github / github/github-mcp-server

Enforce fail-closed startup when PAT/OAuth scope requirements are unmet

オープン
#2,075 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Go
スター
33k
フォーク
5k
平均マージ
2日 1時間
マージ済み PR(30日)
52

説明

Problem
Insufficient scopes can lead to confusing partial functionality instead of explicit blocking.

Why now
Permission-scoped operation is a core safety expectation for the GitHub MCP server.

Current behavior is insufficient
Scope problems can surface late at tool-call time and appear as sporadic failures.

Expected behavior
At startup (or deterministic preflight), fail closed when required scope requirements for configured toolsets are unmet.

Acceptance criteria
- Deterministic scope validation result before normal operation.
- Explicit classification for scope/policy failures.
- Clear remediation guidance in machine-readable + human-readable error output.

Validation
- Add tests for scope-deficient and scope-sufficient configurations.
- Verify deterministic error class and output shape.

Codepaths
- `pkg/scopes`
- `pkg/http/oauth`
- `cmd/github-mcp-server`

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。