Multi-Hoster-Upload/gateway/README.md
Administrator d69e5c39bf feat(diagnostics): MCP gateway + harden redaction so no secret ever leaves the box
Adds the connect-by-code side of remote diagnostics and closes two real
secret-leak vectors that an end-to-end gateway<->agent test surfaced.

Gateway (gateway/, local stdio MCP, Claude connects once):
- 14 read-only tools (server_health hub, read_log, list_logs, list_errors,
  get_queue_state, get_history, get_config_redacted, get_system_info,
  get_rotation_state, get_app_events + connect/disconnect/list/current).
- The HOST is always supplied by the operator, never taken from the code.
- TLS fingerprint pinning is enforced in the socket 'open' handler BEFORE the
  token is sent (wss opt-in); plain ws is loopback-only.
- registry.json (holds bearer tokens) is gitignored; only an empty example ships.

Security hardening (gates every off-box payload):
- redactLogText now scrubs opaque bearer/token-family secrets that are NOT
  stored config credentials (e.g. a session token a hoster returns inside an
  error string): bare token/auth_token/refresh_token/session_token + standalone
  "Bearer <opaque>". Benign "token bucket" prose is left intact.
- get_config_redacted deep-redacts every string leaf (JSON-safe, per-leaf, so
  the cookie/sess line patterns can't gobble across a compact-JSON field) and
  drops the history subtree (served by get_history with its own per-error
  redaction). This plugs leaks via globalSettings.pendingQueue[].error etc.

Bind-address safety:
- _safeDiagBindAddress() forces the diagnostic agent to 127.0.0.1/::1; the
  0.0.0.0 UI option is removed. Direct LAN/Internet bind stays disabled until
  encrypted transport (wss) exists — remote access goes through an SSH/VPN
  tunnel to loopback. (Never plaintext ws:// on all interfaces.)

Tests: end-to-end gateway<->agent gate (connect -> server_health/read_log/
get_config_redacted, asserts zero secret leakage, rejects doodstream log, path
traversal and write ops); + redaction regression tests in the main suite.
385 app tests + 9 gateway tests pass; lint 0 errors.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-19 17:39:31 +02:00

1.9 KiB

mhu-diagnostics-gateway

A standalone local stdio MCP gateway for remote, read-only diagnostics of the Multi-Hoster-Uploader app.

It is two things at once:

  • an MCP server to Claude Code (stdio transport), exposing read-only diagnostic tools, and
  • a plain WebSocket client to a diagnostic agent running inside the Electron app on a remote Windows server.

The operator enables "Diagnose-Zugriff" on a server, copies the connection code, and tells Claude server <name> at <host>, code <CODE>. Claude calls connect_server(code, host) and then the read-only diagnostic tools. After the first successful connect the server is remembered under its label, so later you can just say connect_server(label:"prod-3") with no code.

This package is fully self-contained. It does not import anything from the parent Electron app and is not part of the app build.

Install

cd gateway
npm install

Requires Node >= 18.

Register with Claude Code (one time)

claude mcp add --transport stdio mhu-diag -- node "C:\Users\ploet\Desktop\Claude Projekte\multi-hoster-uploader\gateway\index.js"

Adjust the absolute path if you cloned the repo elsewhere.

Usage

In Claude Code, tell Claude:

server prod-3 at 127.0.0.1, code mhu1_<...>

Claude will call connect_server and then diagnostic tools such as server_health (the one-shot "what's wrong" hub), read_log, list_errors, get_queue_state, get_rotation_state, and so on.

Security

  • Read-only. No screen access, no input injection, no writes. Only reads logs, errors, queue/history/config (redacted), rotation and system info.
  • The code is a secret — it carries the auth token. Do not paste it anywhere public.
  • The safe default is to reach the agent over 127.0.0.1 via an SSH local port-forward or WireGuard. See docs/remote-diagnostics-setup.md.
  • registry.json stores tokens and is git-ignored — never commit it.