FlowFuse / FlowFuse/flowfuse

5.13 Broker and MQTT (special review)

Open
#7,682 0 comments 0 reactions 0 assignees View on GitHub
story
Dominant language
JavaScript
Stars
400
Forks
89
Avg merge
1d 21h
Merged PRs (30d)
146

Description

# 5.13 Broker and MQTT (special review)

**Parent:** Story 5 (#7232)
**Tool file:** new `forge/ee/lib/mcp/tools/broker.js`
**Status:** SPECIAL REVIEW

## Summary

The team broker (built-in MQTT broker clients) and 3rd-party brokers (external broker credentials + topics). This category is credential-sensitive. The endpoints that mint MQTT broker credentials (broker client create/link, setting a client password, 3rd-party broker registration, raw credential fetch) are **not implemented per the #7513 decision**: that issue prevents any PAT-authenticated request from obtaining MQTT broker credentials, and MCP agents are always PAT-authenticated. They are mapped in the admin appendix (issue 5.A) so the decision is reversible. The remaining broker writes (topic CRUD, lifecycle, delete client) do **not** mint credentials, so #7513 does not apply to them; they are phase-2 candidates in 5.13-b/c, contingent on a product decision to allow broker mutation over MCP.

Contributor guide

Open the contributing guide

Research direction

Start with forge/ee/lib/mcp/tools/broker.js and the #7513 decision. Review the admin appendix issue 5.A and the phase-2 candidates in 5.13-b/c; implementation is not ready until a product decision allows broker mutation over MCP. Done would be an agreed scope for the non-credential broker endpoints.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
api, backend
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.