Skip to content

Harden Trustify MCP HTTP and authentication handling - #77

Open
rh-jfuller wants to merge 5 commits into
mainfrom
more-fixes
Open

rh-jfuller wants to merge 5 commits into
mainfrom
more-fixes

Conversation

@rh-jfuller

@rh-jfuller rh-jfuller commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor
  • Replace blocking HTTP calls with async reqwest requests.
  • Add request/connect timeouts and request/response size limits.
  • Bound pagination and multi-PURL input sizes.
  • Safely encode URL path segments and query parameters.
  • Expose all package-list parameters in the MCP schema.
  • Allow AUTH_DISABLED=true without OIDC configuration.
  • Add regression coverage for concurrency, limits, URL encoding, schema behavior, and disabled authentication.

Summary by Sourcery

Harden Trustify MCP HTTP and authentication handling with asynchronous, bounded, safely encoded requests and more robust configuration behavior.

Bug Fixes:

  • Allow authentication to be disabled without requiring OIDC configuration.
  • Prevent oversized pagination, PURL inputs, request bodies, and responses from being processed.

Enhancements:

  • Use asynchronous HTTP requests with connection and request timeouts.
  • Safely construct and encode Trustify API URLs and query parameters.
  • Expose all package-list request parameters in the MCP tool schema.

Build:

  • Remove reqwest blocking support and enable Tokio time support.

Tests:

  • Add regression coverage for asynchronous concurrency, request and response limits, URL encoding, MCP schema behavior, and disabled authentication.
Add HTTP timeouts, request and response size limits, bounded pagination,
and maximum PURL counts. Add regression tests for oversized inputs and
responses.
Use reqwest URL builders for encoded path segments and query parameters,
and remove the requirement for callers to pre-encode PURLs. Add reserved
character URL coverage.
Combine SBOM URI, query, and limit into one package-list request object
so all parameters are visible and usable by MCP clients.
Check AUTH_DISABLED before loading OIDC variables and add regression tests
for disabled-mode initialization and boolean parsing.
@sourcery-ai

sourcery-ai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

The PR hardens Trustify MCP networking by replacing blocking calls with bounded async reqwest operations, safely constructing URLs and payloads, enforcing pagination and PURL limits, correcting package-list schema exposure, and permitting explicitly disabled authentication without OIDC settings, with targeted regression coverage.

Sequence diagram for hardened Trustify API calls

sequenceDiagram
    participant Tool as MCP tool
    participant Client as Async reqwest client
    participant API as Trustify API

    Tool->>Tool: validate_limit()
    Tool->>Tool: validate_purls()
    Tool->>Tool: build_api_url()
    Tool->>Client: send()
    Client->>API: HTTP request with timeout
    API-->>Client: HTTP response
    Client-->>Tool: response body
    Tool->>Tool: read_response_body()
    Tool->>Tool: deserialize_response()
    Tool-->>Tool: Return MCP result
Loading

Sequence diagram for disabled authentication startup

sequenceDiagram
    participant Startup as Router startup
    participant Env as Environment
    participant OIDC as OIDC configuration
    participant Router as Protected router

    Startup->>Env: Read AUTH_DISABLED
    alt AUTH_DISABLED is true
        Startup->>Router: Return router without authentication
    else Authentication enabled
        Startup->>Env: Read OPENID_ISSUER_URL and OPENID_CLIENT_ID
        Startup->>OIDC: Configure authenticator
        OIDC-->>Router: Authentication middleware
    end
Loading

File-Level Changes

Change Details Files
Migrated Trustify API access and integration readiness checks to nonblocking asynchronous HTTP.
  • Removed reqwest blocking support and used async request execution throughout.
  • Updated integration polling to await async requests and timers.
  • Added a concurrency regression test for runtime nonblocking behavior.
Cargo.toml
src/bin/common/trustify.rs
tests/integration_test.rs
Added bounded HTTP request and response handling.
  • Configured 5-second connect and 30-second request timeouts.
  • Limited serialized request bodies and streamed response bodies to fixed byte caps.
  • Rejected oversized pagination and multi-PURL inputs with MCP invalid-parameter errors.
src/bin/common/trustify.rs
Centralized safe Trustify URL construction and parameter encoding.
  • Built URLs from parsed base URLs and encoded path segments with reqwest::Url.
  • Encoded query values via query-pair APIs instead of string interpolation.
  • Preserved base paths while clearing inherited query and fragment components.
src/bin/common/trustify.rs
Corrected MCP package-list schema and request mapping.
  • Exposed the SBOM URI alongside query and limit fields in the package-list parameter schema.
  • Updated the tool to consume all package-list parameters from one request object.
  • Removed the requirement for callers to pre-URL-encode PURLs.
src/bin/common/trustify.rs
src/bin/common/trustify_requests.rs
tests/integration_test.rs
Allowed authentication to be explicitly disabled without OIDC configuration.
  • Short-circuited router protection when AUTH_DISABLED is case-insensitively true.
  • Changed authentication parsing to accept only an explicit true value.
  • Added regression coverage for disabled-auth startup and parsing behavior.
src/auth.rs
Added regression coverage for the new HTTP safety and schema behavior.
  • Tested URL encoding, input limits, response limits, async concurrency, and generated MCP tool schemas.
src/bin/common/trustify.rs
src/auth.rs
tests/integration_test.rs

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@rh-jfuller rh-jfuller self-assigned this Sep 9, 2026
@rh-jfuller
rh-jfuller requested a review from mrizzi September 9, 2026 10:13

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="tests/integration_test.rs" line_range="89-110" />
<code_context>
       "name": "trustify_sbom_details",
       "description": "Get the details of a SBOM from a trustify instance by SBOM URI",
-      "inputSchema": {
-        "type": "object",
-        "properties": {
-          "sbom_uri": {
-            "description": "Sbom URI",
-            "type": "string"
-          }
-        },
-        "required": [
-          "sbom_uri"
-        ],
+        "inputSchema": {
+          "type": "object",
</code_context>
<issue_to_address>
**issue (testing):** The expected MCP schema adds `query` and `limit` to `trustify_sbom_details`, but the implementation still exposes `SbomUriRequest` for that tool and only accepts `sbom_uri`. The schema regression test therefore fails because the expected schema is attached to the wrong tool; those fields belong to `trustify_sbom_list_packages`.

**Triggers:** When the integration tool-list tests run.

**Suggested fix:** Keep `trustify_sbom_details`'s expected schema limited to `sbom_uri` and add `query` and `limit` to the expected `trustify_sbom_list_packages` schema.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and when AUTH_DISABLED is true, this change bypasses the authentication middleware entirely and allows every request through without OIDC configuration. If that policy is wrong, the resulting unauthorized access or data exposure occurs immediately and cannot be fully undone by reverting.

Blocking findings: tests/integration_test.rs:110


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Comment thread tests/integration_test.rs
Comment on lines +89 to +110
"type": "object",
"properties": {
"sbom_uri": {
"description": "Sbom URI",
"type": "string"
},
"query": {
"description": "Search query for packages within the SBOM",
"type": "string"
},
"limit": {
"description": "Maximum number of packages to return",
"type": "integer",
"format": "uint",
"minimum": 0
}
},
"required": [
"sbom_uri",
"query",
"limit"
],

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue (testing): The expected MCP schema adds query and limit to trustify_sbom_details, but the implementation still exposes SbomUriRequest for that tool and only accepts sbom_uri. The schema regression test therefore fails because the expected schema is attached to the wrong tool; those fields belong to trustify_sbom_list_packages.

Triggers: When the integration tool-list tests run.

Suggested fix: Keep trustify_sbom_details's expected schema limited to sbom_uri and add query and limit to the expected trustify_sbom_list_packages schema.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant