Commit a06dcb9
committed
fix: harden input handling in api client, mcp config, and yaml escape
- use null check instead of truthy for limit param (fixes limit=0 bug)
- encode url path segments to prevent path injection
- fix mcp config read/write key mismatch when both servers and mcpServers exist
- escape backslashes and newlines in yaml frontmatter
Constraint: all fixes are at API/output boundaries, no internal logic changes
Confidence: high
Scope-risk: narrow1 parent 1ca761d commit a06dcb9
File tree
3 files changed
+6
-7
lines changed- src
- api
- commands/init
3 files changed
+6
-7
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
149 | 149 | | |
150 | 150 | | |
151 | 151 | | |
152 | | - | |
| 152 | + | |
153 | 153 | | |
154 | 154 | | |
155 | 155 | | |
156 | 156 | | |
157 | | - | |
| 157 | + | |
158 | 158 | | |
159 | 159 | | |
160 | 160 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
| 59 | + | |
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| |||
80 | 80 | | |
81 | 81 | | |
82 | 82 | | |
83 | | - | |
| 83 | + | |
| 84 | + | |
84 | 85 | | |
85 | 86 | | |
86 | | - | |
87 | | - | |
88 | 87 | | |
89 | 88 | | |
90 | 89 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
150 | 150 | | |
151 | 151 | | |
152 | 152 | | |
153 | | - | |
| 153 | + | |
154 | 154 | | |
0 commit comments