Agent token scope: the capability boundary, and its ADR #24
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
#23 An Agent round-trips through the MCP endpoint
olympus/infra-forge
Reference
olympus/infra-forge#24
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent
#17 — Install forgejo-mcp on the Guest as a LAN-reachable Service
What to build
The boundary that makes the endpoint safe to hand an Agent, recorded and then demonstrated against the live endpoint.
The decision: each Agent presents its own Forgejo token, so no single credential is shared across the fleet. Triage is
write:issue; browsing PRs and repository code addsread:repository;write:repository— which unlocks contents, Actions, PR merge and push — is refused, so a leaked Agent token's blast radius stops at issues.The demonstration: the server enforces none of this, so the scopes are the whole boundary and have to be shown to hold. An issue call succeeds with a
write:issuetoken; the same call is refused403by a token lacking the issue category; and awrite:issuetoken is refused403on a PR-merge or file-write call.The decision is recorded as an ADR taking the next free number, with its row in the ADR index.
Acceptance criteria
write:issuefor triage;read:repositoryadded for PR and code browsing;write:repositoryrefused; and that the Service holds no credential and enforces no authorisation, so the token is the only boundary.docs/adr/*as a glob, so a new ADR needs no manifest edit.)write:issuetoken,403for the same call without the issue category, and403for a PR-merge or file-write call under awrite:issuetoken.Implemented on the integration branch
hermes/17-forgejo-mcp(commit6f882f0), draft PR #56.ADR 0005 —
docs/adr/0005-agent-token-scope.md, the next free number (0001–0004 taken), with its row added todocs/adr/index.md. No manifest edit:docs/adr/*is already a published glob.It records: per-Agent Forgejo tokens (no shared fleet credential);
write:issuefor triage, plusread:organization— honestly more than the ticket's prose, because the label tools (add_issue_labels,create_issue/update_issuewithlabels) callGET /orgs/<owner>/labelsfirst and that call is403underwrite:issuealone, failing the whole tool;read:repositoryto browse PRs and code;write:repositoryrefused; and that the credential-less Service enforces no authorisation, so the token scope is the only boundary.Capability seam, verified live against the PRE endpoint
http://10.12.0.142:8089/mcponpit/mcp-probe(tokens minted on the PRE Guest only — no PROD mutation; serverforgejo-mcp 3.2.0, 156 tools):list_repo_issueswrite:issueisError=False)list_repo_issuesread:repositorytoken does not have at least one of required scope(s): [read:issue]create_filewrite:issue... [write:repository]merge_pull_requestwrite:issueserver returned HTTP 403 (expected 200)Closes with PR #56.