fix(local,keychain,api): prefer keychain for secrets, disable stdio MCP by default, surface approval-record failures - #1891
Open
ra-co88 wants to merge 1 commit into
Conversation
…CP by default, surface approval-record failures
ra-co88
force-pushed
the
fix/secrets-provider-defaults
branch
from
August 30, 2026 17:14
bff2366 to
4400942
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Three defaults change in the shipped local config:
dangerouslyAllowStdioMCPdefaults to false — stdio MCP servers are off unless explicitly enabled.Why
Tokens defaulted to the plaintext file store even on platforms with a durable keychain — the weaker storage became the default by registration order, not by decision. Stdio servers spawn local processes; that is not a default a security-conscious distribution should ship. And a swallowed approval-record failure meant a pause that never recorded its approval — invisible breakage.
What changed
describeKeychainAvailability()encodes the platform truth (reachable/unreachable/unsupported) driving the ordering; the config consults it.recordPendingApprovalfailures report through the host's error capture; execution behavior is unchanged (the pause still returns paused, not a 500).Headless/Linux behavior is unchanged: where the keychain probe fails, the file store remains the default.
Test plan
All green against current main.