Skip to content

fix(mcp): restrict MCP server destination changes to admins - #8629

Merged
TheodoreSpeaks merged 6 commits into
stagingfrom
fix/mcp-secret-exfil
Oct 5, 2026
Merged

TheodoreSpeaks merged 6 commits into
stagingfrom
fix/mcp-secret-exfil

Conversation

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator

Summary

  • Changing an MCP server's destination (origin or path) now requires workspace admin; query-string edits and every other field stay at write
  • Enforced in updateMcpServer via a required allowDestinationChange flag, so the settings PATCH route, the Copilot edit, and the v2 update all hit the same check
  • Use cases authorize the new admin-only mcp_servers.change_destination operation before writing; the legacy route derives the flag from the caller's role
  • Registering a server whose hashed id collides with an existing row at a different destination is now refused instead of repointing that row

Type of Change

  • Bug fix

Testing

  • Unit tests for writer refusal, admin path, query-string-only edits, route role mapping, and the id-collision refusal
  • bun run lint, bun run check:audits, block registry and docs-manifest checks pass

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFCu7AdYKDS9qmX4qaJg2e

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 5, 2026 7:02pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 10 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/mcp/orchestration/server-lifecycle.ts Outdated
Comment thread apps/sim/lib/mcp/utils.ts Outdated
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@TheodoreSpeaks I have started the AI code review. It will take a few minutes to complete.

@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Restricts MCP server destination changes to admin role.

The PR appears safe to merge based on this review.

Summary

The PR restricts MCP server destination changes to workspace admins, permits query-string-only edits for writers, and rejects registration when a server ID collides with a different destination. Since the previous review, the only change replaces a relative test import with the configured path alias.

Reviews (6) · Last reviewed commit: "chore(mcp): use absolute import in utils..."

Comment thread apps/sim/lib/mcp/utils.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/mcp/orchestration/server-lifecycle.ts Outdated
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@TheodoreSpeaks I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/mcp/orchestration/server-lifecycle.ts Outdated
Comment thread apps/sim/lib/mcp/orchestration/server-lifecycle.ts
Comment thread apps/sim/app/api/mcp/servers/[id]/route.test.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/mcp/orchestration/server-lifecycle.ts Outdated
Comment thread apps/sim/lib/mcp/application/use-cases.ts
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@TheodoreSpeaks I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@TheodoreSpeaks I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/mcp/utils.test.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@TheodoreSpeaks I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@TheodoreSpeaks
TheodoreSpeaks merged commit a865f47 into staging Oct 5, 2026
33 checks passed
@TheodoreSpeaks
TheodoreSpeaks deleted the fix/mcp-secret-exfil branch October 5, 2026 19:33

This branch was previously deployed

1 inactive deployment
Preview — fd39eddc Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant