Restrict workspace writes to admins (#1919)
* Restrict workspace writes to admins Co-authored-by: Max schwenk <maschwenk@gmail.com> * Fix self-host MCP request forwarding * Update file secrets durability invariant * Fix versioned cloud credentials * Fix self-host live-role scenario * Update cloud principal contract tests * Remove stray audit history assertions * Fix no-auth credential classification * fix(mcp): project legacy stdio as no-auth * fix(graphql): classify empty auth templates as no-auth * fix(sdk): defer no-auth classification to engine * fix(sdk): ignore placements on no-auth methods * test(mcp): make reconcile cleanup infallible * test(graphql): use empty no-auth timeout input * test(e2e): remove no-auth placeholder credentials * test(e2e): use empty no-auth credential shapes * Project legacy stdio credentials truthfully * Reject invalid no-auth placements * Reject MCP no-auth credential input * Propagate MCP test cleanup failures * Honor projected legacy stdio credentials * Deduplicate invalid auth method warnings --------- Co-authored-by: Max schwenk <maschwenk@gmail.com>
R
Rhys Sullivan committed
caa03919a8f2a5c82ed13bc4ea9060e964af3a79
Parent: 9c67fd5
Committed by GitHub <noreply@github.com>
on 9/2/2026, 10:40:28 AM