Skip to content

feat(mcp): add exposeSharedState to the mcp route options - #444

Open
erkamyaman wants to merge 1 commit into
devframes:mainfrom
erkamyaman:feat/mcp-expose-shared-state-filter
Open

erkamyaman wants to merge 1 commit into
devframes:mainfrom
erkamyaman:feat/mcp-expose-shared-state-filter

Conversation

@erkamyaman

Copy link
Copy Markdown
Contributor

Problem

@devframes/hub and the dev server mount the MCP route with exposeSharedState: true hardcoded, and the route options give no way to change it. A host that keeps a state for its own UI but turns an inspector's agent tools off still has that state listed by devframe_state_read and served as a devframe://state/<key> resource. The agent tools are hidden, but the data leaks through the generic state tool.

The MCP adapter already supports boolean | (key) => boolean (createMcpServer, createMcpFetchHandler, and the Next host). Only the hub and the dev server mount could not reach it.

Change

McpRouteOptions gets exposeSharedState?: boolean | ((key: string) => boolean). resolveMcpConfig carries it, and both mounts (initHub and initDevframe) pass config.exposeSharedState ?? true instead of true.

  • true (default, also when omitted): every key is exposed. Nothing changes for existing users.
  • false: no devframe_state_read tool and no devframe://state resources.
  • (key) => boolean: only accepted keys are listed, readable, and served as resources. A rejected key gets the same unknown-key error as a missing one.

The states still exist and work over RPC, so a UI can use them while agents cannot.

initHub({
  mcp: { exposeSharedState: key => key.startsWith('my-tool:public:') },
})

I reused the existing type instead of adding a string[] form, so the option has one shape across createMcpServer, createMcpFetchHandler, the Next host and the route options. A list is a one-line filter.

Docs updated in the MCP adapter page, the hub-initiate guide and the agent-native guide.

Tests

In packages/hub/src/node/__tests__/initiate.test.ts (aggregate route) and packages/devframe/src/adapters/__tests__/initiate.test.ts (dev server route):

  • default exposes every key through devframe_state_read and resources/list
  • a filter hides a key from the key list, from a direct read (unknown-key error) and from the resources
  • false removes the tool and the resources

The filter and false tests failed before the change. The API snapshot for McpRouteOptions is updated.

Verified

pnpm lint && pnpm knip && pnpm test && pnpm typecheck && pnpm build all pass.

The dev server and the hub always passed exposeSharedState: true to the MCP route, so devframe_state_read and the devframe://state resources listed every shared state. The mcp route options now take exposeSharedState (boolean or key filter, default true) and both mounts forward it.
Copilot AI balanced review requested due to automatic review settings October 9, 2026 20:54
@vercel

vercel Bot commented Oct 9, 2026

Copy link
Copy Markdown

@erkamyaman is attempting to deploy a commit to the NuxtLabs Team on Vercel.

A member of the Team first needs to authorize it.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The option is consistently typed, propagated, documented, and covered across both MCP mounting paths.

0 open findings

What changed in this PR

Adds configurable shared-state exposure to MCP routes while preserving existing default behavior.

Changes:

  • Propagates exposeSharedState through devframe and hub MCP configuration.
  • Adds route-level filtering and disablement tests.
  • Documents the new option and updates the API snapshot.
File Description
tests/​__snapshots__/​tsnapi/​devframe/​index.snapshot.d.ts Updates the public API snapshot.
packages/​hub/​src/​node/​initiate.ts Passes exposure policy to aggregate MCP.
packages/​hub/​src/​node/​__tests__/​initiate.test.ts Tests default, filtered, and disabled exposure.
packages/​devframe/​src/​types/​devframe.ts Defines the new route option.
packages/​devframe/​src/​adapters/​initiate.ts Applies the option during MCP mounting.
packages/​devframe/​src/​adapters/​_shared.ts Preserves the option during configuration resolution.
packages/​devframe/​src/​adapters/​__tests__/​initiate.test.ts Tests filtering on dev server routes.
docs/​content/​2.adapters/​7.mcp.md Documents route exposure controls.
docs/​content/​1.guide/​18.hub-initiate.md Documents hub configuration.
docs/​content/​1.guide/​15.agent-native.md Updates shared-state guidance.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants