anthropics / anthropics/claude-code

Scheduled routines prompt for connector tool approval; "Allow for all scheduled runs" errors instead of persisting

Aperta
#92,006 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
area:mcp area:permissions area:routines bug duplicate
Lingua principale
Python
Stelle
145k
Fork
23.1k
Metriche di merge delle PR
Metriche PR in attesa

Descrizione

Routines created via the MCP `create_trigger` API attach a connector with an empty tool policy, so every firing prompts for approval that nobody is there to answer. The button meant to fix this errors.

### What happens

A routine calls `mcp__Supabase__execute_sql` and blocks on **"Allow Claude to Execute Sql?"** with *Allow once / Allow for all scheduled runs / Deny*. Clicking **Allow for all scheduled runs** errors, so nothing persists and the next firing prompts again. Unattended firings stall.

### What's expected

Docs state routines run as autonomous cloud sessions with no permission-mode picker and **no approval prompts during a run**, with reach determined by the repos, environment and connectors included. No prompt should appear.

### Evidence

`list_triggers` shows the routine's stored connector grant is empty:

```json
{
"name": "Supabase",
"url": "https://mcp.supabase.com/mcp",
"permitted_tools": [],
"tool_policy_overrides": [],
"clear_tool_policy_overrides": false,
"created_via": "meta_mcp"
}
```

Two separate routines on this account show the identical empty grant.

The **account-level** connector settings are not empty. In Customize > Connectors > Supabase: read-only tools (18) = *Always allow*; write/delete tools = *Custom*, with Execute SQL, Apply migration and Deploy Edge Function all set to allow. Routines appear not to read these.

Confirmed the account settings work in an **interactive** session: `mcp__Supabase__get_project_url` and `mcp__Supabase__execute_sql` (`select 1`) both ran with no prompt. Only routine-fired sessions prompt.

The project `.claude/settings.json` also carries `permissions.allow` entries `mcp__Supabase__*` and `mcp__supabase__*`, which per the permissions docs is valid wildcard syntax for all tools on a server.

### Two bugs, possibly related

1. `create_trigger` accepts only connector *names*, with no field for per-tool policy, so API-created routines get a bare attachment with no policy snapshot and fall back to prompting.
2. **Allow for all scheduled runs** errors rather than writing `tool_policy_overrides`, so there is no way to recover from (1) at the prompt.

### Doc gaps

Not documented: whether project-level `.claude/settings.json` allow rules are honored inside routine sessions, and what "Allow for all scheduled runs" persists, or where.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

Start by reproducing the issue through the MCP create_trigger and list_triggers APIs, then compare the stored connector grant with the account-level Supabase connector settings and the project's .claude/settings.json permissions. Trace what happens when Allow for all scheduled runs is selected and identify where the policy should persist; done means scheduled sessions use the intended grant without prompting or erroring.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
supabase
Ambito
authorization, backend-api-design
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
42/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.