{"record":{"id":"d7dd4c93591beddc","repo":"koala73/worldmonitor","slug":"no-result-found-in-sse-response","errorCode":null,"errorMessage":"No result found in SSE response","messagePattern":"No result found in SSE response","errorType":"exception","errorClass":null,"httpStatus":422,"severity":"error","filePath":"api/mcp-proxy.ts","lineNumber":294,"sourceCode":"// Generic message surfaced to the caller when a serverUrl resolves to a\n// private/reserved address. The specific blocked IP is deliberately NOT echoed\n// back: returning it turns the proxy into an address oracle (the caller could\n// enumerate internal IPs by observing which hostnames get blocked). SSRF review\n// finding — log the concrete IP server-side for debugging, tell the caller only\n// that the host is disallowed.\nconst SSRF_BLOCKED_PUBLIC_MESSAGE = 'serverUrl host is not allowed';\n\nfunction throwBlockedAddress(blockedAddress) {\n  // Server-side audit/debug log with the concrete blocked address. This is the\n  // only place the resolved internal IP appears; it never reaches the response.\n  console.error('[mcp-proxy]', {\n    event: 'mcp_proxy_ssrf_blocked',\n    ts: new Date().toISOString(),\n    blocked_address: blockedAddress,\n  });\n  throw new McpProxySsrfError(SSRF_BLOCKED_PUBLIC_MESSAGE);\n}\n\nasync function resolveDnsJson(hostname, recordType, signal) {\n  const url = new URL(DNS_JSON_ENDPOINT);\n  url.searchParams.set('name', hostname);\n  url.searchParams.set('type', recordType);\n  const dnsTimeout = AbortSignal.timeout(DNS_RESOLUTION_TIMEOUT_MS);\n  const response = await fetch(url.toString(), {\n    headers: {\n      Accept: 'application/dns-json',\n      'User-Agent': 'WorldMonitor-MCP-Proxy/1.0',\n    },\n    signal: signal ? AbortSignal.any([signal, dnsTimeout]) : dnsTimeout,\n  });\n  if (!response.ok) {\n    throw new Error(`DNS ${recordType} lookup failed: HTTP ${response.status}`);\n  }\n  const data = await response.json();\n  if (data?.Status !== 0) {\n    throw new Error(`DNS ${recordType} lookup failed: status ${data?.Status}`);","sourceCodeStart":276,"sourceCodeEnd":312,"githubUrl":"https://github.com/koala73/worldmonitor/blob/e586b8b4b80f595aa7ece295eec10d76f2921240/api/mcp-proxy.ts#L276-L312","documentation":"Thrown by parseJsonRpcResponse when an upstream MCP server answered with content-type text/event-stream but none of the parsed data lines contained a JSON-RPC object with a result or error field. The transport worked; the SSE payload simply never carried a JSON-RPC response (for example only keep-alive/comments, malformed data lines that were skipped, or a stream closed before the response frame).","triggerScenarios":"Thrown at api/mcp-proxy.ts:291 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Confirm the remote endpoint actually implements the MCP Streamable HTTP/SSE protocol and sends a JSON-RPC response frame","Capture the raw SSE body to inspect which data lines were skipped by the JSON.parse guard","Retry once: servers that flush events slowly can close the stream before the response frame"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"e586b8b4b80f595aa7ece295eec10d76f2921240","analyzedAt":"2026-08-21T16:51:25.751Z","contentChangedAt":"2026-08-21T16:51:25.751Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}