Skip to content

feat(profile): enforce profile policy on every execution surface (Spec 108-d) - #1411

Merged
github-actions[bot] merged 11 commits into
mainfrom
codex/108-d-profile-execution-enforcement
Sep 29, 2026
Merged

github-actions[bot] merged 11 commits into
mainfrom
codex/108-d-profile-execution-enforcement

Conversation

@Dumbris

@Dumbris Dumbris commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

Enforce Profiles v3 policy consistently across MCP calls and discovery, /mcp/all, nested code execution, REST calls/replay/search, and anonymous profile scope. Denials remain typed and carry block_reason; credential and anonymous profile switching uses one-hop switchable_to admission with uniform refusals.

Review fixes

  • Confine anonymous callers with an active locked client binding at /mcp/p/{slug}, returning the same refusal for existing and missing profiles.
  • Apply REST discovery policy to raw upstream tool names, with regressions for both per-server and global inventories.

Spec and findings

Spec 108-d: specs/108-profiles-v3/ (T044–T055a). Closes P3’s fail-closed enforcement gap across discovery and execution.

Validation

  • Full GitHub CI passed on 066a20c7c8189aeaebac793ea07967a63ee70192.
  • Focused server and HTTP API regressions passed normally and under -race.
  • Built the exact PR source and smoke-tested isolated REST, embedded Web UI, MCP initialize/tools/list, and profile-scoped MCP URLs.
  • git diff --check, formatting, build, and commit hooks passed.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 066a20c
Status: ✅  Deploy successful!
Preview URL: https://d0813715.mcpproxy-docs.pages.dev
Branch Preview URL: https://codex-108-d-profile-executio.mcpproxy-docs.pages.dev

View logs

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

📦 Build Artifacts

Workflow Run: View Run
Branch: codex/108-d-profile-execution-enforcement

Available Artifacts

  • archive-darwin-amd64 (30 MB)
  • archive-darwin-arm64 (27 MB)
  • archive-linux-amd64 (18 MB)
  • archive-linux-arm64 (16 MB)
  • archive-windows-amd64 (30 MB)
  • archive-windows-arm64 (27 MB)
  • frontend-dist-pr (0 MB)
  • installer-dmg-darwin-amd64 (24 MB)
  • installer-dmg-darwin-arm64 (22 MB)
  • smart-mcp-proxymcpproxy-goPQ8OOE.dockerbuild (0 MB)

How to Download

Option 1: GitHub Web UI (easiest)

  1. Go to the workflow run page linked above
  2. Scroll to the bottom "Artifacts" section
  3. Click on the artifact you want to download

Option 2: GitHub CLI

gh run download 36516585508 --repo smart-mcp-proxy/mcpproxy-go

Note: Artifacts expire in 14 days.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved (Model B): Paperclip review verdicts = ACCEPT and qa-gate green at this head SHA. Arming auto-merge; GitHub merges when all required checks pass.

@github-actions
github-actions Bot merged commit acfd057 into main Sep 29, 2026
46 checks passed
github-actions Bot pushed a commit that referenced this pull request Sep 29, 2026
…open (#1420)

Fixes the still-actual items from the 108-a profile policy review
follow-ups.

- Glob compilation now uses `(?s)` so `*` matches embedded newlines in a
tool identity (a deny pattern such as `github:delete*` no longer fails
open on `github:delete\nrepo`). Regression cases added first and
confirmed failing.
- Legacy profile round-trip test now asserts byte equality
(`require.Equal`), matching its doc comment.
- Renamed the mislabeled "tool name containing a slash" glob case and
added a real slash-containing exact case.
- Corrected the node-fixture comment: only tool names and order are
shared between the JSON and in-process fixtures.

Not changed: items 4 and 5 are obsolete (the policy enforcement test
override was removed in #1411); item 6 (REST-door test fake) is a
low-value coverage gap left open.

Refs #1393
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants