[Feature Request] MCP allow list should validate against WebHook/SSE/HTTP path, not just configured name

Status Closed — not planned
Maintainer reply None cached
Activity 3 comments · opened Dec 16, 2025 · closed Feb 14, 2026

Bug Description
The allow list for MCPs in managed settings seems like a good idea, but matching only on the configured name means it's pretty useless. Nothing stops someone from adding an MCP under a different name, to bypass the restrictions.

Environment Info

  • Platform: linux
  • Terminal: gnome-terminal
  • Version: 2.0.69

View original on GitHub ↗

This issue has 3 comments on GitHub. Read the full discussion on GitHub ↗