Repository navigation
Commit 2a6b2bc
committed
fix: hide input values from tool validation error messages
Tool validation errors previously echoed the rejected input value via
pydantic's default str(ValidationError) format, leaking PII/PHI in
servers that handle sensitive data.
Set hide_input_in_errors=True on ArgModelBase.model_config so the
generated arg model never includes input_value in its error messages.
The error still describes the rule (type, constraint) but not the data.
Fixes #35721 parent f1b6589 commit 2a6b2bc
2 files changed
Lines changed: 20 additions & 1 deletion
File tree
- src/mcp/server/mcpserver/utilities
- tests/server/mcpserver
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
109 | 109 | | |
110 | 110 | | |
111 | 111 | | |
112 | | - | |
| 112 | + | |
113 | 113 | | |
114 | 114 | | |
115 | 115 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1520 | 1520 | | |
1521 | 1521 | | |
1522 | 1522 | | |
| 1523 | + | |
| 1524 | + | |
| 1525 | + | |
| 1526 | + | |
| 1527 | + | |
| 1528 | + | |
| 1529 | + | |
| 1530 | + | |
| 1531 | + | |
| 1532 | + | |
| 1533 | + | |
| 1534 | + | |
| 1535 | + | |
| 1536 | + | |
| 1537 | + | |
| 1538 | + | |
| 1539 | + | |
| 1540 | + | |
| 1541 | + | |
0 commit comments