Skip to content

The MCP server cannot serve security-restricted bugs to users who already have access to them #6582

Description

@joewalker

Context: I asked Claude to get me the details of a security bug. It proposed some bad-for-us suggestions without any good ones. I have access to some security bugs, so I think I should be able to do this in an official way rather than be steered to a hacky and dangerous way.

(Aside: It discovered that it could actually find out a lot about a security bug using moz-phab. It also suggested I install https://github.com/python-bugzilla/python-bugzilla or putting an API key in ~/.config/bugzilla/curlrc)

It seems to me that the best option would be to allow the user to configure an API key or use OAuth or similar to allow the MCP to act as me.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions