{"record":{"id":"d5dd50f418898a25","repo":"koala73/worldmonitor","slug":"serverurl-dns-resolution-failed-message","errorCode":null,"errorMessage":"serverUrl DNS resolution failed: ${message}","messagePattern":"serverUrl DNS resolution failed: (.+?)","errorType":"exception","errorClass":"McpProxySsrfError","httpStatus":422,"severity":"error","filePath":"api/mcp-proxy.ts","lineNumber":170,"sourceCode":" * OPTIONS preflights are deliberately NOT emitted — a static 204 that cannot\n * fail would double row volume for no diagnostic value. /mcp skips them too\n * (McpUsage.skip).\n */\nfunction emitProxyUsage(req, status: number, durationMs: number, ctx, callerIdentity = null): void {\n  if (!ctx) return;\n  try {\n    const usageIdentity = proxyUsageIdentityFor(req, callerIdentity);\n    emitUsageEvents(ctx, [buildRequestEvent({\n      requestId: deriveRequestId(req),\n      domain: 'mcp',\n      route: '/api/mcp-proxy',\n      method: req.method,\n      status,\n      // Measured from handler entry, so this INCLUDES the auth/rate-limit\n      // gates — unlike logProxyCall's `started`, which begins after auth.\n      // The usage row is the end-to-end caller-visible latency.\n      durationMs,\n      reqBytes: deriveReqBytes(req),\n      // Not tracked: the proxy streams upstream bodies through bounded readers\n      // and jsonResponse sets no content-length, so there is no byte count to\n      // report without buffering a second time. Size questions belong to\n      // MAX_MCP_PROXY_RESPONSE_BYTES, not to this row.\n      resBytes: 0,\n      customerId: usageIdentity.customer_id,\n      principalId: usageIdentity.principal_id,\n      authKind: usageIdentity.auth_kind,\n      tier: usageIdentity.tier,\n      planKey: usageIdentity.plan_key,\n      country: deriveCountry(req),\n      ipCity: deriveIpCity(req),\n      ipRegion: deriveIpRegion(req),\n      executionRegion: deriveExecutionRegion(req),\n      executionPlane: 'vercel-edge',\n      originKind: 'mcp',\n      cacheTier: 'no-store',\n      ip: deriveIp(req),","sourceCodeStart":152,"sourceCodeEnd":188,"githubUrl":"https://github.com/koala73/worldmonitor/blob/7d06c8633d256c18e38133030bc3613976a96ec9/api/mcp-proxy.ts#L152-L188","documentation":"SSRF guard error in the MCP proxy's assertServerUrlSafe: resolving the hostname's A/AAAA records via DoH threw (network, timeout, or DNS status failure), so safety could not be established. The underlying error message is embedded; the request is refused rather than allowed through unverified.","triggerScenarios":"Thrown at api/mcp-proxy.ts:168 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Retry — transient DoH failures resolve on retry","Verify the hostname resolves publicly (dig/nslookup from another host)","If the DoH endpoint is unreachable from the edge runtime, fix egress or the DNS_JSON_ENDPOINT configuration"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"7d06c8633d256c18e38133030bc3613976a96ec9","analyzedAt":"2026-08-21T16:51:25.751Z","contentChangedAt":"2026-08-21T16:51:25.751Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}