Skip to content

Commit 2a6b2bc

Browse files
fix: hide input values from tool validation error messages
Tool validation errors previously echoed the rejected input value via pydantic's default str(ValidationError) format, leaking PII/PHI in servers that handle sensitive data. Set hide_input_in_errors=True on ArgModelBase.model_config so the generated arg model never includes input_value in its error messages. The error still describes the rule (type, constraint) but not the data. Fixes #3572
1 parent f1b6589 commit 2a6b2bc

2 files changed

Lines changed: 20 additions & 1 deletion

File tree

‎src/mcp/server/mcpserver/utilities/func_metadata.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ def model_dump_one_level(self) -> dict[str, Any]:
109109
kwargs[output_name] = value
110110
return kwargs
111111

112-
model_config = ConfigDict(arbitrary_types_allowed=True)
112+
model_config = ConfigDict(arbitrary_types_allowed=True, hide_input_in_errors=True)
113113

114114

115115
class FuncMetadata(BaseModel):

‎tests/server/mcpserver/test_func_metadata.py‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1520,3 +1520,22 @@ def fn() -> StepA | StepB: ... # pragma: no branch
15201520

15211521
meta = func_metadata(fn)
15221522
assert meta.output_schema is None
1523+
1524+
1525+
def test_validation_error_does_not_echo_input_value():
1526+
"""Tool validation errors must not leak the rejected input value (PII/PHI risk).
1527+
1528+
Regression test for: https://github.com/modelcontextprotocol/python-sdk/issues/3572
1529+
"""
1530+
1531+
def fn(name: str, age: int) -> str: ... # pragma: no branch
1532+
1533+
meta = func_metadata(fn)
1534+
with pytest.raises(Exception) as exc_info:
1535+
meta.arg_model.model_validate({"name": "Alice", "age": "not-a-number"})
1536+
1537+
error_text = str(exc_info.value)
1538+
assert "not-a-number" not in error_text, "Rejected input value must not appear in validation error message"
1539+
assert "int_parsing" in error_text or "int" in error_text.lower(), (
1540+
"Error should still describe the rule (type mismatch)"
1541+
)

0 commit comments

Comments
 (0)