Skip to content

hardening(docs): MCP key pepper quality check and build guard - #22

Merged
SaulBuilds merged 1 commit into
mainfrom
fix/pba-r2-docs-mcp-pepper
Sep 25, 2026
Merged

SaulBuilds merged 1 commit into
mainfrom
fix/pba-r2-docs-mcp-pepper

Conversation

@SaulBuilds

Copy link
Copy Markdown
Contributor

Summary

Small hardening follow-up to #20: MCP key pepper handling.

  • Pepper check. MCP_KEY_PEPPER must be at least 32 chars after trimming, have at least 8 distinct characters, and carry no surrounding whitespace. A whitespace-only or low-variety pepper is refused.
  • Diagnosability. When MCP_API_KEYS is configured without a usable pepper, the server logs one line and check:mcp-keys (postbuild) fails the build.
  • Script fix. The weak-pepper assertions in check-mcp-keys.mjs now store the key under the weak pepper, so only the pepper rule can refuse it.
  • Docs. .env.example and README state the pepper requirements, and that keys are minted only with scripts/mint-mcp-key.mjs.

Tests: test/mcp-key-floor.test.ts covers pepper status, the whitespace pepper and the one-time warning, plus check:mcp-keys. Hand mutants (floor 32 → 1, whitespace, distinct-count, warning removed) are each killed. Details are in the private audit record.

OWNER: MCP_KEY_PEPPER must meet the rule above. A build with MCP_API_KEYS set and an unusable pepper now fails.

Tests and commands: main: 98 passed / 4 skipped. This PR: 101 / 4. The run used node 22.21.1 and npm 10.9.4: npm ci, audit --audit-level=high, typecheck, test, build, verify:bundle, content-lint --strict, sbom. All green.

🤖 Generated with Claude Code

https://claude.ai/code/session_012cD3fDq5vhh2YWZPU2SV6H

…rning

- mcpPepperStatus: the pepper must be at least 32 chars after trimming, have
  at least 8 distinct characters and no surrounding whitespace. A
  whitespace-only or low-variety pepper is refused.
- The resolver logs once when MCP_API_KEYS is configured without a usable
  pepper (keys fail closed to public).
- check:mcp-keys fails the build in the same case.
- The weak-pepper assertions in check-mcp-keys.mjs now store the key under the
  weak pepper, so only the pepper rule can refuse it.
- Docs: the pepper requirements, and that keys are minted only with the script.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012cD3fDq5vhh2YWZPU2SV6H
@SaulBuilds
SaulBuilds merged commit 4a49441 into main Sep 25, 2026
9 checks passed
@SaulBuilds
SaulBuilds deleted the fix/pba-r2-docs-mcp-pepper branch September 25, 2026 16:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants