Problem/Motivation

After making mcp_admin a non-is_admin enumerated break-glass role, grants still attached the role if a site widened it with extra permissions (including approve mcp sentinel operations). The five-permission list is only a security boundary if it is enforced at elevation time.

Proposed resolution

  • Single source of truth: McpBreakGlassManager::ALLOWED_PERMISSIONS (must match optional role YAML).
  • grant() refuses any permission outside that allowlist; proper subset still grants.
  • Kernel tests and docs.

Remaining tasks

  • Implementation in progress on GitHub (PR linked from the companion issue).
  • Release notes under Unreleased / next tag.

Related

GitHub companion: Wilkes-Liberty/mcp_sentinel#87. Related status-report drift: #88 / d.o companion once filed.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Version: 1.x-dev » 2.2.0
Status: Active » Fixed

Fixed in 2.2.0.

GitHub companion #87 closed as completed; shipped via PR #90 (grant-time allowlist seal).

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

jmcerda’s picture

Status: Fixed » Closed (fixed)

Closed (fixed): grant-time permission allowlist seal shipped in 2.2.0 (GitHub #87). Grants refuse when mcp_admin holds permissions outside ALLOWED_PERMISSIONS.

https://www.drupal.org/project/mcp_sentinel/releases/2.2.0
https://github.com/Wilkes-Liberty/mcp_sentinel/issues/87