ask internally about it. Will keep you posted. Thanks |
|
I think this was superseded by #108. |
|
@Raibaz Sounds good! If that's the case, feel free to close this. P.S. FastMCP has a draft PR that would solve this upstream: PrefectHQ/fastmcp#5185 |
|
FYI the fastmcp PR above was merged! Once they release it, the dep here can be bumped to avoid this kind of bug altogether without any configuration here. |
Security Bug
Root Cause
httpxlogger toWARNINGso the access token in fastmcp's tokeninfo request URL would not be logged.httpx2, so the logger name stopped matching and every authenticated request logged the user's Google access token again, e.g.INFO:httpx2:HTTP Request: GET https://oauth2.googleapis.com/tokeninfo?access_token=<token> "HTTP/1.1 200 OK"Fix
httpx2to fix the bugPossible Improvements
uv.locksince upgrading fastmcp switchedhttpxtohttpx2, but it wasn't clear that the original logging fix was broken