Problem/Motivation
MCP Sentinel currently detects incomplete scope/profile wiring, but released setup paths can leave OAuth enforcement disabled and treat missing scopes as permissive. A governed endpoint can therefore remain available without an applicable active policy or the enforcement wiring needed to apply it. The prior warning-only lineage does not establish a fail-closed product boundary.
Proposed resolution
Make governed operation refuse service when any required source-governance prerequisite is missing:
- MCP Sentinel is unavailable or disabled;
- no active policy/profile applies to the request and target;
- required scope enforcement is disabled or required scopes are absent;
- required write, decision, or evidence enforcement wiring is incomplete.
Local policy remains authoritative and may always deny more than an upstream decision.
Acceptance criteria
- A governed endpoint cannot serve a request without an applicable active policy/profile.
- Missing or empty required scopes deny rather than becoming a no-op.
- Production-oriented setup enables the required enforcement path by default.
- Status reporting names the exact missing prerequisite without substituting a warning for denial.
- Automated tests cover missing module configuration, missing profile, disabled OAuth enforcement,
- Non-governed operation, if retained, is explicit and cannot be selected accidentally by a governed
missing scopes, and incomplete enforcement wiring.
product path.
Related history
This extends the warning-only lineage without reopening or redefining the earlier closed issue.
API changes
Governed requests gain a deterministic fail-closed error when required governance is unavailable.
Comments
Comment #2
jmcerdaPublic working mirror: GitHub #106.
Drupal.org remains the authority for this work item; implementation discussion and pull-request linkage may occur in the mirror.
Comment #7
jmcerdaShipped in 2.4.0. Governed Tool, context, JSON:API, and GraphQL product paths now share one typed readiness decision and refuse service when the required server/bridge/OAuth/audit/Tool registration or the designated Consumer → active owner → role-bound policy wiring is missing. Authenticated GET /drupal-mcp/readiness reports contract_ready plus a stable non-secret reason, and explicitly does not claim policy effectiveness, verified evidence, or overall posture. Ordinary human Drupal traffic stays outside this boundary.
Release: https://www.drupal.org/project/mcp_sentinel/releases/2.4.0
Code: merged on 1.x (GitHub PR #114, tag 2.4.0).