Repository navigation
feat(server): /mcp narrows a client's modes from T3-Mode-Limit - #16653
juliusmarminge wants to merge 1 commit into
Conversation
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
0f9bf5b to
fa837fb
Compare
fa837fb to
77ec4c8
Compare
End-to-end run, two real serversTwo Through the link, the box refused launches above the caller's modes. A plain call at CI also showed an unused Opus 5.5 via Claude Code. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to The change narrows OAuth MCP callers’ mode limits, and both limits reach dispatch enforcement. No concrete merge-blocking risk is apparent. 🚥 Pre-merge checks | ✅ 3 | ❌ 1
✨ Finishing Touches
Comment |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR adds per-request MCP mode restrictions and threads them through the authorization checks governing delegated work. Although the optional path is tested and does not alter callers that omit the header, it changes security-sensitive permission boundaries. No code changes detected at You can add or adjust custom eligibility rules. Learn more. |
8eadb66 to
0b07846
Compare
0b07846 to
6e0740f
Compare
6e0740f to
b6c6fe6
Compare
An OAuth client on /mcp is capped by the access it was approved with. When another environment calls on behalf of one of its agents, that agent may run under narrower modes, and the target has no way to know. /mcp now reads `T3-Mode-Limit: <runtimeMode>/<interactionMode>` from OAuth clients and caps the request at the narrower of the two. The header can only narrow: a broader one changes nothing, and a malformed one is refused with 400. The client's interaction mode can now be capped too; before, it was always default. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
b6c6fe6 to
72f69ac
Compare
Part of cross-environment orchestration: an environment linked to another signs in to its
/mcpas an outside agent. Every linked call has to carry the calling agent's own limits, so a plan-mode agent on the laptop can't start full-access work on the box just because the link was approved atauto.What changes
/mcpreads an optionalT3-Mode-Limit: <runtime>/<interaction>header, from OAuth (mcp-client) callers only.invalid_mode_limit).clientModeCeilingreplacesclientRuntimeModeCeiling, adding an interaction ceiling.loadCallerand the orchestrator MCP service use it, so the access declarations and the in-lockDispatchModeLimitcheck enforce the narrowed modes.Verification
McpHttpServer.test.ts. A real/mcp, with anautoOAuth client, serves a probe tool that starts a thread throughMcpToolAccess.startsThreads. Results:auto/default;approval-required/plan→ narrowed, and escalation requests above it are refused;Opus 5.5 via Claude Code.
🤖 Generated with Claude Code