fix: correct Rule 15 wording and MCP key access contradiction #117
@@ -278,7 +278,10 @@ def audit(path):
|
|||||||
# Check endpoint validity
|
# Check endpoint validity
|
||||||
if server_name in VALID_MCP_ENDPOINTS:
|
if server_name in VALID_MCP_ENDPOINTS:
|
||||||
expected = VALID_MCP_ENDPOINTS[server_name]
|
expected = VALID_MCP_ENDPOINTS[server_name]
|
||||||
check(url == expected, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}')
|
if url == expected:
|
||||||
|
check(True, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}')
|
||||||
|
else:
|
||||||
|
check(False, 'Rule 15', f'MCP server "{server_name}" URL is incorrect: {url} (expected: {expected})')
|
||||||
else:
|
else:
|
||||||
warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}')
|
warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}')
|
||||||
|
|
||||||
|
|||||||
@@ -243,9 +243,8 @@ MCP server entries in `mcp_servers:` must follow the format shown in the Templat
|
|||||||
- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with agent virtual key
|
- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with agent virtual key
|
||||||
- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"`
|
- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"`
|
||||||
- Confirmed: tools/list returns 200 (MCP endpoint accessible with virtual keys)
|
- Confirmed: tools/list returns 200 (MCP endpoint accessible with virtual keys)
|
||||||
- Note: This contradicts infrastructure-update.prose.md:214 ("only master key has access") —
|
- Note: This differs from infrastructure-update.prose.md:214 ("only master key has access")
|
||||||
the LiteLLM version may have been upgraded since that contract was written
|
— the LiteLLM version was upgraded to support per-key MCP grants
|
||||||
- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models)
|
|
||||||
|
|
||||||
**Key rotation note:**
|
**Key rotation note:**
|
||||||
- MCP headers use literal keys (not env-vars), so they do NOT auto-rotate with the vault
|
- MCP headers use literal keys (not env-vars), so they do NOT auto-rotate with the vault
|
||||||
|
|||||||
Reference in New Issue
Block a user