Skip to content

fix(profile): make glob '*' match newlines so deny rules cannot fail open - #1420

Merged
github-actions[bot] merged 2 commits into
mainfrom
fix/low-1393-profile-policy
Sep 29, 2026
Merged

github-actions[bot] merged 2 commits into
mainfrom
fix/low-1393-profile-policy

Conversation

@Dumbris

@Dumbris Dumbris commented Sep 29, 2026

Copy link
Copy Markdown
Member

Fixes the still-actual items from the 108-a profile policy review follow-ups.

  • Glob compilation now uses (?s) so * matches embedded newlines in a tool identity (a deny pattern such as github:delete* no longer fails open on github:delete\nrepo). Regression cases added first and confirmed failing.
  • Legacy profile round-trip test now asserts byte equality (require.Equal), matching its doc comment.
  • Renamed the mislabeled "tool name containing a slash" glob case and added a real slash-containing exact case.
  • Corrected the node-fixture comment: only tool names and order are shared between the JSON and in-process fixtures.

Not changed: items 4 and 5 are obsolete (the policy enforcement test override was removed in #1411); item 6 (REST-door test fake) is a low-value coverage gap left open.

Refs #1393

…open

Compile profile glob patterns with the (?s) flag so '*' also matches embedded newlines in a tool identity. Also tighten the legacy round-trip test to assert byte equality, fix a mislabeled glob test case, and correct the node-fixture drift comment.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: e1ec00c
Status: ✅  Deploy successful!
Preview URL: https://8b28936a.mcpproxy-docs.pages.dev
Branch Preview URL: https://fix-low-1393-profile-policy.mcpproxy-docs.pages.dev

View logs

@github-actions

Copy link
Copy Markdown
Contributor

📦 Build Artifacts

Workflow Run: View Run
Branch: fix/low-1393-profile-policy

Available Artifacts

  • archive-darwin-amd64 (30 MB)
  • archive-darwin-arm64 (27 MB)
  • archive-linux-amd64 (18 MB)
  • archive-linux-arm64 (16 MB)
  • archive-windows-amd64 (30 MB)
  • archive-windows-arm64 (27 MB)
  • frontend-dist-pr (0 MB)
  • installer-dmg-darwin-amd64 (24 MB)
  • installer-dmg-darwin-arm64 (22 MB)
  • smart-mcp-proxymcpproxy-go56DQHX.dockerbuild (0 MB)

How to Download

Option 1: GitHub Web UI (easiest)

  1. Go to the workflow run page linked above
  2. Scroll to the bottom "Artifacts" section
  3. Click on the artifact you want to download

Option 2: GitHub CLI

gh run download 36565970847 --repo smart-mcp-proxy/mcpproxy-go

Note: Artifacts expire in 14 days.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved (Model B): Paperclip review verdicts = ACCEPT and qa-gate green at this head SHA. Arming auto-merge; GitHub merges when all required checks pass.

@github-actions
github-actions Bot merged commit eede497 into main Sep 29, 2026
58 of 61 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants