Skip to content

Conversation

@DamjanBecirovic
Copy link
Collaborator

📝 Description

This PR improves the security posture of the exposed MCP tools by adding:

  • RBAC permissions check for the user on whose behalf the action is taken
  • Verifying the resource ownership of the requested resources
  • Sanitization of input parameters before passing them to the backend services

✅ Checklist

  • I have tested this change
  • This change requires documentation update

@github-project-automation github-project-automation bot moved this to Backlog in Roadmap Oct 31, 2025
@DamjanBecirovic DamjanBecirovic changed the title Db/mcp security improvements MCP - security improvements Oct 31, 2025
@DamjanBecirovic DamjanBecirovic mentioned this pull request Oct 31, 2025
2 tasks
@DamjanBecirovic DamjanBecirovic merged commit 493b5c5 into feat/mcp_server Nov 4, 2025
2 checks passed
@DamjanBecirovic DamjanBecirovic deleted the db/mcp-security-improvements branch November 4, 2025 12:24
DamjanBecirovic added a commit that referenced this pull request Nov 6, 2025
## 📝 Description

This PR improves the security posture of the exposed MCP tools by
adding:
- RBAC permissions check for the user on whose behalf the action is
taken
- Verifying the resource ownership of the requested resources
- Sanitization of input parameters before passing them to the backend
services
---------
Co-authored-by: hamir-suspect <ahasanbasic@semaphore.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

3 participants