|
mcp: credentials leave the tree, and sub-agents lose the task board
Five tracked configs (gnexus-creds, gntodo, hard-panel, synapse, tgclient) carried live bearer tokens — in git, in every clone, and handed to the admin client by GET /admin/mcp/config. They now name a variable, and the value lives in the service .env (chmod 600, untracked). Substitution happens once, at transport open, next to the project-relative path resolution: that is the single place a transport is built, so every stored and serialised config stays placeholder-only and save_mcp_servers — reached by create_mcp_server and PUT /admin/mcp/config — cannot write a secret back into a tracked file. A variable that is not set refuses the connection instead of dropping the header, which would fail open: a server may answer an unauthenticated request as an anonymous user rather than returning 401. Sub-agents also drop gntodo, gnexus-creds, tgclient and synapse from their scopes, and the runner injects a scope anchor unconditionally — a sub-agent asked to echo one word had picked a project off the task board and researched it for forty iterations. Docs: docs/mcp.md#secrets, a migration recipe in deploy/UPDATE.md, the variable names in .env.example and deploy/env.template, and a regression guard over the tracked configs. The old values stay in git history; rotating all five at their sources is the remediation, not a follow-up. |
|---|
|
|
| .env.example |
|---|
| deploy/UPDATE.md |
|---|
| deploy/env.template |
|---|
| docs/mcp.md |
|---|
| manuals/create_mcp_server.md |
|---|
| mcp_servers.d/gnexus-creds.json |
|---|
| mcp_servers.d/gntodo.json |
|---|
| mcp_servers.d/hard-panel.json |
|---|
| mcp_servers.d/synapse.json |
|---|
| mcp_servers.d/tgclient.json |
|---|
| navi/core/subagent_runner.py |
|---|
| navi/mcp/client.py |
|---|
| navi/mcp/secrets.py 0 → 100644 |
|---|
| navi/profiles/developer/config.json |
|---|
| navi/profiles/discuss/config.json |
|---|
| navi/profiles/modeler_3d/config.json |
|---|
| navi/profiles/navi_code/config.json |
|---|
| navi/profiles/secretary/config.json |
|---|
| navi/profiles/server_admin/config.json |
|---|
| tests/_mcp_test_server.py |
|---|
| tests/integration/test_mcp_integration.py |
|---|
| tests/unit/mcp/test_no_literal_secrets.py 0 → 100644 |
|---|
| tests/unit/mcp/test_secrets.py 0 → 100644 |
|---|