Skip to content

fix(mcp): treat different URL credentials as a new destination - #8656

Merged
waleedlatif1 merged 1 commit into
stagingfrom
fix/mcp-destination-credentials
Oct 6, 2026
Merged

waleedlatif1 merged 1 commit into
stagingfrom
fix/mcp-destination-credentials

Conversation

@TheodoreSpeaks

@TheodoreSpeaks TheodoreSpeaks commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • isSameMcpServerDestination now compares URL username and password, not just origin + path — URL.origin excludes userinfo, so a URL with different embedded credentials was treated as the same destination
  • Follow-up to fix(mcp): restrict MCP server destination changes to admins #8629; only the query string and fragment may differ now

Type of Change

  • Bug fix

Testing

  • Added a regression case to lib/mcp/utils.test.ts; it fails on the pre-fix code and passes after
  • lib/mcp/ suite (345 tests), bun run lint, bun run check:audits (58 audits), docs-manifest:check

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 6, 2026 2:52am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Changes how MCP server destinations are compared for equality.

The PR appears safe to merge; no outstanding finding or new actionable issue was identified.

Summary

The PR makes MCP destination comparison include URL username and password, and adds a regression test for credential-only differences.

  • Query strings and fragments remain excluded from the comparison.

Reviews (2) · Last reviewed commit: "fix(mcp): treat different URL credential..."

Comment thread apps/sim/lib/mcp/utils.test.ts
@waleedlatif1
waleedlatif1 merged commit 20a7350 into staging Oct 6, 2026
34 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/mcp-destination-credentials branch October 6, 2026 03:05
@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@greptile

@TheodoreSpeaks

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@TheodoreSpeaks I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — 1ddae51a Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants