mirror of
https://github.com/supermemoryai/supermemory.git
synced 2026-09-30 01:51:28 +00:00
fix(mcp): treat full-scope read grants as read-only
This commit is contained in:
parent
57b430b5b6
commit
0e12f0b3a6
2 changed files with 17 additions and 3 deletions
|
|
@ -46,4 +46,16 @@ describe("effectiveContainerTagAccess", () => {
|
|||
{ containerTag: "one", permission: "read" },
|
||||
])
|
||||
})
|
||||
|
||||
it("treats full-scope read-only grants as read on every tag", () => {
|
||||
const session: SessionInfo = {
|
||||
...baseSession,
|
||||
scope: { type: "full", permission: "read" },
|
||||
}
|
||||
|
||||
expect(effectiveContainerTagAccess(["one", "two"], session)).toEqual([
|
||||
{ containerTag: "one", permission: "read" },
|
||||
{ containerTag: "two", permission: "read" },
|
||||
])
|
||||
})
|
||||
})
|
||||
|
|
|
|||
|
|
@ -21,10 +21,12 @@ export function effectiveContainerTagAccess(
|
|||
permission = memberAccess.get(containerTag) ?? "read"
|
||||
}
|
||||
|
||||
if (
|
||||
if (session.scope?.permission === "read") {
|
||||
permission = "read"
|
||||
} else if (
|
||||
session.scope?.type === "scoped" &&
|
||||
(session.scope.permission === "read" ||
|
||||
(scopedTags.size > 0 && !scopedTags.has(containerTag)))
|
||||
scopedTags.size > 0 &&
|
||||
!scopedTags.has(containerTag)
|
||||
) {
|
||||
permission = "read"
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue