Commit a71bb31
committed
fix(@angular/cli): enforce MCP roots in get_best_practices tool
getVersionSpecificBestPractices() resolves an npm package (and reads a
file path declared in that package's package.json) starting from a
caller-supplied workspacePath, without checking it against the client's
declared MCP roots. Every other workspace-path-consuming MCP tool
(run_target, devserver_start/stop/wait_for_build) validates this through
resolveWorkspaceAndProject()'s isAllowedWorkspacePath() check; this tool
never did.
Export isAllowedWorkspacePath() from workspace-utils.ts and call it in
getVersionSpecificBestPractices() before resolving anything, falling back
to the bundled guide when the path is outside the allowed roots, matching
this file's existing fallback behavior for every other failure case.1 parent 9c282d3 commit a71bb31
2 files changed
Lines changed: 19 additions & 3 deletions
Lines changed: 18 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
| |||
86 | 87 | | |
87 | 88 | | |
88 | 89 | | |
| 90 | + | |
89 | 91 | | |
90 | 92 | | |
91 | 93 | | |
92 | 94 | | |
93 | 95 | | |
94 | 96 | | |
| 97 | + | |
95 | 98 | | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
96 | 108 | | |
97 | 109 | | |
98 | 110 | | |
| |||
175 | 187 | | |
176 | 188 | | |
177 | 189 | | |
178 | | - | |
| 190 | + | |
179 | 191 | | |
180 | 192 | | |
181 | 193 | | |
| |||
184 | 196 | | |
185 | 197 | | |
186 | 198 | | |
187 | | - | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
188 | 204 | | |
189 | 205 | | |
190 | 206 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
110 | 110 | | |
111 | 111 | | |
112 | 112 | | |
113 | | - | |
| 113 | + | |
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
| |||
0 commit comments