fix(mcp): complete internal auth and audit loading - #13993
Merged
diegosouzapw merged 6 commits intoSep 29, 2026
Merged
diegosouzapw merged 6 commits into
diegosouzapw merged 6 commits into
Conversation
… test Rebase-equivalent merge to clear the DIRTY/CONFLICTING state against the current release tip. The only real conflict was a cosmetic comment/ indentation reflow in audit.test.ts's shutdown timeout comment (both sides asserted identical behavior with the same 30000ms timeout); kept this branch's version, which has the comment lines in original order. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
# Conflicts: # open-sse/mcp-server/__tests__/audit.test.ts # open-sse/mcp-server/audit.ts
diegosouzapw
merged commit Sep 29, 2026
c8ab05f
into
diegosouzapw:release/v3.8.51
0 of 3 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
better-sqlite3dependency through the existing standalone-saferuntimeRequirehelper.Related Issues
Root Cause
The central MCP fetch path acquired internal-service authentication in #9260, but
advancedTools.tsandpickFastestModel.tsuse privateapiFetchhelpers. Those helpers continued forwarding only the caller's read-only bearer token to management routes, so valid read-only MCP calls failed with403 Invalid management token. The cache route also did not recognize the internal service token.Separately, the audit module dynamically imported
node:moduleand calledcreateRequire(import.meta.url). In the webpack standalone server bundle that loader can be rewritten to a non-callable module wrapper, causinga is not a functionwhen audit writes run.Security
/api/cacheaccepts the service token only with the server-stamped loopback locality proof.Validation
npm run test:vitest— 51 files, 474 tests passednpm run check:open-sse-typechecknpm run typecheck:corenpm run build:contributor; inspected the emitted audit route and confirmed it callsruntimeRequire("better-sqlite3")release/v3.8.51head before validationFull
npm run lintreached only the repository-wide stale-suppressions gate (There are suppressions left that do not occur anymore); linting the changed files passes. The full Node unit run progressed through the suite but was stopped after the pre-existing, source-documented Node runtime hang inproxyfetch-direct-response-start-timeout-10214.test.ts; no failure from a changed or related test was observed.The same patch was also validated against a live Docker deployment: the affected read-only MCP tools succeeded, audit rows appeared through both storage and
/api/mcp/audit, and logs no longer containedInvalid management token, the audit loader exception, orscope_deniedfor allowed read tools.Tests Added Or Updated
open-sse/mcp-server/__tests__/audit.test.tsopen-sse/mcp-server/__tests__/httpAuthContext.test.tstests/unit/internal-service-auth.test.tsCoverage Notes
The MCP Vitest suite covers the two private fetch helpers and the audit loader source contract. The Node unit test covers the cache route's loopback-only internal-service boundary. Production bundling validates the exact audit loading path that previously failed only after webpack transformation.
Reviewer Notes
No migration or external-key scope change is required. Operators still need
OMNIROUTE_INTERNAL_SERVICE_TOKEN_FILEconfigured for the internal hop; missing configuration preserves the existing authentication behavior.