feat(permissions): complete MAX P7 config, guards and MCP cutover - #382
Merged
Merged
Conversation
leemour
force-pushed
the
feat/p7-cutover
branch
from
October 3, 2026 21:49
b413bce to
1303b10
Compare
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
MAX rejects canonical permissions today and uses separate legacy policy checks in CLI, native methods, the server and MCP. This completes its P7 cutover: one layered permission map governs reads and writes, while config migrate translates legacy access settings and moderation consent without losing MAX settings or saved checkpoints.
The owner's concrete policy is covered through CLI and MCP:
{"profiles":{"work":{"permissions":{"messages":"readonly","messages.delete":"allow"}}}}Message reading and deletion work, deletion needs no extra flag/form, and message sends/edits/forwards/pins are refused. Other resources keep their configured/default rights.
Most MCP writes are now offered by default. Denied resources hide tools/prompts/resources, readonly hides writes, ask uses a terminal answer or sealed MCP form, and allow does not ask. JSON mode never asks interactively. Explicit confirmation reaches the server, which rechecks its current configuration and does not let confirmation override deny/readonly. Recipients, hourly limits, server-owned journaling and applied-operation receipts remain enforced. Agent generic deletion remains owner-only; other-device logout and login secrets are not offered.
Legacy files remain readable. After canonical permissions appear, old access setters refuse. Retired MCP grant flags start with a warning and grant nothing; confirm-send still requires every write to be shown. MAX's strict schema and its serve/transcribeModel/kind-specific provenance are preserved, using the shared schema, translation, resolver and migration engine for permission policy. Shared moderation rules replace the duplicate schema. Shared unpin correction #485 is published in 0.138 and included in main's adopted SDK 0.139.
Validation: 1,361 tests passed, 2 skipped; coverage above all existing global/per-file floors; lint, typecheck, generated specs/commands, docs, parity, Bun smoke and command matrix passed (513 tested, 59 with documented exclusions, 0 missing). New tests cover the mixed policy, denial before MAX access, native/nested read gates, terminal/JSON confirmation, migration preview/idempotence/profile lock/group checkpoints, MCP forms/hiding, and raw server requests including moderation without a second question.
No live account operations or owner configuration edits. T6's separate live verification remains pending.