Serve every MCP endpoint as a projection of one executor - #1936
Draft
RhysSullivan wants to merge 2 commits into
Draft
Serve every MCP endpoint as a projection of one executor#1936RhysSullivan wants to merge 2 commits into
RhysSullivan wants to merge 2 commits into
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-marketing | 6c82206 | Commit Preview URL Branch Preview URL |
Sep 03 2026, 08:10 AM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-cloud | 6c82206 | Sep 03 2026, 08:13 AM |
RhysSullivan
force-pushed
the
mcp-projection
branch
from
September 3, 2026 07:55
ae8c406 to
971b3f4
Compare
Contributor
Cloudflare preview
Sign-in is Cloudflare Access (one-time PIN to an allowed email). The preview has its own database and encryption key; it is destroyed when this PR closes. |
@executor-js/codemode-core
@executor-js/runtime-quickjs
@executor-js/cli
@executor-js/config
@executor-js/execution
@executor-js/sdk
@executor-js/plugin-file-secrets
@executor-js/plugin-graphql
@executor-js/plugin-keychain
@executor-js/plugin-mcp
@executor-js/plugin-onepassword
@executor-js/plugin-openapi
executor
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The default
/mcpendpoint and the toolkit endpoint (/mcp/toolkits/<slug>) shared auth and transport but not the executor. A toolkit session built a second executor with a different plugin set, and the toolkits plugin installed a policy provider that replaced the workspace policy table instead of layering on it. Workspacerequire_approvalandblockpolicies were therefore never evaluated on toolkit endpoints (#1752). The/mcp/toolkits/<slug>path grammar was also copied in six places.Change
Every MCP endpoint is now one executor seen through a projection.
@executor-js/sdkgainsToolProjection(a visibility filter plus an optional rule overlay) andexecutor.project(name | projection), which rebuilds the view over the same database, plugins, tenant, and subject. Projection rules combine with workspace policies under least privilege: a projection can narrow what the workspace allows but never loosen it. ThetoolPolicyProviderplugin hook is replaced bytoolProjections.@executor-js/plugin-toolkitsno longer takesactiveToolkitSlug. It registers a projection source that resolves a toolkit slug to its connections and rules; every host executor can serve any toolkit.@executor-js/host-mcpowns the resource grammar (mcpResourceFromPathname,mcpResourcePath). Cloud, self-host, host-cloudflare, and local all route through it. Two new scoped endpoints ride the same path:/mcp/integrations/<slug>[,<slug>…]and/mcp/tools/<tool id>./mcp).Verification
bun run typecheck,lint,format:checkgreen.policies.test.ts(new projection cases: allowlist, unknown name exposes nothing, cannot loosen a workspace block, workspacerequire_approvalstill gates, inline integration and single-tool projections), toolkits plugin, host-mcp (new grammar and key tests), cloud mount and auth-provider, self-host MCP, local executor and MCP, host-cloudflare.scenarios/toolkits-mcp.test.tson self-host: 9 of 9 pass, including three new scenarios: a workspace approval policy still gates a toolkit endpoint, a workspace block is enforced on a toolkit endpoint, and the integration and single-tool endpoints project the same catalog.Pre-existing failures in
apps/local(serve.test.ts,v1-v2-migration.test.ts,owned-database.test.ts) reproduce identically onmainand are unrelated.Closes #1752.