fix: approve every launcher-injected MCP server under protected Full access - #6
Merged
zfy0701 merged 1 commit intoSep 20, 2026
Conversation
…access Protected Full access answered MCP tool approvals itself but approved only ACP-injected servers with a `url`, so a launcher's own stdio bridge had every call cancelled with `user cancelled MCP tool call`. Only the launcher can inject a server, and a name any config layer also declares is never approved, so the injected list is already the provenance proof. Drop the transport condition and rename the field to say what it holds. Fixes agentconnect-md/agentconnect#2151. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Protected Full access answers MCP tool approvals itself: every granular approval
category is disabled, so no client is ever asked. It approved only ACP-injected
servers whose config carries a
url, so a launcher that injects its own bridgeover stdio had every call to that bridge cancelled with
user cancelled MCP tool call, and no approval ever reached the launcher.The same call succeeds in
agentandread-only, which forward the approval tothe ACP client; it failed only in the mode meant to be the most permissive.
Change
Drop the transport condition. Every server the launcher injected through
session/new,session/loadorsession/forkis approved on any transport,under the guards #4 already had:
is never approved, so session config cannot borrow a launcher-injected name;
Only the launcher can put a server on the injected list, so the list is already
the provenance proof. Transport added nothing to it.
fullAccessHttpMcpServersis renamed tofullAccessApprovedMcpServers, since itno longer holds only HTTP servers.
readme-dev.mdis updated, including thesentence that said stdio servers receive no automatic approval.
One behaviour change to be aware of: any other stdio server the launcher injects
(an operator's own MCP servers, for example) is approved under Full access as
well. Other modes still forward those approvals to the client.
Verification
npm run typecheckclean.vitest run src/__tests__/PermissionLifecycleContext.test.ts src/__tests__/CodexACPAgent/CodexAcpClient.test.ts: 118 passed. The full suite was not run locally.name a config layer declares is not.
urlcondition restored, the new case fails withexpected [ 'assigned' ] to deeply equal [ 'bridge', 'assigned' ], which isthe reported bug.
Fixes agentconnect-md/agentconnect#2151. Supersedes #5: same outcome without a
per-launch secret, because the config-layer name guard already refuses a
borrowed name.
🤖 Generated with Claude Code