Repository navigation
fix: readable onepassword:// resources and security hardening (v5.0.0) - #33
Merged
Merged
Conversation
…0.4) Security release from an internal review. - item_get: deny-by-default field masking. SSH private keys, TOTP seeds, and card numbers were returned in plaintext without reveal. - Vault allow-list (OP_MCP_ALLOWED_VAULTS) is now enforced by every tool and resource, and op:// references are also checked by the vault they resolve to, not only as written (new src/vault-access.ts). - op_run redaction (new src/redaction.ts): single-pass masking over the original output, so overlapping secrets no longer leak each other's remainder; also masks base64 (any alignment), JSON/URL-escaped, and multi-line/CRLF forms. - op_run: output cap enforced while the command runs (memory-exhaustion DoS), timeouts kill the whole process tree and always return, the credential env scrub is case-insensitive, and the tool description no longer overclaims. - CI: remove the leftover issue_comment-triggered mcp-v2-migration.yml (contents: write, triggerable by any GitHub user). publish.yml passes the release tag via env, does not persist credentials, and splits build/test/pack (npm ci --ignore-scripts, no OIDC) from a publish-only job that alone holds id-token: write. - macOS Keychain lookup runs /usr/bin/security; startup warning when the token is passed on the command line. - Docs and CHANGELOG updated; version bumped to 4.0.4. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…0.0)
Every resources/read failed with -32602 "Resource URI ... is invalid":
the SDK parses the URI with new URL() before dispatching, and a scheme
cannot start with a digit (RFC 3986 3.1), so no 1password:// URI ever
reached a handler.
- Resource URIs now use the onepassword:// scheme. Breaking for anything
that hard-coded the old URIs, hence 5.0.0.
- onepassword://vaults/{vaultId}/items is a ResourceTemplate and reads
vaultId from the percent-decoded template variables. It was a static
resource whose URI was the literal template string, so no concrete
vault URI could match it.
- buildServer() moved to src/server.ts (re-exported from index.ts) so
tests can build the real server without starting stdio.
- tests/resources.e2e.test.ts: a real MCP client reads every advertised
resource from serveStdio(() => buildServer()) over an in-memory
transport, in both the 2025 and 2026-07-28 protocol eras. Adds the
@modelcontextprotocol/client dev dependency.
- README, agents.md, CONTRIBUTING, and CHANGELOG updated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Combine origin/claude/security-vulnerabilities-review-5d20ad (d9905bd) with the onepassword:// resources fix. Conflict resolution: - package.json, package-lock.json, server.json, SERVER_VERSION: 5.0.0. - CHANGELOG.md: keep both entries, 5.0.0 above 4.0.4. - README.md: onepassword:// URIs with #32's allow-list note on the vaults row, and a changelog pointer that names both releases. The allow-list section's `1password://vaults` line merged without a conflict; it now reads onepassword://vaults and also names the items template. Semantic conflict: - tests/vault-allowlist.test.ts called the resource callbacks with the old signatures (no URI, or a 1password:// string with no template variables). They now pass a URL and, for vault-items, { vaultId }. src/resources/index.ts merged cleanly: filterAllowedVaults() filters onepassword://vaults, and assertVaultIdAllowed() runs on the decoded vaultId from the template variables, the same value items.list() gets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Read onepassword://vaults and the items template through the real MCP client with OP_MCP_ALLOWED_VAULTS set, in both protocol eras. The vault listing is filtered, items of a vault outside the list are refused before items.list() runs, and the check sees the percent-decoded vaultId, so an encoded ID can't slip past it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The security hardening from #32 ships in the same release as the resource URI change, so 4.0.4 is never published. Move its Security and Changed notes into the 5.0.0 entry, name the items template in the allow-list note, and point the README and agents.md at 5.0.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
One release, 5.0.0, combining two pieces of work. Supersedes #32, which can be closed once this merges. 4.0.4 is never published; its notes are folded into the 5.0.0 CHANGELOG entry.
1. Resources fix (breaking URI change). The three MCP resources couldn't be read by real clients:
resources/readURI withnew URL(), and1password://isn't a valid scheme, because a scheme can't start with a digit. Every read failed with-32602 Resource URI … is invalid.…/vaults/{vaultId}/itemswas registered as a static URI, so no concrete vault URI could match it.Now the URIs use
onepassword://. I ruled outop://because it collides with 1Password secret references. The per-vault items resource is aResourceTemplate, andvaultIdcomes from the template variables, percent-decoded.2. Security hardening from #32, merged in unchanged as
d9905bd:item_getmasking.src/vault-access.ts).op_runfixes for redaction, the output cap, and timeouts.Breaking and behavior changes
1password://…toonepassword://…. The old ones never resolved.OP_MCP_ALLOWED_VAULTS) now applies to every tool and resource. Tools that take avaultIdneed the vault's ID, not its name.item_gethides SSH keys, OTP seeds, and card numbers unless you passreveal: true.How the two fit together
src/resources/index.tsmerged cleanly.filterAllowedVaults()filtersonepassword://vaults, andassertVaultIdAllowed()runs on the decodedvaultId, the same valueitems.list()gets.tests/vault-allowlist.test.tscalled the callbacks with the old signatures. The merge commit updates them.buildServer()moved tosrc/server.ts(still re-exported fromsrc/index.ts), so tests can build the real server without starting stdio.Testing
tests/resources.e2e.test.ts: a real@modelcontextprotocol/client(new dev dependency, same version as the server package) reads every advertised resource fromserveStdio(() => buildServer())overInMemoryTransport, in both the 2025 and 2026-07-28 protocol eras. It also covers the allow-list, including a check that percent-encoding can't bypass it. Run against master's code, it fails with exactly the reported error.vaultIdinstead of the decoded one, makes the new tests fail.npm run clean && npm ci && npm run build && npm run lint && npm test): 414 passed, 1 skipped (a POSIX-onlyop_runtest, skipped on Windows).npm ci --ignore-scripts && npm run build && npm test): passes. Versions are aligned at 5.0.0 inpackage.json,package-lock.json,server.json, andSERVER_VERSION.Commits
4cb988bfix(resources):onepassword://URIs andResourceTemplate(v5.0.0)d9905bdsecurity hardening from fix(security): harden item_get, vault allow-list, op_run, and CI (v4.0.4) #32 (unchanged)0a8ae15merge, with the conflict resolutions and test updatesae34267end-to-end allow-list tests4edf37fCHANGELOG: fold 4.0.4 into 5.0.0🤖 Generated with Claude Code