Repository navigation
fix(clients): revoke the client credential on disconnect - #1518
Merged
Merged
Conversation
DELETE /api/v1/connect/{client} and mcpproxy disconnect (daemon and
offline) now revoke the client credential after removing the entry, as
approved by the maintainer. A revoke failure stays HTTP 200 and is
reported in credential_revoke_error. The Web UI confirmation says so;
docs, swagger and CHANGELOG updated.
fix(runtime): audit and announce the binding restore when a rotating
connect fails to finalize (compensating profile_change record plus
client.binding_changed), and log a restore failure.
Closes #1435
Refs #1451
…revoked tombstones on disconnect The Connect list now reports credential_revoke_error instead of a plain success, disconnect no longer re-forgets an already revoked credential, and the POST /connect swagger text no longer claims a connect revokes.
…nd-internal-httpapi-inter
Dumbris
enabled auto-merge (squash)
October 5, 2026 17:48
Deploying mcpproxy-docs with
|
| Latest commit: |
3c38e93
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://e1f85be5.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://fix-issues-w2b1-backend-inte.mcpproxy-docs.pages.dev |
Dumbris
disabled auto-merge
October 5, 2026 18:00
|
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
Contributor
📦 Build ArtifactsWorkflow Run: View Run Available Artifacts
How to DownloadOption 1: GitHub Web UI (easiest)
Option 2: GitHub CLI gh run download 37417800555 --repo smart-mcp-proxy/mcpproxy-go
|
…nnect A profileless reconnect of a disconnected (revoked) client re-minted it bound to All servers, silently widening a profile-locked client. The revoked tombstone already keeps the prior pin and mode; resolveBindingLocked now keeps it for a revoked record too. An explicit profile still wins, and a tombstone with no binding starts from the defaults. The reconnect preview shares the rule. Old tombstones decode unchanged. refs #1435
… connect minted over it A fresh mint over a revoked/expired record now snapshots the replaced binding on the new record. Abort and undo revoke through ForgetClientCredentialRestoringPrior, which puts it back, so a later profileless reconnect cannot re-mint with the binding of a connect that never took effect. Also corrects the stale REST docs and notes the require_mcp_auth=off guard refusal.
…ange; keep the held binding in the undo record
…nd-internal-httpapi-inter
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Disconnecting a client now revokes its client credential, per the maintainer-approved option B. The change covers
DELETE /api/v1/connect/{client}, daemon-backedmcpproxy disconnectand offlinemcpproxy disconnect. A revoke failure stays HTTP 200 and is reported incredential_revoke_error.Items
credential_revoke_errorwhen the revoke fails. Docs, CLI help, swagger and CHANGELOG are updated. Tests:cmd/mcpproxy/connect_disconnect_revoke_test.go,internal/httpapi/connect_client_credential_test.go,frontend/tests/unit/connect-modal-display-path-reload.spec.ts.profile_changeaudit record, emitsclient.binding_changed, and logs a restore failure. Test:internal/runtime/clients_service_restore_audit_test.go.Skipped or declined
config.db. This was declined. It needs a socket-liveness probe, the trigger is narrow, and failing loudly beats silently skipping the revoke.Review Status
Clean after review, unresolved findings: [].
config.db. Declined: it needs a socket-liveness probe, the trigger is narrow, and failing loudly beats silently skipping the revoke.Reconnect keeps the profile pin
Review found that disconnect plus a profileless reconnect silently widened a profile-pinned client to All servers, because a revoked credential was treated as a fresh grant.
Conservative fix:
Tests cover the preserved binding, explicit profile override, and old-tombstone fallback, alongside the existing "revoked starts from the defaults" contract case. Latest main merged in;
go build ./...andinternal/httpapi,internal/profiletests pass.Closes #1435
Refs #1451