Require authentication for accessing MCP tools

This commit is contained in:
Jan Böhmer 2026-07-25 21:35:27 +02:00
parent 8b484d5776
commit 32669b2cc0
3 changed files with 14 additions and 0 deletions

View file

@ -73,3 +73,6 @@ security:
- { path: "^/api", allow_if: 'is_granted("@api.access_api") and is_authenticated()' }
# Restrict access to KICAD to users, which has API access permission
- { path: "^/kicad-api", allow_if: 'is_granted("@api.access_api") and is_authenticated()' }
# Restrict MCP access to users, which has the MCP access permission
- { path: "^/mcp", allow_if: 'is_granted("@api.use_mcp") and is_authenticated()' }

View file

@ -381,7 +381,12 @@ perms: # Here comes a list with all Permission names (they have a perm_[name] co
access_api:
label: "perm.api.access_api"
apiTokenRole: ROLE_API_READ_ONLY
use_mcp:
label: "perm.api.use_mcp"
alsoSet: [ 'access_api' ]
apiTokenRole: ROLE_API_READ_ONLY
manage_tokens:
label: "perm.api.manage_tokens"
alsoSet: ['access_api']
apiTokenRole: ROLE_API_FULL

View file

@ -13793,5 +13793,11 @@ Buerklin-API Authentication server:
<target>Warning: Changing values here can break the info retrieval mechanism! You should use the "update from info provider" functionality whenever possible.</target>
</segment>
</unit>
<unit id="bNrxe9i" name="perm.api.use_mcp">
<segment>
<source>perm.api.use_mcp</source>
<target>Use MCP tools (for AI agents)</target>
</segment>
</unit>
</file>
</xliff>