Skip to content

Add MCP negative control for secret:false #1402

Description

@Dumbris

Follow-up: add an MCP negative control for secret:false

Origin: glm:initialMCP.F2 from the PR1397 MCP review.

The MCP regression tests currently prove that a secret-shaped name such as Authorization becomes secret:true even when the registry declares secret:false, but they do not prove the inverse response behavior. Add a plainly named non-secret input such as PORT with secret:false to the explicit-registry and/or omitted-registry fixture and assert that the MCP response does not contain secret:true for that input.

Existing lower-level controls are present in internal/secretlike/secretlike_test.go (PORT, WORKDIR, PATH, and REGION are negative cases), and internal/registries/catalog_test.go exercises PORT only with an explicit Secret:true. Neither is an end-to-end MCP response negative control, so this follow-up would protect against a regression that forces every MCP input to secret-like.

Do not treat this as a PR1397 production defect; it is test strengthening for a future change.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugSomething isn't workingpriority/lowNice to have; address when bandwidth allowstriage/acceptedTriaged and accepted for the backlog

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions