docs(adr): ADR 0027 — launch scope is the credential boundary; dir= is never a token selector #92

Merged
hexajon merged 1 commit from refs/pull/92/head into main 2026-07-15 15:12:58 +00:00
hexajon commented 2026-07-15 15:12:53 +00:00 (Migrated from codeberg.org)

Summary

Records the 2026-07-15 owner ruling as ADR 0027: the MCP server's launch scope is its credential scope, and dir= selects a repository, never a token. Exactly two enumerated crossings, both bound to the target checkout's own origin remote — contribute (the existing ADR 0019 worktree→finish flow, now named explicitly) and report (cross-repo issue filing: create/comment plus dedup reads, owner_repo pinned to the clone's origin, typed tool only). The raw API passthrough never resolves foreign credentials (why #87 is closed). Rationale recorded for future devs/agents: blast radius, scope coherence, git/API-plane symmetry, and the perishability of bug context that makes the report crossing necessary. Adds the index row.

Enforcement and the parity pin remain #90; the constrained issue-filing implementation is #59; the unauthed-launch-scope remedies are #88 (connect-time warning) and #89 (in-session OAuth login). Refs #90, #59, #88, #89.

## Summary Records the 2026-07-15 owner ruling as ADR 0027: the MCP server's launch scope is its credential scope, and dir= selects a repository, never a token. Exactly two enumerated crossings, both bound to the target checkout's own origin remote — contribute (the existing ADR 0019 worktree→finish flow, now named explicitly) and report (cross-repo issue filing: create/comment plus dedup reads, owner_repo pinned to the clone's origin, typed tool only). The raw API passthrough never resolves foreign credentials (why #87 is closed). Rationale recorded for future devs/agents: blast radius, scope coherence, git/API-plane symmetry, and the perishability of bug context that makes the report crossing necessary. Adds the index row. Enforcement and the parity pin remain #90; the constrained issue-filing implementation is #59; the unauthed-launch-scope remedies are #88 (connect-time warning) and #89 (in-session OAuth login). Refs #90, #59, #88, #89.
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
sixfold-space/madtea!92
No description provided.