Skip to content

Allow MCP to be disabled by a team - #8652

Merged
Steve-Mcl merged 6 commits into
mainfrom
8651-mcp-enablement
Sep 28, 2026
Merged

Steve-Mcl merged 6 commits into
mainfrom
8651-mcp-enablement

Conversation

@Steve-Mcl

@Steve-Mcl Steve-Mcl commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description

As requested by a customer (see #8651)

  • Adds a "MCP Access" toggle to Team Settings > Danger, under AI Flow Deploy. Enabled by default for every team. Reuses mcpThirdParty - already a platform feature flag and a per-TeamType (plan) default - but this is the first thing that lets a team set its own override: mcpThirdParty is now in the PUT /api/v1/teams/:teamId allowedFeatures list, and the toggle writes it to the team's own properties.features.
  • Disabling it hides the "Connect your AI agent" button and dialog (already gated on this flag in the frontend) and blocks third-party MCP tool calls against that team in two places:
    • forge/routes/auth/permissions.js - the needsPermission gate that already blocks a team-disabled-AI call now also checks mcpThirdParty. Covers the REST-backed platform tool group.
    • forge/ee/routes/mcp/server.js - a new check where a pinned browser tab's team is resolved, covering platform_ui and flow_building tool calls. These are dispatched straight to the browser tab and never hit the REST gate above. Fixed the same gap for the existing ai team toggle while I was in there.
  • 403s from both gates now carry a hint field pointing the calling agent back to the toggle, e.g. "A team owner can re-enable MCP access from Team Settings > Danger Zone."

Test plan

  • npm run test:unit:forge
  • Toggle MCP Access off for a team, confirm the "Connect your AI agent" button disappears
  • With a team-scoped PAT and MCP Access off, confirm a third-party MCP client gets a 403 with the hint
  • With a browser tab pinned via the MCP toggle and MCP Access off for that team, confirm platform_ui/flow_building tool calls are refused

Screenshots

image image image

Related Issue(s)

closes #8651

Checklist

  • I have read the contribution guidelines
  • Suitable unit/system level tests have been added and they pass
  • Documentation has been updated
    • Upgrade instructions
    • Configuration details
    • Concepts
  • Changes flowforge.yml?
    • Issue/PR raised on FlowFuse/helm to update ConfigMap Template
    • Issue/PR raised on FlowFuse/CloudProject to update values for Staging/Production
  • Link to Changelog Entry PR, or note why one is not needed.

Labels

  • Includes a DB migration? -> add the area:migration label

@andypalmi

Copy link
Copy Markdown
Contributor

Are you also hiding the MCP toggle on pages where the team has MCP disabled?

@andypalmi

andypalmi commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Ok no you are leaving it visible but I'd suggest we remove it since the user shouldn't even be able to call the platform ui tool to pin the browser session on that team

@Steve-Mcl

Copy link
Copy Markdown
Contributor Author

Are you also hiding the MCP toggle on pages where the team has MCP disabled?

Yes.

added screenshots to OP

@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.43%. Comparing base (d271eb9) to head (ded9e6e).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #8652   +/-   ##
=======================================
  Coverage   77.42%   77.43%           
=======================================
  Files         469      469           
  Lines       25346    25356   +10     
  Branches     6751     6754    +3     
=======================================
+ Hits        19624    19634   +10     
  Misses       5722     5722           
Flag Coverage Δ
backend 77.43% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@andypalmi

Copy link
Copy Markdown
Contributor

Looks good, both gates and tests check out. Two nits:

  1. Description mentions a hint field, but the guidance is appended to error instead. Match the description, or was a structured hint intended?
  2. The 403s say "Danger Zone" but the tab is labelled "Danger".

@Steve-Mcl

Copy link
Copy Markdown
Contributor Author

Looks good, both gates and tests check out. Two nits:

  1. Description mentions a hint field, but the guidance is appended to error instead. Match the description, or was a structured hint intended?
  2. The 403s say "Danger Zone" but the tab is labelled "Danger".

Originally there was a hint field but it was not being returned to the ai. I decided to fold the message in to the error instead (was the quickest win).

2. The 403s say "Danger Zone" but the tab is labelled "Danger"

Please make a suggestion and I will apply it.

Comment thread forge/routes/auth/permissions.js Outdated

@andypalmi andypalmi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Drop "Zone" so the wording matches the "Danger" nav label. Same as the permissions.js:147 suggestion, for the remaining spots:

Comment thread forge/routes/auth/permissions.js Outdated
Comment thread forge/ee/routes/mcp/server.js Outdated
Comment thread forge/ee/routes/mcp/server.js Outdated
Comment thread test/unit/forge/ee/routes/mcp/server_spec.js Outdated
Comment thread test/unit/forge/ee/routes/mcp/server_spec.js Outdated
Comment thread test/unit/forge/ee/routes/mcp/teamAiGate_spec.js Outdated
Comment thread test/unit/forge/ee/routes/mcp/teamMcpGate_spec.js Outdated

@andypalmi andypalmi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Trimming down comments

Comment thread forge/ee/routes/mcp/server.js Outdated
Comment thread forge/ee/routes/mcp/server.js Outdated
Comment thread forge/routes/auth/permissions.js Outdated
Comment thread test/unit/forge/ee/routes/mcp/teamMcpGate_spec.js Outdated
Comment thread test/unit/forge/ee/routes/mcp/teamMcpGate_spec.js Outdated
Steve-Mcl and others added 2 commits September 28, 2026 10:03
Co-authored-by: Andrea Palmieri <76187074+andypalmi@users.noreply.github.com>
@Steve-Mcl

Copy link
Copy Markdown
Contributor Author

@andypalmi all suggestions applied.

@cstns are you ok with approach AND the flags used to gate MCP? (see screenshots in OP for ui part)

@andypalmi

andypalmi commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Yes I'm okay with it, you can merge as soon as all tests pass

EDIT: Sorry, I thought you were talking to me haha

@cstns cstns left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Steve-Mcl
Steve-Mcl enabled auto-merge (squash) September 28, 2026 12:56
@Steve-Mcl
Steve-Mcl merged commit a231326 into main Sep 28, 2026
29 checks passed
@Steve-Mcl
Steve-Mcl deleted the 8651-mcp-enablement branch September 28, 2026 13:19

This branch was successfully deployed

1 active deployment
staging — ded9e6e6 Deployed Sep 28, 2026 by Steve-Mcl via Remove application #11926
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Ability to disable MCP at team level

3 participants