Skip to content

Persist MCP authority usage, revocation, and idempotency - #18

Merged
HarperZ9 merged 2 commits into
mainfrom
codex/control-durable-authority-20260915
Sep 15, 2026
Merged

HarperZ9 merged 2 commits into
mainfrom
codex/control-durable-authority-20260915

Conversation

@HarperZ9

@HarperZ9 HarperZ9 commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

Remote MCP actions can otherwise reuse finite grants or idempotency keys after a restart. This adds optional SQLite authority state that persists revocation, reserves usage atomically, and refuses a repeated request or conflicting key. Unresolved precommit reservations remain unavailable until a local operator records recovery.

When enabled, the actuation path refuses access to configured grant, journal, and authority-state files before reading or writing them, including literal percent characters, resolvable aliases, and existing hardlinks. Local CLI commands support revocation, recovery, and state diagnosis. Existing operation without the optional state configuration is retained.

Validation: hosted Windows CI passed 457 Python tests and the browser-client suite. Local validation also passed 456 Python tests, 5 browser-client tests, MCP stdio smoke, and the installed editable CLI doctor. A CLI subprocess regression test preserves configured sibling dependency paths; its clean-site reproduction passed with Python -S. Independent review reproduced the prior filename and hardlink bypasses and confirmed refusal before action with unchanged protected files. Staged whitespace checks passed; final cleanup removed two trailing blank lines without changing the Python AST.

Limits: these are local synthetic checks. Path resolution is not race-proof, and rollback of the authority database requires an external protected anchor to detect. This does not establish production safety for browser, UIA, command, provider, or network effectors. No package release or production deployment is included.

@HarperZ9
HarperZ9 merged commit c73d745 into main Sep 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant