Skip to content

Restrict enterprise MCP auth and fail closed on config refresh - #49260

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/34429cd339c1ec152a2ee8697cb29f0cff5d9e5f
Sep 29, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/34429cd339c1ec152a2ee8697cb29f0cff5d9e5f

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Restrict enterprise MCP auth and fail closed on config refresh

Why

Configuration reloads must honor current managed restrictions without granting new enterprise MCP authority to existing sessions or overwriting newer configuration with stale snapshots.

What changed

  • Allow enterprise managed authentication only for configured MCP servers. Remove plugin ema_auth overlays from the schema and disable servers that still use them.
  • Refresh ordinary MCP settings while preserving session settings and initially admitted enterprise registrations. Disable enterprise MCP when its registration changes, policy revokes access, or configuration loading or resolution fails; require a new session to restore enterprise authority.
  • Publish refreshes only when their captured configuration is still current, with bounded retries in app-server reloads. Preserve updated managed restrictions even when a refresh is rejected.
  • Finish processing other thread refreshes before config/mcpServer/reload reports a rejection, and document that an error can accompany partially applied changes.

Testing

Add regression coverage for stale refreshes, bounded retries, managed-policy revocation, persistent enterprise disablement, ordinary MCP transport changes, and rejection of plugin enterprise authentication. Verify that denied enterprise servers receive no requests.

## Why

Configuration reloads must honor current managed restrictions without granting new enterprise MCP authority to existing sessions or overwriting newer configuration with stale snapshots.

## What changed

- Allow enterprise managed authentication only for configured MCP servers. Remove plugin `ema_auth` overlays from the schema and disable servers that still use them.
- Refresh ordinary MCP settings while preserving session settings and initially admitted enterprise registrations. Disable enterprise MCP when its registration changes, policy revokes access, or configuration loading or resolution fails; require a new session to restore enterprise authority.
- Publish refreshes only when their captured configuration is still current, with bounded retries in app-server reloads. Preserve updated managed restrictions even when a refresh is rejected.
- Finish processing other thread refreshes before `config/mcpServer/reload` reports a rejection, and document that an error can accompany partially applied changes.

## Testing

Add regression coverage for stale refreshes, bounded retries, managed-policy revocation, persistent enterprise disablement, ordinary MCP transport changes, and rejection of plugin enterprise authentication. Verify that denied enterprise servers receive no requests.

GitOrigin-RevId: 34429cd339c1ec152a2ee8697cb29f0cff5d9e5f
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/34429cd339c1ec152a2ee8697cb29f0cff5d9e5f branch from d9f2225 to af0d68a Compare September 29, 2026 13:08
@copyberry
copyberry Bot merged commit af0d68a into main Sep 29, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/34429cd339c1ec152a2ee8697cb29f0cff5d9e5f branch September 29, 2026 13:08
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant