Repository navigation
fix(mcp): load hosted scrape and search profiles without saving - #494
Conversation
Hosted firecrawl_scrape and firecrawl_search are annotated readOnlyHint: true, but a named browser profile still saved its changes: the API defaults profile.saveChanges to true, and both tools forwarded saveChanges as given. The scrape description also still said browser actions can change the live page, though the hosted schema has no actions. In safe mode, the scrape profile and the search scrapeOptions profile now take only a name, and the server always sends saveChanges: false. A call shaped by an older tool definition that still sends saveChanges loads the profile and saves nothing. Both scrape descriptions say a profile loads without saving. Local mode, crawl and interact keep their existing profile contract, and interact remains the way to save browser state. Co-Authored-By: Claude <noreply@anthropic.com>
There was a problem hiding this comment.
All reported issues were addressed across 4 files
Auto-approved with 1 open P3 issue: Fixes hosted read-only scrape/search so named profiles load without saving by restricting profile to name and forcing saveChanges:false; updates docs/descriptions and adds tests. Bounded bug fix aligning code with documented read-only behavior.
Fix all with cubic | Re-trigger cubic
Co-Authored-By: Claude <noreply@anthropic.com>
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Auto-approved: Fixes hosted scrape/search to load named profiles without saving by forcing saveChanges:false in safe mode, while keeping local mode and firecrawl_interact unchanged. The change is bounded, backward-compatible, and covered by updated tests and docs.
Re-trigger cubic
Why
Hosted
firecrawl_scrapeandfirecrawl_searchare annotatedreadOnlyHint: true, but they can still write state. A named browser profile saves its changes, because the API defaultsprofile.saveChangestotrueand both tools forwardsaveChangesas given. The main scrape description also still says "Browser actions can change the live page when interactive actions are enabled", though the hosted schema has noactions.The ChatGPT plugin scan flags both tools for this: "This tool is marked readOnlyHint: true, but its behavior appears to have a user-visible side effect."
This reinstates the profile guard from the first revision of #472, which was later narrowed to provider terms only. The README already says a hosted profile "loads saved browser state without saving changes to it", so this makes the code match the docs.
Summary
profileand the searchscrapeOptions.profiletake only aname, and the server always sendssaveChanges: false.saveChanges: trueloads the profile and saves nothing. It doesn't error.firecrawl_crawlandfirecrawl_interactkeep their existing profile contract. The README again points tofirecrawl_interactfor saving browser state.storeInCacheis unchanged, because setting it tofalseis the caller's way to opt out of caching.Test Plan
pnpm test: 171/171 pass.tests/mcp-read-only-scrape.test.mjsfails on main and passes here. It checks that the hosted scrape and search profile schemas take onlyname, thatsaveChanges: falseis forwarded even when the caller sendstrue, the descriptions on both surfaces, and that local scrape keepssaveChanges.pnpm exec tsc --noEmit,pnpm exec eslint src/index.tsandgit diff --checkpass.Summary by cubic
Fixes hosted
firecrawl_scrapeandfirecrawl_searchso named browser profiles on the read-only hosted surface load saved state without writing changes back. The API defaultssaveChangesto true, so the server now forcessaveChanges: falsefor these profiles.Behavior
profileschema accepts onlyname; calls shaped by older tool definitions that still sendsaveChangesload the profile but save nothing.firecrawl_crawl, andfirecrawl_interactkeep their existing profile contract;firecrawl_interactremains the way to save browser state.firecrawl_searchnote to the full endpoint.Written for commit c61b02c. Summary will update on new commits.