Skip to content

fix(mcp): keep hosted scrape read-only - #472

Merged
Max17190 merged 3 commits into
mainfrom
fix/hosted-scrape-read-only
Oct 1, 2026
Merged

Max17190 merged 3 commits into
mainfrom
fix/hosted-scrape-read-only

Conversation

@Max17190

@Max17190 Max17190 commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Why

Hosted firecrawl_scrape can accept Alexandria provider terms, which changes organization state and prevents the tool from being read-only. Provider terms should be accepted by an organization admin in the dashboard so data retrieval can remain read-only.

Summary

  • Reject every firecrawl terms/* capability except terms/show on all MCP surfaces. Reject an entire mixed batch before sending any execution request.
  • Mark hosted scrape as read-only. Local scrape keeps its existing non-read-only annotation because browser actions remain available.
  • Direct terms recovery and research-agent continuation to dashboard acceptance. Keep terms/show, provider requirements, request IDs, and thread approval contracts intact.
  • Preserve existing browser-profile options, search behavior and annotations, and crawl and interact contracts.
  • Update the related documentation and add regression coverage for the execution boundary. Read-only annotations describe tool behavior; client confirmation policies still apply.

Test Plan

  • pnpm test: 168 tests pass.
  • Hosted full and search endpoints reject direct, normalized, and mixed-batch terms writes before any capability execution request; terms/show remains usable.
  • Hosted scrape is marked read-only and keeps existing browser-profile options. Search annotations and profile options remain unchanged. Hosted browser actions remain unavailable; local scrape keeps browser actions.
  • Terms errors and research-agent metadata direct acceptance to the dashboard while preserving recovery and continuation payloads.
  • pnpm exec tsc --noEmit, ESLint on changed source files, and git diff --check pass.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 10 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread src/index.ts Outdated
@Max17190

Max17190 commented Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

Review context for the current revision: the read-only change applies to hosted firecrawl_scrape. It rejects provider terms writes before capability execution and directs acceptance to the dashboard. Existing browser-profile options, search annotations and behavior, and crawl and interact contracts are preserved.

The full test suite passes, 168/168. TypeScript, ESLint on changed source files, and git diff --check also pass.

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR.

The read-only contract applies to hosted firecrawl_scrape and firecrawl_search page retrieval. firecrawl_crawl remains readOnlyHint: false with its existing writable profile contract; it does not call the read-only handlers. Assess the implementation, terms guard, mixed-batch rejection, profile handling, and dashboard recovery against those tool boundaries.

The focused execution tests pass (5/5).

@Max17190 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Requires human review: The PR changes hosted data-handling and provider-terms authorization policy, including who may accept terms and whether hosted profiles can persist state. Those product and security tradeoffs require human approval.

Re-trigger cubic

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files (changes from recent commits).

Auto-approved with 1 open P3 issue: Makes hosted firecrawl_scrape read-only, blocks terms capabilities except terms/show, and redirects acceptance to the dashboard. Regression tests and documentation cover the restrictions.

Fix all with cubic | Re-trigger cubic

Comment thread README.md Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved with 1 open P3 issue.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Requires human review: The PR changes provider-terms authorization and hosted profile persistence behavior. Dashboard-only consent and whether hosted scrape may forward saveChanges require product and security judgment.

Re-trigger cubic

@Max17190
Max17190 merged commit b8da0b5 into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants