Skip to content

Honor multi-valued claims in vMCP authz - #6748

Open
lorenzozanee wants to merge 2 commits into
stacklok:mainfrom
lorenzozanee:fix/vmcp-multivalued-claims
Open

lorenzozanee wants to merge 2 commits into
stacklok:mainfrom
lorenzozanee:fix/vmcp-multivalued-claims

Conversation

@lorenzozanee

Copy link
Copy Markdown
Contributor

Summary

multi_valued_claims is accepted by MCPAuthzConfig but dropped on the VirtualMCPServer path, so Cedar never creates the configured claimset_* attribute and policies that use it deny requests.

  • Forward the setting through referenced authz resources and ConfigMap-backed configuration into Cedar options.
  • Add the optional vMCP config field, synchronize deepcopy and the CRD/API reference, and add focused regression tests.

Fixes #6737

Type of change

  • Bug fix
  • New feature
  • Refactoring (no behavior change)
  • Dependency update
  • Documentation
  • Other (describe):

Test plan

  • Unit tests (task test)
  • E2E tests (task test-e2e)
  • Linting (task lint-fix)
  • Manual testing (describe below)
  • Static checks: gofmt -d on changed Go files, git diff --check, YAML parsing, and CRD schema field checks

The focused command go test ./cmd/thv-operator/pkg/vmcpconfig ./pkg/vmcp/auth/factory did not reach compilation because proxy.golang.org timed out fetching dependencies. No functional/manual test is claimed.

API Compatibility

  • This PR does not break the v1beta1 API, OR the api-break-allowed label is applied and the migration guidance is described above.

Changes

File Change
vMCP authz conversion and factory Forward multi_valued_claims into Cedar options.
vMCP config and deepcopy Add the optional field and copy its slice.
Operator CRD and API reference Document the optional string array.
Focused tests Cover referenced config, ConfigMap config, and Cedar factory propagation.

Does this introduce a user-facing change?

Yes. VirtualMCPServer authorization can use configured multi-valued JWT claims as Cedar set attributes.

Special notes for reviewers

Signed-off-by: lorenzozanee <wyz0707@proton.me>
@codecov

codecov Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.34%. Comparing base (fc57a22) to head (e808fc8).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #6748      +/-   ##
==========================================
+ Coverage   79.30%   79.34%   +0.04%     
==========================================
  Files         802      802              
  Lines       81245    81248       +3     
==========================================
+ Hits        64428    64468      +40     
+ Misses      16812    16775      -37     
  Partials        5        5              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Sanskarzz
Sanskarzz self-requested a review October 4, 2026 09:02
@Sanskarzz

Copy link
Copy Markdown
Collaborator

@lorenzozanee Please fix the CI failures before we proceed with the review. Thanks!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

multi_valued_claims in MCPAuthzConfig is silently ignored for VirtualMCPServer

2 participants