Skip to content

fix(adt-mcp): fail closed on unbounded scoped-read dispatch - #223

Merged
ThePlenkov merged 2 commits into
abapify:mainfrom
ThePlenkov:fix/cts-scoped-read-transports
Sep 29, 2026
Merged

ThePlenkov merged 2 commits into
abapify:mainfrom
ThePlenkov:fix/cts-scoped-read-transports

Conversation

@ThePlenkov

@ThePlenkov ThePlenkov commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

User description

Summary

Fixes #222 — review findings from #221 (CodeAnt / CodeRabbit): read-scoped tokens must not reach CTS tools that accept arbitrary transport identifiers.

  • isScopedReadResourceAllowed in packages/adt-mcp/src/lib/tools/scope-catalogue.ts now fails closed: only get_object/get_object_structure dispatch under a scoped-read credential, and only when the call's TYPE:NAME object key is in resourceKeys.
  • Previously the branch was unreachable-but-open: scopedReadTools in parseScopedAdtInvocationPolicy already whitelists only the two object tools, so the return true fallback had no effect today — but any future widening of that whitelist (e.g. to cts_* reads) would have silently granted unbounded transport access.
  • resourceKeys are canonical object keys (CLAS:ZCL_RELEASE_GATE); transport IDs like DEVK900123 have no binding form and are deliberately not reinterpreted. Transport-aware scoping needs a new contract + issuer change — out of scope here.

Tests

  • Revived tests/scope-enforcement.test.ts — it was dead code: excluded by the vitest include and unrunnable under node --test (.js→.ts specifiers). Converted node:test import → vitest, added it to vitest.config.ts. 12 tests now run in nx test adt-mcp.
  • New regression test: a scoped access with toolNames: ['get_object', 'cts_get_transport'] and resourceKeys: ['CLAS:ZCL_RELEASE_GATE'] still gets mcp_scope_denied on cts_get_transport (handler never called), while get_object for the bound object succeeds.
  • Stale assertion fixed: atc_run/run_unit_tests were reclassified read → safe_execute in e0c792b; the dormant test still asserted read and now asserts the correct class.

Note: 17 other tests/*.test.ts files in this package remain excluded from the vitest config and still use node:test — same dead-code state this file was in. Worth a follow-up sweep.

Test plan

  • bunx nx test adt-mcp — 106 tests pass (2 files)
  • bunx nx lint adt-mcp — pass
  • bunx nx build adt-mcp — pass
  • bunx nx format:check — clean

Generated with Devin


Summary by cubic

Fixes scoped-read dispatch so a read-scoped credential never reaches tools that accept arbitrary transport identifiers, even if the tool whitelist later widens. isScopedReadResourceAllowed now denies every tool except get_object/get_object_structure; previously it returned true for any other tool, an open default that is unreachable today but would grant unbounded transport access if the whitelist ever grew.

Testing

  • Revives tests/scope-enforcement.test.ts under vitest with a regression test proving a widened toolNames list still blocks cts_get_transport with mcp_scope_denied while a resource-bound get_object succeeds.
  • Converts the 17 other dormant test files (auth, HTTP, safe-execution, registry) from node:test to vitest and widens vitest.config.ts include to tests/**/*.test.ts so they run in CI.
  • Fixes stale assertions: atc_run/run_unit_tests are now asserted as safe_execute instead of read, and verified claims comparison accounts for null-prototype objects.

Written for commit 7b41b2f. Summary will update on new commits.

Review in cubic


CodeAnt-AI Description

Prevent scoped read access from reaching unbound transport tools

What Changed

  • Scoped read credentials now allow only resource-bound object reads; other read tools, including transport lookups, are denied before their handlers run
  • Object reads continue to work when the requested object matches an authorized resource
  • ATC analysis is no longer treated as available under ordinary read access
  • Scope enforcement tests now run and cover denied transport access, permitted object access, and the updated ATC permission

Impact

✅ Prevented unauthorized transport reads
✅ Preserved authorized object reads
✅ Corrected ATC access control

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Bug Fixes

    • Scoped access now permits only object retrieval and object-structure tools, and requires each request to match an exact object key in the caller’s scope.
    • Ordinary read access is denied when attempting to run ATC checks.
  • Tests

    • Expanded automated coverage for scoped access and execution-policy enforcement.
    • Updated the test suite to run with Vitest and include all test files.

)

isScopedReadResourceAllowed returned true for every scoped-read tool
other than get_object/get_object_structure. Today the parser whitelist
(scopedReadTools) makes that branch unreachable, but if the whitelist
ever widened — e.g. to the cts_* transport reads — those tools would
inherit unbounded access to arbitrary transport IDs, since resourceKeys
only carry canonical TYPE:NAME object keys and cannot bind transports.

Flip the default to deny: only resource-bound object reads dispatch
under a scoped credential.

Revive scope-enforcement.test.ts under vitest (it was dead code —
excluded from the vitest include and unrunnable under node --test) and
add a regression test proving a widened toolNames list still cannot
dispatch cts_get_transport while a resource-bound get_object succeeds.
Also update the stale ATC assertion: atc_run/run_unit_tests were
reclassified as safe_execute in e0c792b, and the dormant test still
asserted read.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@codeant-ai

codeant-ai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 7b41b2f Sep 28, 2026 · 22:48 22:48
✅ Reviewed your PR a9bec28 Sep 28, 2026 · 21:45 21:47

@codeant-ai

codeant-ai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c15347e7-c914-4696-961b-27d77c096488

📥 Commits

Reviewing files that changed from the base of the PR and between d6315ce and 7b41b2f.

📒 Files selected for processing (21)
  • packages/adt-mcp/src/lib/tools/scope-catalogue.ts
  • packages/adt-mcp/tests/adt-execution-policy.test.ts
  • packages/adt-mcp/tests/delegated-assistant-catalogue.test.ts
  • packages/adt-mcp/tests/delegated-assistant-policy.test.ts
  • packages/adt-mcp/tests/destination-registry.test.ts
  • packages/adt-mcp/tests/flow-checkout-tr.test.ts
  • packages/adt-mcp/tests/http-auth.test.ts
  • packages/adt-mcp/tests/http-changeset.test.ts
  • packages/adt-mcp/tests/http-destination-scope.test.ts
  • packages/adt-mcp/tests/http-handler.test.ts
  • packages/adt-mcp/tests/http-integration.test.ts
  • packages/adt-mcp/tests/http-invocation-auth.test.ts
  • packages/adt-mcp/tests/http-invocation.test.ts
  • packages/adt-mcp/tests/http-oauth.test.ts
  • packages/adt-mcp/tests/integration.test.ts
  • packages/adt-mcp/tests/safe-execute-enforcement.test.ts
  • packages/adt-mcp/tests/scope-enforcement.test.ts
  • packages/adt-mcp/tests/source-capabilities.test.ts
  • packages/adt-mcp/tests/source-version-metadata.test.ts
  • packages/adt-mcp/tests/transport-source-manifest-capabilities.test.ts
  • packages/adt-mcp/vitest.config.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Scoped read checks now allow only object lookup tools. Enforcement tests cover scoped access, and the ADT MCP tests switch to Vitest with an expanded test-file include pattern.

Changes

Scoped read authorization

Layer / File(s) Summary
Restrict and verify scoped read access
packages/adt-mcp/src/lib/tools/scope-catalogue.ts, packages/adt-mcp/tests/scope-enforcement.test.ts
Scoped checks reject tools other than get_object and get_object_structure. Tests verify that scoped transport lookup is denied and canonical scoped object lookup succeeds. They also update expectations for ordinary-read tool classifications.

Vitest test suite

Layer / File(s) Summary
Run the test suite with Vitest
packages/adt-mcp/tests/*, packages/adt-mcp/vitest.config.ts
Test imports and lifecycle hooks switch from Node’s test APIs to Vitest. The Vitest include pattern now covers all tests/**/*.test.ts files.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 7b41b

Scoped callers are denied transport reads while retaining access to in-scope objects. The change is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 7b41b

The change strengthens scoped-read access: transport lookups are denied before their handlers run, while reads of an authorized object remain available. No introduced security finding was established. The assessment is limited to the examined dispatch path and does not cover every deployment or alternate registration path.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — On the examined destination dispatch path, the change removes a potential route from a widened scoped-read allowlist to arbitrary transport lookups. It does not establish that unscoped credentials or alternate registration paths have changed.

Trust Boundaries and Controls

  • observed — For scoped requests on the examined path, the wrapper denies failed authorization before handler execution. The resource check rejects non-object scoped reads, while the separate tool and destination checks also remain required.

Hardening Proposals

  • proposed — If transport-aware scoped reads are introduced later, define an issuer-to-dispatch resource-binding contract and test both layers without removing the independent fail-closed dispatch check.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 21 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: scoped-read dispatch now fails closed when access is unbounded.
Linked Issues check ✅ Passed Issue #222 requires scoped-read access to prevent arbitrary CTS transport reads because resourceKeys has no transport binding. isScopedReadResourceAllowed now returns false for every tool except…
Out of Scope Changes check ✅ Passed The product change is limited to scoped-read resource enforcement. The added regression test directly covers issue #222. The Vitest import updates, test include expansion, and assertion correction ena…
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@baz-reviewer

baz-reviewer Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review this PR on Baz

Merger

Ready to Merge

The fail-closed dispatch change matches the stated security intent, and the only review concern was addressed by enabling the full Vitest suite. No unresolved blocker remains.

@codeant-ai codeant-ai Bot added the size:M This PR changes 30-99 lines, ignoring generated files label Sep 28, 2026

@amazon-q-developer amazon-q-developer Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The security fix properly implements fail-closed behavior for scoped-read dispatch. The change from return true to return false in isScopedReadResourceAllowed correctly prevents scoped-read credentials from reaching unbounded transport tools. Test coverage validates both the denial of cts_get_transport and the continued access to whitelisted object tools.


You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.

@gitar-bot

gitar-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@codacy-production

codacy-production Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 5 complexity · -2 duplication

Metric Results
Complexity 5
Duplication -2

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for adt-cli canceled.

Name Link
🔨 Latest commit 7b41b2f
🔍 Latest deploy log https://app.netlify.com/projects/adt-cli/deploys/6abaeeac4f848c000836f273

Comment thread packages/adt-mcp/vitest.config.ts Outdated
18 test files used node:test and were excluded from the vitest include,
so they never ran in CI — authentication, safe-execution, HTTP, and
registry regressions would pass undetected. Convert imports to vitest,
map node:test before/after hooks to beforeAll/afterAll, and widen the
include to tests/**/*.test.ts.

Two stale assertions surfaced once the dormant tests ran: the ATC test
(fixed in the previous commit — atc_run/run_unit_tests are safe_execute
since e0c792b, not read) and a deepStrictEqual on verified claims whose
null-prototype objects did not match plain-object literals (invocation
intentionally clones untrusted claims into Object.create(null)).

All 19 files / 208 tests pass.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@codeant-ai codeant-ai Bot added size:L This PR changes 100-499 lines, ignoring generated files and removed size:M This PR changes 30-99 lines, ignoring generated files labels Sep 28, 2026
@sonarqubecloud

Copy link
Copy Markdown

@ThePlenkov
ThePlenkov merged commit 7c69efa into abapify:main Sep 29, 2026
22 checks passed
@ThePlenkov
ThePlenkov deleted the fix/cts-scoped-read-transports branch September 29, 2026 09:28
ThePlenkov added a commit that referenced this pull request Sep 29, 2026
Reconciled openspec/changes/ against shipped code (#224). Eight changes
were fully implemented but never archived, leaving openspec/specs/
without an adt-mcp domain and invisible spec drift.

Archived:
- add-mcp-http-transport — spec delta converted from MODIFIED to ADDED
  (no adt-mcp spec existed to modify); 32 tasks ticked, 3 Docker
  artefact tasks left unchecked as deferred
- add-delegated-assistant-read-scope — verified fail-closed dispatch
- classify-atc-as-read-analysis — already reconciled to safe_execute
- add-bounded-analysis-class — verification task ticked (PR #223 gates)
- add-cts-transport-metadata-json — verification ticked; live-SAP proof
  deferred
- add-flow-index-only, add-aclass-parser, arc-1-feature-parity

add-aclass-parser shipped a prose spec without delta headers — the prose
is preserved as design.md and rewritten as a proper ADDED delta.

Remaining open changes are genuinely incomplete (live-SAP verification,
credential rotation, or unfinished waves).

Closes #224

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

baz: ready to merge size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

adt-mcp: scoped-read tokens can query arbitrary transports via cts_* read tools

1 participant