mcp: add readonly guard to config add/remove handlers#3708
Conversation
The deploy and delete handlers check s.readonly and refuse to act in readonly mode. However, the six config mutation handlers (envs add/remove, labels add/remove, volumes add/remove) execute unconditionally, allowing an AI agent to modify func.yaml even in readonly mode. Add the same readonly guard to all six config mutation handlers. Signed-off-by: elvandlie@gmail.com <elvandlie@gmail.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Elvand-Lie The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @Elvand-Lie. Thanks for your PR. I'm waiting for a knative member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3708 +/- ##
==========================================
- Coverage 56.91% 56.29% -0.63%
==========================================
Files 181 181
Lines 20928 20952 +24
==========================================
- Hits 11912 11794 -118
- Misses 7808 7991 +183
+ Partials 1208 1167 -41
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Signed-off-by: elvandlie@gmail.com <elvandlie@gmail.com>
The
deployanddeletehandlers checks.readonlyand refuse to act in readonly mode. However, the six config mutation handlers (configEnvsAdd,configEnvsRemove,configLabelsAdd,configLabelsRemove,configVolumesAdd,configVolumesRemove) execute unconditionally, allowing an AI agent to modifyfunc.yamleven when readonly mode is active.Add the same readonly guard to all six config mutation handlers, consistent with deploy and delete.
Changes
s.readonlyguard toconfigEnvsAddHandlerandconfigEnvsRemoveHandlers.readonlyguard toconfigLabelsAddHandlerandconfigLabelsRemoveHandlers.readonlyguard toconfigVolumesAddHandlerandconfigVolumesRemoveHandlerFixes #3704
Release Note
Docs