Problem/Motivation

MCP Sentinel currently detects incomplete scope/profile wiring, but released setup paths can leave OAuth enforcement disabled and treat missing scopes as permissive. A governed endpoint can therefore remain available without an applicable active policy or the enforcement wiring needed to apply it. The prior warning-only lineage does not establish a fail-closed product boundary.

Proposed resolution

Make governed operation refuse service when any required source-governance prerequisite is missing:

  • MCP Sentinel is unavailable or disabled;
  • no active policy/profile applies to the request and target;
  • required scope enforcement is disabled or required scopes are absent;
  • required write, decision, or evidence enforcement wiring is incomplete.

Local policy remains authoritative and may always deny more than an upstream decision.

Acceptance criteria

  • A governed endpoint cannot serve a request without an applicable active policy/profile.
  • Missing or empty required scopes deny rather than becoming a no-op.
  • Production-oriented setup enables the required enforcement path by default.
  • Status reporting names the exact missing prerequisite without substituting a warning for denial.
  • Automated tests cover missing module configuration, missing profile, disabled OAuth enforcement,
  • missing scopes, and incomplete enforcement wiring.

  • Non-governed operation, if retained, is explicit and cannot be selected accidentally by a governed
  • product path.

Related history

This extends the warning-only lineage without reopening or redefining the earlier closed issue.

API changes

Governed requests gain a deterministic fail-closed error when required governance is unavailable.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Public working mirror: GitHub #106.

Drupal.org remains the authority for this work item; implementation discussion and pull-request linkage may occur in the mirror.

  • jmcerda committed 78cfa82d on fix/3616543-fail-closed-readiness
    Issue #3616543: Add cspell project words for Packet A CI
    
    Unblock the...

  • 93884dfe committed on 1.x
    Issue #3616543: Fail closed when source governance is unavailable (#114...

  • jmcerda committed 78cfa82d on 1.x
    Issue #3616543: Add cspell project words for Packet A CI
    
    Unblock the...

  • jmcerda committed 8676517a on 1.x
    Issue #3616543: Fail closed when governance is unavailable
    
    Co-authored-...
jmcerda’s picture

Status: Active » Fixed

Shipped in 2.4.0. Governed Tool, context, JSON:API, and GraphQL product paths now share one typed readiness decision and refuse service when the required server/bridge/OAuth/audit/Tool registration or the designated Consumer → active owner → role-bound policy wiring is missing. Authenticated GET /drupal-mcp/readiness reports contract_ready plus a stable non-secret reason, and explicitly does not claim policy effectiveness, verified evidence, or overall posture. Ordinary human Drupal traffic stays outside this boundary.

Release: https://www.drupal.org/project/mcp_sentinel/releases/2.4.0
Code: merged on 1.x (GitHub PR #114, tag 2.4.0).

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

  • jmcerda committed a5115465 on 1.x
    Issue #3616543: Document the readiness probe on the project page
    

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.