[Feature Request] MCP allow list should validate against WebHook/SSE/HTTP path, not just configured name
Status Closed — not planned
Maintainer reply None cached
Activity 3 comments · opened Dec 16, 2025 · closed Feb 14, 2026
Bug Description
The allow list for MCPs in managed settings seems like a good idea, but matching only on the configured name means it's pretty useless. Nothing stops someone from adding an MCP under a different name, to bypass the restrictions.
Environment Info
- Platform: linux
- Terminal: gnome-terminal
- Version: 2.0.69
This issue has 3 comments on GitHub. Read the full discussion on GitHub ↗