Repository navigation
feat(mcp): add exposeSharedState to the mcp route options - #444
Open
erkamyaman wants to merge 1 commit into
Open
erkamyaman wants to merge 1 commit into
erkamyaman wants to merge 1 commit into
Conversation
The dev server and the hub always passed exposeSharedState: true to the MCP route, so devframe_state_read and the devframe://state resources listed every shared state. The mcp route options now take exposeSharedState (boolean or key filter, default true) and both mounts forward it.
|
@erkamyaman is attempting to deploy a commit to the NuxtLabs Team on Vercel. A member of the Team first needs to authorize it. |
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The option is consistently typed, propagated, documented, and covered across both MCP mounting paths.
0 open findings
What changed in this PR
Adds configurable shared-state exposure to MCP routes while preserving existing default behavior.
Changes:
- Propagates
exposeSharedStatethrough devframe and hub MCP configuration. - Adds route-level filtering and disablement tests.
- Documents the new option and updates the API snapshot.
| File | Description |
|---|---|
tests/__snapshots__/tsnapi/devframe/index.snapshot.d.ts |
Updates the public API snapshot. |
packages/hub/src/node/initiate.ts |
Passes exposure policy to aggregate MCP. |
packages/hub/src/node/__tests__/initiate.test.ts |
Tests default, filtered, and disabled exposure. |
packages/devframe/src/types/devframe.ts |
Defines the new route option. |
packages/devframe/src/adapters/initiate.ts |
Applies the option during MCP mounting. |
packages/devframe/src/adapters/_shared.ts |
Preserves the option during configuration resolution. |
packages/devframe/src/adapters/__tests__/initiate.test.ts |
Tests filtering on dev server routes. |
docs/content/2.adapters/7.mcp.md |
Documents route exposure controls. |
docs/content/1.guide/18.hub-initiate.md |
Documents hub configuration. |
docs/content/1.guide/15.agent-native.md |
Updates shared-state guidance. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
@devframes/huband the dev server mount the MCP route withexposeSharedState: truehardcoded, and the route options give no way to change it. A host that keeps a state for its own UI but turns an inspector's agent tools off still has that state listed bydevframe_state_readand served as adevframe://state/<key>resource. The agent tools are hidden, but the data leaks through the generic state tool.The MCP adapter already supports
boolean | (key) => boolean(createMcpServer,createMcpFetchHandler, and the Next host). Only the hub and the dev server mount could not reach it.Change
McpRouteOptionsgetsexposeSharedState?: boolean | ((key: string) => boolean).resolveMcpConfigcarries it, and both mounts (initHubandinitDevframe) passconfig.exposeSharedState ?? trueinstead oftrue.true(default, also when omitted): every key is exposed. Nothing changes for existing users.false: nodevframe_state_readtool and nodevframe://stateresources.(key) => boolean: only accepted keys are listed, readable, and served as resources. A rejected key gets the same unknown-key error as a missing one.The states still exist and work over RPC, so a UI can use them while agents cannot.
I reused the existing type instead of adding a
string[]form, so the option has one shape acrosscreateMcpServer,createMcpFetchHandler, the Next host and the route options. A list is a one-line filter.Docs updated in the MCP adapter page, the hub-initiate guide and the agent-native guide.
Tests
In
packages/hub/src/node/__tests__/initiate.test.ts(aggregate route) andpackages/devframe/src/adapters/__tests__/initiate.test.ts(dev server route):devframe_state_readandresources/listfalseremoves the tool and the resourcesThe filter and
falsetests failed before the change. The API snapshot forMcpRouteOptionsis updated.Verified
pnpm lint && pnpm knip && pnpm test && pnpm typecheck && pnpm buildall pass.