Persist MCP authority usage, revocation, and idempotency - #18
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remote MCP actions can otherwise reuse finite grants or idempotency keys after a restart. This adds optional SQLite authority state that persists revocation, reserves usage atomically, and refuses a repeated request or conflicting key. Unresolved precommit reservations remain unavailable until a local operator records recovery.
When enabled, the actuation path refuses access to configured grant, journal, and authority-state files before reading or writing them, including literal percent characters, resolvable aliases, and existing hardlinks. Local CLI commands support revocation, recovery, and state diagnosis. Existing operation without the optional state configuration is retained.
Validation: hosted Windows CI passed 457 Python tests and the browser-client suite. Local validation also passed 456 Python tests, 5 browser-client tests, MCP stdio smoke, and the installed editable CLI doctor. A CLI subprocess regression test preserves configured sibling dependency paths; its clean-site reproduction passed with Python -S. Independent review reproduced the prior filename and hardlink bypasses and confirmed refusal before action with unchanged protected files. Staged whitespace checks passed; final cleanup removed two trailing blank lines without changing the Python AST.
Limits: these are local synthetic checks. Path resolution is not race-proof, and rollback of the authority database requires an external protected anchor to detect. This does not establish production safety for browser, UIA, command, provider, or network effectors. No package release or production deployment is included.