Skip to content

[Security][P1] Block suspended users in MCP token auth path - #556

Merged
2witstudios merged 1 commit into
masterfrom
codex/issue-548-mcp-suspension-enforcement
Feb 12, 2026
Merged

2witstudios merged 1 commit into
masterfrom
codex/issue-548-mcp-suspension-enforcement

Conversation

@2witstudios

@2witstudios 2witstudios commented Feb 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Enforce suspension checks in MCP token validation.
  • Deny suspended users in validateMCPToken.
  • Log suspended-user MCP auth attempts as security events.
  • Revoke the presented MCP token (revokedAt) on first suspended-user detection.
  • Add auth middleware tests proving suspended MCP tokens are denied and revoked.
  • Document the chosen behavior in security posture notes.

Behavior Decision

Previously issued MCP tokens are revoked on first post-suspension use, then denied on all subsequent requests.

Files Changed

  • apps/web/src/lib/auth/index.ts
  • apps/web/src/lib/auth/__tests__/auth-middleware.test.ts
  • docs/security/2026-02-11-security-posture-assessment.md

Testing

  • pnpm --filter web test -- src/lib/auth/__tests__/auth-middleware.test.ts
  • Result: target suite passed (src/lib/auth/__tests__/auth-middleware.test.ts), but the command also executed additional unrelated suites in this environment and failed on pre-existing issues:
    • DB connectivity for src/lib/auth/__tests__/admin-role-version.test.ts (EPERM connecting to 127.0.0.1:5432 / ::1:5432)
    • Unrelated assertions in src/app/api/ai/settings/__tests__/route.test.ts expecting 201 but receiving 400

Closes #548

Summary by CodeRabbit

  • Bug Fixes

    • MCP token validation now checks for suspended user accounts and revokes tokens on first detection, with security events logged for audit and monitoring purposes.
  • Documentation

    • Security assessment documentation updated to reflect remediation of the MCP token suspension enforcement gap, including details on new token revocation behavior.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Feb 12, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

This PR implements security enforcement for suspended users in the MCP token authentication path. It adds suspension checking to MCP token validation, logs security events for suspended user access attempts, revokes tokens on first detection, and includes test coverage for the new behavior.

Changes

Cohort / File(s) Summary
Auth Implementation
apps/web/src/lib/auth/index.ts
Adds logSecurityEvent import and suspendedAt field loading. When validating MCP tokens, checks if the associated user is suspended; if so, logs a security event with reason mcp_token_user_suspended, revokes the token, and denies access by returning null.
Auth Tests
apps/web/src/lib/auth/__tests__/auth-middleware.test.ts
Mocks logSecurityEvent from server utilities and adds test cases for suspended MCP token scenarios: validateMCPToken revokes suspended users' tokens with logged security events, and authenticateMCPRequest returns error for suspended users.
Security Documentation
docs/security/2026-02-11-security-posture-assessment.md
Updates P1 security claim to reflect remediation as of February 12, 2026. Documents that MCP token validation now checks user suspension state and revokes tokens on detection. Marks suspension enforcement remediation as completed in priority list.

Sequence Diagram

sequenceDiagram
    participant Client
    participant validateMCP as validateMCPToken
    participant DB as Database
    participant Logger as logSecurityEvent
    participant Server as Auth Server

    Client->>validateMCP: Request with MCP token
    validateMCP->>DB: Load user data + suspendedAt
    DB-->>validateMCP: User record returned
    
    alt User is suspended
        validateMCP->>Logger: Log security event<br/>(mcp_token_user_suspended)
        Logger-->>validateMCP: Event recorded
        validateMCP->>DB: Update token revokedAt
        DB-->>validateMCP: Token revoked
        validateMCP->>Server: Return null (deny access)
        Server-->>Client: 401 Unauthorized
    else User is active
        validateMCP->>Server: Validation successful
        Server-->>Client: Grant access
    end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Poem

🐰 Suspended users hop no more,
Their MCP tokens revoked at the door,
Security events log each attack,
No sneaky access, no coming back! 🔐

🚥 Pre-merge checks | ✅ 4 | ❌ 1
❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main security change: blocking suspended users in the MCP token authentication path.
Linked Issues check ✅ Passed The PR implements all acceptance criteria from #548: validateMCPToken now denies suspended users, logs security events, includes tests, and documents token revocation behavior.
Out of Scope Changes check ✅ Passed All changes are directly aligned with issue #548 requirements: suspension enforcement in MCP validation, security event logging, tests, and documentation.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch codex/issue-548-mcp-suspension-enforcement

No actionable comments were generated in the recent review. 🎉


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@2witstudios
2witstudios merged commit 4372d80 into master Feb 12, 2026
10 checks passed
@2witstudios
2witstudios deleted the codex/issue-548-mcp-suspension-enforcement branch March 11, 2026 03:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security][P1] Block suspended users in MCP token auth path

1 participant