fix: first-run docs, changelog, upgrade-start log noise and set_profile reach - #1482
Merged
Merged
Conversation
…treat an in-flight connect as no error
… a switchable client
…d credentials still apply without a profile
…d first-run fixes since v0.69.0
Deploying mcpproxy-docs with
|
| Latest commit: |
ce91a75
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://3d05ba99.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://firstrun-docs-and-verified-f.mcpproxy-docs.pages.dev |
Contributor
📦 Build ArtifactsWorkflow Run: View Run Available Artifacts
How to DownloadOption 1: GitHub Web UI (easiest)
Option 2: GitHub CLI gh run download 37107865284 --repo smart-mcp-proxy/mcpproxy-go
|
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Docs, changelog and verified fixes from a first-run, upgrade and user-test pass on
main(335477e).Docs
docs/features/profiles.md: profiles are optional. Without an effective profile, no profile-level restriction applies (a scoped credential's own grant still does). The quick start is presented as being for scoped access.docs/configuration.md(quarantinedrow): explains the real default. A server added through the UI, CLI or API follows its trust mode. A first-seen config-file server with noquarantinedkey and noconfig.dbrecord is held for review. An explicit value wins, and a recorded server keeps its state. Links to the admission rules.docs/features/security-quarantine.md: the hand-editing section names the extra conditions: quarantine is enabled, and the trust mode is notauto(including legacyauto_approve_tool_changes/skip_quarantineresolving toauto), matchingServerConfig.EffectiveTrustMode.docs/getting-started/quick-start.mdx: a plain note that a server added by editing the file is held for review until approved.CHANGELOG.md: the security, review, catalog, telemetry, CLI and first-run fixes merged since v0.69.0 (fix(security): keep implicit quarantine across server restarts and config writes (Spec fix-quarantine-restart) #1463, fix: Home estimate label, Get started card, Activity conflict clear and status-coloured health (Spec fix-ux-residuals) #1467–fix: first-run user test findings in setup import, secrets, status pill and profile Try it (Spec fix-usertest-web) #1473, fix(review): review screen starts fail-closed with exact-count approve (Spec fix-review-defaults) #1481) plus this PR's.Fixes (each reproduced in an isolated instance, regression test fails on main)
reportPreFixAdmissionsran on every gate pass (initial gate,LoadConfiguredServers, every publish), so an upgrade start logged the "predate the config-load admission gate" advisory 2–5 times. It is now reported once per server per process. Gate decisions are unchanged.LoadConfiguredServers→AddServerasked a not-yet-ready client to connect. The second call was correctly refused with "connection already in progress or established (state: Connecting)" but logged at ERROR, and server identity registration was skipped. A newmanaged.ErrConnectAlreadyActivesentinel (same message text) letsAddServertreat it as success at debug level.set_profileunder-reported a switchable client's reach. After a successful switch,resolveEffectiveProfileForJustSetSlugtreated the client binding as authoritative and reported the binding's servers instead of the selected profile's.Verification