fix(mcp): treat full-scope read grants as read-only

This commit is contained in:
Dhravya 2026-09-23 01:12:51 +00:00 • committed by Dhravya Shah
parent 57b430b5b6
commit 0e12f0b3a6
2 changed files with 17 additions and 3 deletions

View file

@ -46,4 +46,16 @@ describe("effectiveContainerTagAccess", () => {
{ containerTag: "one", permission: "read" },
])
})
it("treats full-scope read-only grants as read on every tag", () => {
const session: SessionInfo = {
...baseSession,
scope: { type: "full", permission: "read" },
}
expect(effectiveContainerTagAccess(["one", "two"], session)).toEqual([
{ containerTag: "one", permission: "read" },
{ containerTag: "two", permission: "read" },
])
})
})

View file

@ -21,10 +21,12 @@ export function effectiveContainerTagAccess(
permission = memberAccess.get(containerTag) ?? "read"
}
if (
if (session.scope?.permission === "read") {
permission = "read"
} else if (
session.scope?.type === "scoped" &&
(session.scope.permission === "read" ||
(scopedTags.size > 0 && !scopedTags.has(containerTag)))
scopedTags.size > 0 &&
!scopedTags.has(containerTag)
) {
permission = "read"
}