SEC-KN-3: cap mcp_access role by scopes; block agent self-apply.
Pass 2 P6 — agent tokens never inherit admin via HUB_ADMIN_USER_IDS; roleEligibleForPersonalSelfApply rejects mcp_access/agent actors. Seven-tier regression vs pre-fix allowlist inheritance; ROADMAP/handover synced.
sha256:5954c433e02f1be6e102da24f6ccf23649373a50feb9cb819a306969ab621e0d
sha
+15
~14
−5
symbols
sha256:5fc34bcece74db97f403e49a6297b7179dfdfc9556887db6e89e6f0a130a93d9
snapshot
+15
symbols added
~14
symbols modified
−5
symbols removed
0
dead code introduced
Semantic Changes
34 symbols
−
NEXT SESSION — SEC-KN-3 mcp_access role cap (PRIMARY)
section NEXT SESSION — SEC-KN-3 mcp_access role cap (PRIMARY) L20–97
+
NEXT SESSION — SEC-KN-4 delegation principal_ref binding (PRIMARY)
section NEXT SESSION — SEC-KN-4 delegation principal_ref binding (PRIMARY) L20–96
~
table
~
table
← Older
Oldest on feat/sec-kn-3-mcp-access-role-cap
All commits
Newer →
Latest on feat/sec-kn-3-mcp-access-role-cap
0 comments
To add a comment, use the Muse CLI:
muse hub commit comment sha256:5954c433e02f1be6e102da24f6ccf23649373a50feb9cb819a306969ab621e0d --body "your comment"
No comments yet. Be the first to start the discussion.