Skip to content

feat(permissions): complete MAX P7 config, guards and MCP cutover - #382

Merged
leemour merged 5 commits into
mainfrom
feat/p7-cutover
Oct 3, 2026
Merged

leemour merged 5 commits into
mainfrom
feat/p7-cutover

Conversation

@leemour

@leemour leemour commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

MAX rejects canonical permissions today and uses separate legacy policy checks in CLI, native methods, the server and MCP. This completes its P7 cutover: one layered permission map governs reads and writes, while config migrate translates legacy access settings and moderation consent without losing MAX settings or saved checkpoints.

The owner's concrete policy is covered through CLI and MCP:

{"profiles":{"work":{"permissions":{"messages":"readonly","messages.delete":"allow"}}}}

Message reading and deletion work, deletion needs no extra flag/form, and message sends/edits/forwards/pins are refused. Other resources keep their configured/default rights.

Most MCP writes are now offered by default. Denied resources hide tools/prompts/resources, readonly hides writes, ask uses a terminal answer or sealed MCP form, and allow does not ask. JSON mode never asks interactively. Explicit confirmation reaches the server, which rechecks its current configuration and does not let confirmation override deny/readonly. Recipients, hourly limits, server-owned journaling and applied-operation receipts remain enforced. Agent generic deletion remains owner-only; other-device logout and login secrets are not offered.

Legacy files remain readable. After canonical permissions appear, old access setters refuse. Retired MCP grant flags start with a warning and grant nothing; confirm-send still requires every write to be shown. MAX's strict schema and its serve/transcribeModel/kind-specific provenance are preserved, using the shared schema, translation, resolver and migration engine for permission policy. Shared moderation rules replace the duplicate schema. Shared unpin correction #485 is published in 0.138 and included in main's adopted SDK 0.139.

Validation: 1,361 tests passed, 2 skipped; coverage above all existing global/per-file floors; lint, typecheck, generated specs/commands, docs, parity, Bun smoke and command matrix passed (513 tested, 59 with documented exclusions, 0 missing). New tests cover the mixed policy, denial before MAX access, native/nested read gates, terminal/JSON confirmation, migration preview/idempotence/profile lock/group checkpoints, MCP forms/hiding, and raw server requests including moderation without a second question.

No live account operations or owner configuration edits. T6's separate live verification remains pending.

@leemour
leemour merged commit 71b429f into main Oct 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant