Skip to content

fix(code): preserve remembered MCP approvals with env allowlist - #4889

Merged
Mason Daugherty (mdrxy) merged 2 commits into
mainfrom
mdrxy/code/preserve-mcp-approvals
Jul 21, 2026
Merged

fix(code): preserve remembered MCP approvals with env allowlist#4889
Mason Daugherty (mdrxy) merged 2 commits into
mainfrom
mdrxy/code/preserve-mcp-approvals

Conversation

@mdrxy

@mdrxy Mason Daugherty (mdrxy) commented Jul 21, 2026

Copy link
Copy Markdown
Member

Users who configure a process-wide MCP allowlist and also choose “Allow for this project — until changed” are now prompted only once (fixes an issue where this was previously discarded).


A user can intentionally have two kinds of MCP approval at the same time:

  • Process-wide server names in DEEPAGENTS_CODE_DANGEROUSLY_ENABLE_PROJECT_MCP_SERVERS, which bypass project and server-definition binding.
  • Project-scoped approvals saved by the startup prompt, which match only the same project root, server name, and server-definition fingerprint.

Before

  1. The user starts dcode in a project whose MCP servers are not in the process-wide allowlist.

  2. They choose “Allow for this project — until changed.”

  3. dcode writes valid scoped approvals and reports:

    Allowing 2 project MCP servers for this session; remembering 2 for this project.
    
  4. On the next launch, the presence of the process-wide env var causes the loader to ignore every saved scoped approval, even when the env var contains unrelated names.

  5. The same “Approve project MCP servers” prompt appears again.

After

  • Process-wide names and scoped remembered approvals are independent grants, so both remain active.
  • The next launch recognizes the saved project/server fingerprints and does not prompt again.
  • An explicitly empty process-wide allowlist contributes no global names but does not clear remembered project approvals.
  • A changed server command or URL still requires re-approval, and disabled server names still take precedence over every approval source.

Regression coverage reproduces the repeated-launch case and verifies both populated and empty process-wide allowlists.

@github-actions github-actions Bot added dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: S 50-199 LOC labels Jul 21, 2026

@open-swe open-swe Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Open SWE Review found 1 potential issue.

Open in WebView Open SWE trace

Comment thread libs/code/deepagents_code/model_config.py
@mdrxy
Mason Daugherty (mdrxy) merged commit b513bf3 into main Jul 21, 2026
80 checks passed
@mdrxy
Mason Daugherty (mdrxy) deleted the mdrxy/code/preserve-mcp-approvals branch July 21, 2026 16:13
Mason Daugherty (mdrxy) pushed a commit that referenced this pull request Jul 22, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Release notes preview: keep this section in sync with the package
`CHANGELOG.md`. The published GitHub release body is extracted from the
merged `CHANGELOG.md` by `release.yml`, not from this PR description._

---


##
[0.1.45](deepagents-code==0.1.44...deepagents-code==0.1.45)
(2026-07-22)

### Features

- Added the Hooks v2 execution engine and typed hooks data models
([#4880](#4880),
[#4870](#4870))
- Added a filesystem tool allowlist for `dcode` with `--allow-fs-tools`
([#4635](#4635))
- Added a GLM-5.2 harness profile
([#4710](#4710))
- Added a built-in thread inspector skill
([#4769](#4769))
- Replaced Gemini 3.5 Flash with Gemini 3.6 Flash in the model switcher
([#4890](#4890))
- Show experimental mode in the splash screen and debug console
([#4863](#4863))
- Gate debug console click-to-copy behind a checkbox
([#4810](#4810))

### Bug Fixes

- Improved scratch-file handling by allowing cleanup of agent-created
scratch files and safe OS-temp scratch artifacts
([#4860](#4860),
[#4869](#4869))
- Skip grading during `/goal` proposals
([#4941](#4941))
- Improved MCP approval handling: Esc now aborts project MCP approval,
disabled MCP servers are honored for plugins, remembered approvals are
preserved with the env allowlist, and approvals are shared across Git
worktrees
([#4888](#4888),
[#4848](#4848),
[#4889](#4889),
[#4939](#4939))
- Hardened installer downloads and paths
([#4871](#4871))
- Fixed forced `dcode update` checks to bust the CDN cache
([#4862](#4862))
- Prevented failed exit setup from stranding the app
([#4913](#4913))
- Fixed routing so `ctrl+x` goes to the focused `ask_user` input
([#4926](#4926))
- Show `-m` prompts as queued immediately on startup
([#4861](#4861))
- Kept harness-profile diagnostics out of terminal output
([#4943](#4943))
- Avoid tracking inline restart callers
([#4894](#4894))
- Fixed debug console thread ID copying on click
([#4945](#4945))

### Performance Improvements

- Reduced exit latency by coordinating async shutdown teardown
([#4831](#4831))
- Sped up local context detection
([#4922](#4922))

_End release notes preview._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
…chain-ai#4889)

Users who configure a process-wide MCP allowlist and also choose “Allow
for this project — until changed” are now prompted only once (fixes an
issue where this was previously discarded).

---

A user can intentionally have two kinds of MCP approval at the same
time:

- Process-wide server names in
`DEEPAGENTS_CODE_DANGEROUSLY_ENABLE_PROJECT_MCP_SERVERS`, which bypass
project and server-definition binding.
- Project-scoped approvals saved by the startup prompt, which match only
the same project root, server name, and server-definition fingerprint.

### Before

1. The user starts `dcode` in a project whose MCP servers are not in the
process-wide allowlist.
2. They choose “Allow for this project — until changed.”
3. `dcode` writes valid scoped approvals and reports:

Allowing 2 project MCP servers for this session; remembering 2 for this
project.

4. On the next launch, the presence of the process-wide env var causes
the loader to ignore every saved scoped approval, even when the env var
contains unrelated names.
5. The same “Approve project MCP servers” prompt appears again.

### After

- Process-wide names and scoped remembered approvals are independent
grants, so both remain active.
- The next launch recognizes the saved project/server fingerprints and
does not prompt again.
- An explicitly empty process-wide allowlist contributes no global names
but does not clear remembered project approvals.
- A changed server command or URL still requires re-approval, and
disabled server names still take precedence over every approval source.

Regression coverage reproduces the repeated-launch case and verifies
both populated and empty process-wide allowlists.
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Release notes preview: keep this section in sync with the package
`CHANGELOG.md`. The published GitHub release body is extracted from the
merged `CHANGELOG.md` by `release.yml`, not from this PR description._

---


##
[0.1.45](langchain-ai/deepagents@deepagents-code==0.1.44...deepagents-code==0.1.45)
(2026-07-22)

### Features

- Added the Hooks v2 execution engine and typed hooks data models
([langchain-ai#4880](langchain-ai#4880),
[langchain-ai#4870](langchain-ai#4870))
- Added a filesystem tool allowlist for `dcode` with `--allow-fs-tools`
([langchain-ai#4635](langchain-ai#4635))
- Added a GLM-5.2 harness profile
([langchain-ai#4710](langchain-ai#4710))
- Added a built-in thread inspector skill
([langchain-ai#4769](langchain-ai#4769))
- Replaced Gemini 3.5 Flash with Gemini 3.6 Flash in the model switcher
([langchain-ai#4890](langchain-ai#4890))
- Show experimental mode in the splash screen and debug console
([langchain-ai#4863](langchain-ai#4863))
- Gate debug console click-to-copy behind a checkbox
([langchain-ai#4810](langchain-ai#4810))

### Bug Fixes

- Improved scratch-file handling by allowing cleanup of agent-created
scratch files and safe OS-temp scratch artifacts
([langchain-ai#4860](langchain-ai#4860),
[langchain-ai#4869](langchain-ai#4869))
- Skip grading during `/goal` proposals
([langchain-ai#4941](langchain-ai#4941))
- Improved MCP approval handling: Esc now aborts project MCP approval,
disabled MCP servers are honored for plugins, remembered approvals are
preserved with the env allowlist, and approvals are shared across Git
worktrees
([langchain-ai#4888](langchain-ai#4888),
[langchain-ai#4848](langchain-ai#4848),
[langchain-ai#4889](langchain-ai#4889),
[langchain-ai#4939](langchain-ai#4939))
- Hardened installer downloads and paths
([langchain-ai#4871](langchain-ai#4871))
- Fixed forced `dcode update` checks to bust the CDN cache
([langchain-ai#4862](langchain-ai#4862))
- Prevented failed exit setup from stranding the app
([langchain-ai#4913](langchain-ai#4913))
- Fixed routing so `ctrl+x` goes to the focused `ask_user` input
([langchain-ai#4926](langchain-ai#4926))
- Show `-m` prompts as queued immediately on startup
([langchain-ai#4861](langchain-ai#4861))
- Kept harness-profile diagnostics out of terminal output
([langchain-ai#4943](langchain-ai#4943))
- Avoid tracking inline restart callers
([langchain-ai#4894](langchain-ai#4894))
- Fixed debug console thread ID copying on click
([langchain-ai#4945](langchain-ai#4945))

### Performance Improvements

- Reduced exit latency by coordinating async shutdown teardown
([langchain-ai#4831](langchain-ai#4831))
- Sped up local context detection
([langchain-ai#4922](langchain-ai#4922))

_End release notes preview._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: S 50-199 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant