{"record":{"id":"77c5f2e62b87f0c9","repo":"koala73/worldmonitor","slug":"serverurl-dns-resolution-returned-no-addresses","errorCode":null,"errorMessage":"serverUrl DNS resolution returned no addresses","messagePattern":"serverUrl DNS resolution returned no addresses","errorType":"exception","errorClass":"McpProxySsrfError","httpStatus":422,"severity":"error","filePath":"api/mcp-proxy.ts","lineNumber":174,"sourceCode":"function emitProxyUsage(req, status: number, durationMs: number, ctx, callerIdentity = null): void {\n  if (!ctx) return;\n  try {\n    const usageIdentity = proxyUsageIdentityFor(req, callerIdentity);\n    emitUsageEvents(ctx, [buildRequestEvent({\n      requestId: deriveRequestId(req),\n      domain: 'mcp',\n      route: '/api/mcp-proxy',\n      method: req.method,\n      status,\n      // Measured from handler entry, so this INCLUDES the auth/rate-limit\n      // gates — unlike logProxyCall's `started`, which begins after auth.\n      // The usage row is the end-to-end caller-visible latency.\n      durationMs,\n      reqBytes: deriveReqBytes(req),\n      // Not tracked: the proxy streams upstream bodies through bounded readers\n      // and jsonResponse sets no content-length, so there is no byte count to\n      // report without buffering a second time. Size questions belong to\n      // MAX_MCP_PROXY_RESPONSE_BYTES, not to this row.\n      resBytes: 0,\n      customerId: usageIdentity.customer_id,\n      principalId: usageIdentity.principal_id,\n      authKind: usageIdentity.auth_kind,\n      tier: usageIdentity.tier,\n      planKey: usageIdentity.plan_key,\n      country: deriveCountry(req),\n      ipCity: deriveIpCity(req),\n      ipRegion: deriveIpRegion(req),\n      executionRegion: deriveExecutionRegion(req),\n      executionPlane: 'vercel-edge',\n      originKind: 'mcp',\n      cacheTier: 'no-store',\n      ip: deriveIp(req),\n      userAgent: deriveUserAgent(req),\n      uaHash: null,\n      referer: deriveReferer(req),\n      acceptLanguage: deriveAcceptLanguage(req),","sourceCodeStart":156,"sourceCodeEnd":192,"githubUrl":"https://github.com/koala73/worldmonitor/blob/7d06c8633d256c18e38133030bc3613976a96ec9/api/mcp-proxy.ts#L156-L192","documentation":"Thrown by assertServerUrlSafe in the MCP proxy when the serverUrl hostname resolves via DNS but the resolver returns an empty address list. This is an SSRF-guard precondition: the proxy refuses to fetch a target whose DNS name has no usable addresses, so it fires for misconfigured/placeholder hostnames or transient resolver empty answers, before any request is sent.","triggerScenarios":"Thrown at api/mcp-proxy.ts:172 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Verify the serverUrl hostname is correct and publicly resolvable before configuring the MCP client","Test the hostname with an external DNS query (e.g. dig/nslookup) to confirm it returns addresses","If the failure is intermittent, retry or restart the MCP proxy operation after DNS propagation"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"7d06c8633d256c18e38133030bc3613976a96ec9","analyzedAt":"2026-08-21T16:51:25.751Z","contentChangedAt":"2026-08-21T16:51:25.751Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}