Repository navigation
fix(mcp): keep hosted scrape read-only - #472
Conversation
There was a problem hiding this comment.
All reported issues were addressed across 10 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
|
Review context for the current revision: the read-only change applies to hosted firecrawl_scrape. It rejects provider terms writes before capability execution and directs acceptance to the dashboard. Existing browser-profile options, search annotations and behavior, and crawl and interact contracts are preserved. The full test suite passes, 168/168. TypeScript, ESLint on changed source files, and git diff --check also pass. |
@Max17190 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 10 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Requires human review: The PR changes hosted data-handling and provider-terms authorization policy, including who may accept terms and whether hosted profiles can persist state. Those product and security tradeoffs require human approval.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 4 files (changes from recent commits).
Auto-approved with 1 open P3 issue: Makes hosted firecrawl_scrape read-only, blocks terms capabilities except terms/show, and redirects acceptance to the dashboard. Regression tests and documentation cover the restrictions.
Fix all with cubic | Re-trigger cubic
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Requires human review: The PR changes provider-terms authorization and hosted profile persistence behavior. Dashboard-only consent and whether hosted scrape may forward saveChanges require product and security judgment.
Re-trigger cubic
Why
Hosted
firecrawl_scrapecan accept Alexandria provider terms, which changes organization state and prevents the tool from being read-only. Provider terms should be accepted by an organization admin in the dashboard so data retrieval can remain read-only.Summary
firecrawlterms/*capability exceptterms/showon all MCP surfaces. Reject an entire mixed batch before sending any execution request.terms/show, provider requirements, request IDs, and thread approval contracts intact.Test Plan
pnpm test: 168 tests pass.terms/showremains usable.pnpm exec tsc --noEmit, ESLint on changed source files, andgit diff --checkpass.