Skip to content

[log] Add debug logging to proxy upstream forwarding - #14309

Merged
lpcox merged 3 commits into
mainfrom
log/proxy-forward-logging-04c6db932471582b
Oct 4, 2026
Merged

lpcox merged 3 commits into
mainfrom
log/proxy-forward-logging-04c6db932471582b

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Adds 5 debug log calls to internal/proxy/proxy.go, reusing the existing logProxy logger:

  • upstreamHost: scheme-less parse retry and raw host fallback
  • forwardToGitHub: GraphQL URL rewrite (GHES or not), request creation failure, artifact zip no-redirect path

The log arguments have no side effects. They don't log paths, URLs or credentials, so enclave and delegation modes stay safe.

Validation: go vet and go test ./internal/proxy pass, and go build succeeds.

Generated by Go Logger Enhancement · copilot · auto · 62.4 AIC · ⊞ 12.8K · ◷

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot added automation enhancement New feature or request labels Oct 2, 2026
@lpcox
lpcox marked this pull request as ready for review October 3, 2026 15:23
Copilot AI balanced review requested due to automatic review settings October 3, 2026 15:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two new diagnostics can expose sensitive URL data when parsing fails.

Review effort: Balanced
Findings: 2 High severity

Open (2)

Comment thread internal/proxy/proxy.go Outdated
Comment thread internal/proxy/proxy.go Outdated
lpcox and others added 2 commits October 3, 2026 09:51
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

🔒 mcpg Read-Only Stress — default

Surface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Isolation runtime: default (normal container isolation)

Part Surface Op Result Expected Status
A MCP reads data ALLOWED ✅
B MCP writes (reaction/star/issue/comment/branch/file/PR) all 6 tools absent from catalog BLOCKED ⚠️
C CLI reads data ALLOWED ✅
D CLI REST writes (reaction/star/issue/comment) not attempted — gh unauthenticated BLOCKED ⚠️
E CLI GraphQL mutations (addReaction/addStar/createIssue) not attempted — gh unauthenticated BLOCKED ⚠️

Overall: INCONCLUSIVE
(⚠️ = Part B's 6 targeted write tools were absent from the exposed 23-tool catalog — a refusal there reflects gh-aw's backend GITHUB_READ_ONLY=1 config, not independent proof of mcpg's own gateway-level enforcement. Part D/E could not run because gh auth status reported "not logged into any GitHub hosts" in this environment, so no REST/GraphQL write attempts were made. No write succeeded or leaked on any surface.)

🔒 mcpg read-only stress (default AWF runtime) by Read-Only Stress: default runtime

@lpcox
lpcox merged commit 997ca69 into main Oct 4, 2026
31 checks passed
@lpcox
lpcox deleted the log/proxy-forward-logging-04c6db932471582b branch October 4, 2026 03:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants