Raised by the local cross-family review of LibreChat-AI#16246 (finding local:be4a585:L-001), on code that predates that PR on canary.
buildPostLoginPayload in api/server/routes/config.js calls resolveMCPAppsPolicy with every mcpAppSandbox argument up to maxActionPreviewChars, but leaves out the last parameter, operationLimits. When a deployment sets mcpAppSandbox.operationLimits in librechat.yaml, the authenticated startup config therefore publishes the default operation limits, and the client enforces those instead of the configured ones.
Expected: pass appConfig?.mcpAppSandbox?.operationLimits as the final argument, and cover it in api/server/routes/__tests__/config.spec.js with a configured and a default case.
Raised by the local cross-family review of LibreChat-AI#16246 (finding local:be4a585:L-001), on code that predates that PR on
canary.buildPostLoginPayloadinapi/server/routes/config.jscallsresolveMCPAppsPolicywith everymcpAppSandboxargument up tomaxActionPreviewChars, but leaves out the last parameter,operationLimits. When a deployment setsmcpAppSandbox.operationLimitsin librechat.yaml, the authenticated startup config therefore publishes the default operation limits, and the client enforces those instead of the configured ones.Expected: pass
appConfig?.mcpAppSandbox?.operationLimitsas the final argument, and cover it inapi/server/routes/__tests__/config.spec.jswith a configured and a default case.