main · last commit
18 hours ago ·
8tmadfpi
spec-jjo MCP read tools (/mcp) have no auth gate — reads are open behind the Host check
Past Stand
bd reopen spec-jjo
| Created by | Eugene Blikh |
| Owner | bigbes@gmail.com |
| Created | 2026-07-23T05:29:15Z |
| Started | 2026-07-24T16:42:15Z |
| Updated | 2026-07-24T16:45:32Z |
| Closed | 2026-07-24T16:45:32Z |
Phase 3 added the resolver middleware to /mcp so spec_propose can resolve the agent, but the read tools (spec_search/spec_read/spec_list) still have no ACL: anyone passing the Host allowlist can read approved content. graph's /query gates to owner+agents (graph.gate); /mcp does not. The design's read plane is fail-closed (owner+agents only). Add the same gate to the MCP surface. Pre-existing since Phase 2; not caused by Phase 3, but now that /mcp resolves a principal the gate is a one-liner. Deliberately left out of Phase 3 to avoid changing Phase 2 read behavior mid-feature.
spec-ejq
— spec.sr.ht — reviewable document storage for humans and agents
parent-child
open
Nothing depends on this issue.
| id | spec-jjo |
| content_hash | 24266167e6658b316bf0de74a8be97019e0447b2d70f6008f89195e84041133c |
| title | MCP read tools (/mcp) have no auth gate — reads are open behind the Host check |
| description | Phase 3 added the resolver middleware to /mcp so spec_propose can resolve the agent, but the read tools (spec_search/spec_read/spec_list) still have no ACL: anyone passing the Host allowlist can read approved content. graph's /query gates to owner+agents (graph.gate); /mcp does not. The design's read plane is fail-closed (owner+agents only). Add the same gate to the MCP surface. Pre-existing since Phase 2; not caused by Phase 3, but now that /mcp resolves a principal the gate is a one-liner. Deliberately left out of Phase 3 to avoid changing Phase 2 read behavior mid-feature. |
| design | |
| acceptance_criteria | |
| notes | |
| status | closed |
| priority | 3 |
| issue_type | bug |
| assignee | Eugene Blikh |
| estimated_minutes | NULL |
| created_at | 2026-07-23T05:29:15Z |
| created_by | Eugene Blikh |
| owner | bigbes@gmail.com |
| updated_at | 2026-07-24T16:45:32Z |
| closed_at | 2026-07-24T16:45:32Z |
| closed_by_session | |
| external_ref | NULL |
| spec_id | |
| compaction_level | 0 |
| compacted_at | NULL |
| compacted_at_commit | NULL |
| original_size | NULL |
| sender | |
| ephemeral | 0 |
| wisp_type | |
| pinned | 0 |
| is_template | 0 |
| mol_type | |
| work_type | |
| source_system | |
| metadata | �{} |
| source_repo | |
| close_reason | MCP surface gated to owner+agents (mcpsrv.Gate), mounted inside resolver middleware; tests cover anon 401 / owner+agent pass / fail-closed without middleware. Commit 7cc652d. |
| event_kind | |
| actor | |
| target | |
| payload | |
| await_type | |
| await_id | |
| timeout_ns | 0 |
| waiters | |
| hook_bead | |
| role_bead | |
| agent_state | |
| last_activity | NULL |
| role_type | |
| rig | |
| due_at | NULL |
| defer_until | NULL |
| no_history | 0 |
| started_at | 2026-07-24T16:42:15Z |
| is_blocked | 0 |
| id | 49a947ec-d0d5-5d70-ad27-643bcfbfc4f7 |
| issue_id | spec-jjo |
| type | parent-child |
| created_at | 2026-07-23T08:29:28Z |
| created_by | Eugene Blikh |
| metadata | �{} |
| thread_id | |
| depends_on_issue_id | spec-ejq |
| depends_on_wisp_id | NULL |
| depends_on_external | NULL |
| id | 019f8d73-0a9b-7e86-8f51-1851559c98a1 |
| issue_id | spec-jjo |
| event_type | created |
| actor | Eugene Blikh |
| old_value | |
| new_value | |
| comment | NULL |
| created_at | 2026-07-23T08:29:14Z |
| id | 019f9501-8f28-7cb9-adf5-63cf96358bd3 |
| issue_id | spec-jjo |
| event_type | claimed |
| actor | Eugene Blikh |
| old_value | {"id":"spec-jjo","title":"MCP read tools (/mcp) have no auth gate — reads are open behind the Host check","description":"Phase 3 added the resolver middleware to /mcp so spec_propose can resolve the agent, but the read tools (spec_search/spec_read/spec_list) still have no ACL: anyone passing the Host allowlist can read approved content. graph's /query gates to owner+agents (graph.gate); /mcp does not. The design's read plane is fail-closed (owner+agents only). Add the same gate to the MCP surface. Pre-existing since Phase 2; not caused by Phase 3, but now that /mcp resolves a principal the gate is a one-liner. Deliberately left out of Phase 3 to avoid changing Phase 2 read behavior mid-feature.","status":"open","priority":3,"issue_type":"bug","owner":"bigbes@gmail.com","created_at":"2026-07-23T05:29:15Z","created_by":"Eugene Blikh","updated_at":"2026-07-23T05:29:15Z"} |
| new_value | {"assignee":"Eugene Blikh","status":"in_progress"} |
| comment | NULL |
| created_at | 2026-07-24T19:42:15Z |
| id | 019f9504-8f0b-769f-ae58-fa2d2f33e332 |
| issue_id | spec-jjo |
| event_type | closed |
| actor | Eugene Blikh |
| old_value | |
| new_value | MCP surface gated to owner+agents (mcpsrv.Gate), mounted inside resolver middleware; tests cover anon 401 / owner+agent pass / fail-closed without middleware. Commit 7cc652d. |
| comment | NULL |
| created_at | 2026-07-24T19:45:31Z |
No comments.
Close reason