Problem

McpRateLimiter builds event names by concatenating a prefix, policy profile ID, user ID and optional Tool API plugin ID. Drupal's database flood backend stores event names in a varchar(64) column. Valid profile/tool identifiers can exceed that limit, causing an authorized tool call to fail during rate-limit registration on PostgreSQL.

Reproduction

On MCP Sentinel 2.21.1 with Drupal 11.4.7 and PostgreSQL, use an enabled profile named config_auditor with a finite request budget. Call the rate limiter's register method with synthetic UID 4242 and tool ID graphql_compose_codegen_inspect. The resulting event name mcp_sentinel.profile.config_auditor.4242.graphql_compose_codegen_inspect is 72 bytes. Registration throws a database exception reporting a value too long for character varying(64). The same issue can affect page-budget keys with long profile IDs. SQLite-only tests can miss the column-length failure.

Proposed resolution

Use deterministic, bounded keys for both request and page budgets. Preserve separation between profiles, principals and tools, and preserve existing valid keys and active counters during an upgrade. Do not truncate identifiers in a way that merges unrelated budgets. Keep the same key derivation in checks and registration.

Acceptance

Regression tests cover long profile IDs, long tool IDs, large user IDs, request and page budgets, key separation, existing short keys, and upgrade handling of active counters. Verify actual database-backed registration and refusal once the configured budget is exhausted. Include a PostgreSQL regression in addition to supported-core tests.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Status: Active » Fixed

Fixed in MCP Sentinel 2.22.0. Long request and page event names use bounded deterministic keys; existing valid names are unchanged. Database update 10023 preserves identifiers, timestamps and expiration while migrating legacy counters in batches. PostgreSQL regression tests verify database-backed registration, budget refusal, key separation and idempotent migration. Supported-core CI is green.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.