~bigbes/sr-ht-spec · parade

main · last commit 18 hours ago · 8tmadfpi

← Back to the parade

spec-jjo MCP read tools (/mcp) have no auth gate — reads are open behind the Host check Past Stand

status: closed P3 bug @Eugene Blikh
bd reopen spec-jjo
Created byEugene Blikh
Ownerbigbes@gmail.com
Created2026-07-23T05:29:15Z
Started2026-07-24T16:42:15Z
Updated2026-07-24T16:45:32Z
Closed2026-07-24T16:45:32Z
Description
Phase 3 added the resolver middleware to /mcp so spec_propose can resolve the agent, but the read tools (spec_search/spec_read/spec_list) still have no ACL: anyone passing the Host allowlist can read approved content. graph's /query gates to owner+agents (graph.gate); /mcp does not. The design's read plane is fail-closed (owner+agents only). Add the same gate to the MCP surface. Pre-existing since Phase 2; not caused by Phase 3, but now that /mcp resolves a principal the gate is a one-liner. Deliberately left out of Phase 3 to avoid changing Phase 2 read behavior mid-feature.

Depends on

  • spec-ejq — spec.sr.ht — reviewable document storage for humans and agents parent-child open

Depended on by

Nothing depends on this issue.

No comments.

Close reason

MCP surface gated to owner+agents (mcpsrv.Gate), mounted inside resolver middleware; tests cover anon 401 / owner+agent pass / fail-closed without middleware. Commit 7cc652d.
  • Eugene Blikh created the issue · 2026-07-23T08:29:14Z
  • Eugene Blikh added under epic spec-ejq · 2026-07-23T08:29:28Z
  • Eugene Blikh claimed · 2026-07-24T19:42:15Z
  • Eugene Blikh closed the issue · 2026-07-24T19:45:31Z
    MCP surface gated to owner+agents (mcpsrv.Gate), mounted inside resolver middleware; tests cover anon 401 / owner+agent pass / fail-closed without middleware. Commit 7cc652d.
Stored rows — what this pane was built from, as read
issues 1 row
id spec-jjo
content_hash 24266167e6658b316bf0de74a8be97019e0447b2d70f6008f89195e84041133c
title MCP read tools (/mcp) have no auth gate — reads are open behind the Host check
description Phase 3 added the resolver middleware to /mcp so spec_propose can resolve the agent, but the read tools (spec_search/spec_read/spec_list) still have no ACL: anyone passing the Host allowlist can read approved content. graph's /query gates to owner+agents (graph.gate); /mcp does not. The design's read plane is fail-closed (owner+agents only). Add the same gate to the MCP surface. Pre-existing since Phase 2; not caused by Phase 3, but now that /mcp resolves a principal the gate is a one-liner. Deliberately left out of Phase 3 to avoid changing Phase 2 read behavior mid-feature.
design
acceptance_criteria
notes
status closed
priority 3
issue_type bug
assignee Eugene Blikh
estimated_minutes NULL
created_at 2026-07-23T05:29:15Z
created_by Eugene Blikh
owner bigbes@gmail.com
updated_at 2026-07-24T16:45:32Z
closed_at 2026-07-24T16:45:32Z
closed_by_session
external_ref NULL
spec_id
compaction_level 0
compacted_at NULL
compacted_at_commit NULL
original_size NULL
sender
ephemeral 0
wisp_type
pinned 0
is_template 0
mol_type
work_type
source_system
metadata �{}
source_repo
close_reason MCP surface gated to owner+agents (mcpsrv.Gate), mounted inside resolver middleware; tests cover anon 401 / owner+agent pass / fail-closed without middleware. Commit 7cc652d.
event_kind
actor
target
payload
await_type
await_id
timeout_ns 0
waiters
hook_bead
role_bead
agent_state
last_activity NULL
role_type
rig
due_at NULL
defer_until NULL
no_history 0
started_at 2026-07-24T16:42:15Z
is_blocked 0
dependencies 1 row
id 49a947ec-d0d5-5d70-ad27-643bcfbfc4f7
issue_id spec-jjo
type parent-child
created_at 2026-07-23T08:29:28Z
created_by Eugene Blikh
metadata �{}
thread_id
depends_on_issue_id spec-ejq
depends_on_wisp_id NULL
depends_on_external NULL
events 3 rows
id 019f8d73-0a9b-7e86-8f51-1851559c98a1
issue_id spec-jjo
event_type created
actor Eugene Blikh
old_value
new_value
comment NULL
created_at 2026-07-23T08:29:14Z
id 019f9501-8f28-7cb9-adf5-63cf96358bd3
issue_id spec-jjo
event_type claimed
actor Eugene Blikh
old_value {"id":"spec-jjo","title":"MCP read tools (/mcp) have no auth gate — reads are open behind the Host check","description":"Phase 3 added the resolver middleware to /mcp so spec_propose can resolve the agent, but the read tools (spec_search/spec_read/spec_list) still have no ACL: anyone passing the Host allowlist can read approved content. graph's /query gates to owner+agents (graph.gate); /mcp does not. The design's read plane is fail-closed (owner+agents only). Add the same gate to the MCP surface. Pre-existing since Phase 2; not caused by Phase 3, but now that /mcp resolves a principal the gate is a one-liner. Deliberately left out of Phase 3 to avoid changing Phase 2 read behavior mid-feature.","status":"open","priority":3,"issue_type":"bug","owner":"bigbes@gmail.com","created_at":"2026-07-23T05:29:15Z","created_by":"Eugene Blikh","updated_at":"2026-07-23T05:29:15Z"}
new_value {"assignee":"Eugene Blikh","status":"in_progress"}
comment NULL
created_at 2026-07-24T19:42:15Z
id 019f9504-8f0b-769f-ae58-fa2d2f33e332
issue_id spec-jjo
event_type closed
actor Eugene Blikh
old_value
new_value MCP surface gated to owner+agents (mcpsrv.Gate), mounted inside resolver middleware; tests cover anon 401 / owner+agent pass / fail-closed without middleware. Commit 7cc652d.
comment NULL
created_at 2026-07-24T19:45:31Z