Allow MCP to be disabled by a team - #8652
Conversation
|
Are you also hiding the MCP toggle on pages where the team has MCP disabled? |
|
Ok no you are leaving it visible but I'd suggest we remove it since the user shouldn't even be able to call the platform ui tool to pin the browser session on that team |
Yes. added screenshots to OP |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8652 +/- ##
=======================================
Coverage 77.42% 77.43%
=======================================
Files 469 469
Lines 25346 25356 +10
Branches 6751 6754 +3
=======================================
+ Hits 19624 19634 +10
Misses 5722 5722
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Looks good, both gates and tests check out. Two nits:
|
Originally there was a
Please make a suggestion and I will apply it. |
andypalmi
left a comment
There was a problem hiding this comment.
Drop "Zone" so the wording matches the "Danger" nav label. Same as the permissions.js:147 suggestion, for the remaining spots:
andypalmi
left a comment
There was a problem hiding this comment.
Trimming down comments
Co-authored-by: Andrea Palmieri <76187074+andypalmi@users.noreply.github.com>
|
@andypalmi all suggestions applied. @cstns are you ok with approach AND the flags used to gate MCP? (see screenshots in OP for ui part) |
|
Yes I'm okay with it, you can merge as soon as all tests pass EDIT: Sorry, I thought you were talking to me haha |
Description
As requested by a customer (see #8651)
mcpThirdParty- already a platform feature flag and a per-TeamType (plan) default - but this is the first thing that lets a team set its own override:mcpThirdPartyis now in the PUT/api/v1/teams/:teamIdallowedFeatureslist, and the toggle writes it to the team's ownproperties.features.forge/routes/auth/permissions.js- theneedsPermissiongate that already blocks a team-disabled-AI call now also checksmcpThirdParty. Covers the REST-backedplatformtool group.forge/ee/routes/mcp/server.js- a new check where a pinned browser tab's team is resolved, coveringplatform_uiandflow_buildingtool calls. These are dispatched straight to the browser tab and never hit the REST gate above. Fixed the same gap for the existingaiteam toggle while I was in there.hintfield pointing the calling agent back to the toggle, e.g. "A team owner can re-enable MCP access from Team Settings > Danger Zone."Test plan
npm run test:unit:forgeScreenshots
Related Issue(s)
closes #8651
Checklist
flowforge.yml?FlowFuse/helmto update ConfigMap TemplateFlowFuse/CloudProjectto update values for Staging/ProductionLabels
area:migrationlabel