AltimateAI / AltimateAI/altimate-code

test: behavioral regression test that MCP tool calls enforce the permission check

オープン
#997 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
811
フォーク
134
平均マージ
3日 2時間
マージ済み PR(30日)
50

説明

Found during v0.9.1 release review (CTO + Tech-Lead). The security fix e7ec6a9b29 (MCP tools ran with NO permission check — an Effect awaited but never run) has only grep-for-string coverage (`v140-merge-adversarial.test.ts`), which would pass even with the bug present. Add a test that drives an MCP tool call end-to-end through `session/prompt.ts` and asserts `PermissionNext.ask` is actually invoked / the call is gated. Prevents silent reintroduction on refactor.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。