Skip to content

fix: restrict MCP access to allowed repositories - #188

Merged
senamakel merged 1 commit into
mainfrom
mcp-repo-whitelist
Sep 21, 2026
Merged

senamakel merged 1 commit into
mainfrom
mcp-repo-whitelist

Conversation

@senamakel

Copy link
Copy Markdown
Member

What changed

  • add a fail-closed mcp.allowed_repos configuration list
  • reject non-allowlisted repositories before minting a GitHub token or performing reads/writes
  • validate exact owner/name entries, organisation scope, and case-insensitive duplicates
  • configure production for the public tinyhumansai/tinysweeper repository and document the boundary

GitHub App installation alone no longer makes a repository available through MCP.

Verification

  • cargo fmt --all -- --check
  • cargo clippy --locked --all-targets -- -D warnings
  • cargo test --locked --features serve server::mcp:: (16 passed)
  • cargo test --locked (2025 passed)
  • cargo check --locked --all-features --all-targets

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 4 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Incomplete
Priority: critical
Reviewed head: 8f62a401f25e
Updated: 1790007045 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 5 Active findings 4
Tests 1 Noted findings 0
Documentation 1 Resolved findings 0
Configuration 2 Pending checks/questions 1

Completeness: Incomplete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

  • Unreviewed: tinysweeper/tests

Findings

  • high · critique · Enforce the repository allowlist in MCP authorization — `allowed_repos` is added to the configuration, but the MCP server's authorization state and target checks continue to use only `allowed_org`; no MCP code consumes this field. For e (src/config/types\.rs:286)
  • critical · security · Update all router callers for the new allowlist argument — Adding this required parameter changes `router`'s function signature. The existing server route construction is outside this file and is not updated by this pull request, so it sti (src/server/mcp\.rs:101)
  • medium · e2e · Add an end-to-end test that exercises the new allowlist — `checked_repo` is the enforcement point for the new `allowed_repos` gate. It is called from `handle`, `canonicalise`, and the unit tests, but no end-to-end test (the four `src/lan (src/server/mcp\.rs:228)
  • medium · e2e · Add an end-to-end test that exercises the new allowlist — The validation logic in `src/config/validate.rs` is exercised by a unit test, but no end-to-end test validates that a misconfigured `allowed_repos` is rejected at server boot or th (src/config/test\.rs:506)

Could not review: tinysweeper/tests

Before merge

  • Address Enforce the repository allowlist in MCP authorization (src/config/types\.rs).
  • Address Update all router callers for the new allowlist argument (src/server/mcp\.rs).
  • Complete the tests review for tinysweeper/tests.
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 9 files; 1 finding. _The code index is behind this pull request (indexed at `8fb004a0bf7d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._
  • Evidence: src/config/types\.rs — Enforce the repository allowlist in MCP authorization

security

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 8 files; 1 finding. 1 file was not security-reviewed: docs/modules/mcp/README.md (prose or tabular data). _The code index is behind this pull request (indexed at `8fb004a0bf7d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._
  • Evidence: src/server/mcp\.rs — Update all router callers for the new allowlist argument

tests

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: tinysweeper/tests
  • Lane summary: No reviewer could be consulted.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The pull request adds a fail-closed `allowed_repos` allowlist to the MCP endpoint, validated against exact owner/name, organisation scope, and duplicate entries. The diff is consistent, tests cover the new validation and rejection, and the documentation reflects the change. No issues found. _The code index is behind this pull request (indexed at `8fb004a0bf7d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

e2e

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This change adds a per-repository allowlist (`allowed_repos`) to the MCP endpoint, gating every tool call behind an exact `owner/name` check in addition to the existing organisation check. The new field is validated for well-formedness, case-insensitive deduplication, and organisation membership, and is wired into the server router and the unit-test mock. No end-to-end test drives the new behaviour: the e2e harness files mention unrelated tokens such as `tinysweeper` (from existing config keys) or `enabled` / `error` (common words), but no test calls `router`, `checked_repo`, or issues a cross-allowlist tool call over a real or mocked HTTP transport. The change is internal to the server configuration path and is covered at the unit-test level; the e2e gap is a missing system-level exercise of the fail-closed behaviour. _The code index is behind this pull request (indexed at `8fb004a0bf7d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._
  • Evidence: src/server/mcp\.rs — Add an end-to-end test that exercises the new allowlist
  • Evidence: src/config/test\.rs — Add an end-to-end test that exercises the new allowlist
Evidence and run details
  • Models: flash, ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash
  • Spend: $0.032629
  • Tokens: 508558 input · 13906 output · 30674 cached · 680 embedding
Head State Pass summary
8f62a401f25e incomplete 4 active finding(s), 0 resolved finding(s) (at 1790007045)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Warning

Review limit reached

  • Run on-demand review

This review includes 9 billable files and costs up to $2.25.

Or wait 21 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 997e8f7c-84d8-416d-9e2b-e44ebde85acd

📥 Commits

Reviewing files that changed from the base of the PR and between 39aa4f4 and 8f62a40.

📒 Files selected for processing (9)
  • .tinysweeper.toml
  • docs/modules/mcp/README.md
  • src/config/defaults.toml
  • src/config/mod.rs
  • src/config/test.rs
  • src/config/types.rs
  • src/config/validate.rs
  • src/server/mcp.rs
  • src/server/routes.rs

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T16:11:04.051625Z 8f62a40 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

tinysweeper[bot]
tinysweeper Bot previously requested changes Sep 21, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0326 · 508,558 in / 13,906 out · 30,674 cached (6%) · flash, ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 680 embedded
critique:    $0.0158 · 246,132 in / 6,527 out  · 18,214 cached (7%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security:    $0.0147 · 231,013 in / 4,489 out  · 12,460 cached (5%) · gpt-5.6-luna
description: $0.0004 · 6,671 in   / 74 out     · 0 cached (0%)      · deepseek/deepseek-v4-flash
e2e:         $0.0010 · 16,611 in  / 738 out    · 0 cached (0%)      · deepseek/deepseek-v4-flash

Comment thread src/config/types.rs
Comment thread src/server/mcp.rs
Comment thread src/server/mcp.rs
Comment thread src/config/test.rs
@tinysweeper tinysweeper Bot added the priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. label Sep 21, 2026
@senamakel
senamakel dismissed tinysweeper[bot]’s stale review September 21, 2026 16:13

All four threads were answered and resolved with code and test evidence. The two blocking findings are contradicted by the reviewed diff and green compilation: the allowlist is wired through McpState and the sole production router caller. GitHub cannot re-request review from the tinysweeper App identity.

@senamakel
senamakel merged commit ce51852 into main Sep 21, 2026
17 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant