SIGN IN SIGN UP

Restrict workspace writes to admins (#1919)

* Restrict workspace writes to admins

Co-authored-by: Max schwenk <maschwenk@gmail.com>

* Fix self-host MCP request forwarding

* Update file secrets durability invariant

* Fix versioned cloud credentials

* Fix self-host live-role scenario

* Update cloud principal contract tests

* Remove stray audit history assertions

* Fix no-auth credential classification

* fix(mcp): project legacy stdio as no-auth

* fix(graphql): classify empty auth templates as no-auth

* fix(sdk): defer no-auth classification to engine

* fix(sdk): ignore placements on no-auth methods

* test(mcp): make reconcile cleanup infallible

* test(graphql): use empty no-auth timeout input

* test(e2e): remove no-auth placeholder credentials

* test(e2e): use empty no-auth credential shapes

* Project legacy stdio credentials truthfully

* Reject invalid no-auth placements

* Reject MCP no-auth credential input

* Propagate MCP test cleanup failures

* Honor projected legacy stdio credentials

* Deduplicate invalid auth method warnings

---------

Co-authored-by: Max schwenk <maschwenk@gmail.com>
R
Rhys Sullivan committed
caa03919a8f2a5c82ed13bc4ea9060e964af3a79
Parent: 9c67fd5
Committed by GitHub <noreply@github.com> on 9/2/2026, 10:40:28 AM