fix(mcp): ignore project allowlist overrides for env expansion

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
YeonGyu-Kim
2026-04-03 17:45:02 +09:00
parent 2b43558349
commit 316d250465
2 changed files with 50 additions and 3 deletions
+47 -2
View File
@@ -1,7 +1,21 @@
import { describe, expect, it } from "bun:test";
import { mergeConfigs, parseConfigPartially } from "./plugin-config";
import { afterEach, describe, expect, it, mock, spyOn } from "bun:test";
import { mkdtempSync, mkdirSync, rmSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import { join } from "node:path"
import * as shared from "./shared"
import { loadPluginConfig, mergeConfigs, parseConfigPartially } from "./plugin-config";
import { OhMyOpenCodeConfigSchema, type OhMyOpenCodeConfig } from "./config";
const tempDirs: string[] = []
afterEach(() => {
mock.restore()
for (const dir of tempDirs.splice(0)) {
rmSync(dir, { recursive: true, force: true })
}
})
describe("mergeConfigs", () => {
describe("categories merging", () => {
// given base config has categories, override has different categories
@@ -277,3 +291,34 @@ describe("parseConfigPartially", () => {
});
});
});
describe("loadPluginConfig", () => {
it("should only honor mcp_env_allowlist from user config", () => {
// given
const rootDir = mkdtempSync(join(tmpdir(), "omo-plugin-config-"))
const userConfigDir = join(rootDir, "user-config")
const projectDir = join(rootDir, "project")
const projectConfigDir = join(projectDir, ".opencode")
tempDirs.push(rootDir)
mkdirSync(userConfigDir, { recursive: true })
mkdirSync(projectConfigDir, { recursive: true })
writeFileSync(
join(userConfigDir, "oh-my-openagent.jsonc"),
JSON.stringify({ mcp_env_allowlist: ["USER_ONLY_TOKEN"] })
)
writeFileSync(
join(projectConfigDir, "oh-my-openagent.jsonc"),
JSON.stringify({ mcp_env_allowlist: ["PROJECT_TOKEN"] })
)
spyOn(shared, "getOpenCodeConfigDir").mockReturnValue(userConfigDir)
// when
const config = loadPluginConfig(projectDir, {})
// then
expect(config.mcp_env_allowlist).toEqual(["USER_ONLY_TOKEN"])
})
})
+3 -1
View File
@@ -210,8 +210,9 @@ export function loadPluginConfig(
}
// Load user config first (base). Parse empty config through Zod to apply field defaults.
const userConfig = loadConfigFromPath(userConfigPath, ctx)
let config: OhMyOpenCodeConfig =
loadConfigFromPath(userConfigPath, ctx) ?? OhMyOpenCodeConfigSchema.parse({});
userConfig ?? OhMyOpenCodeConfigSchema.parse({});
// Override with project config
const projectConfig = loadConfigFromPath(projectConfigPath, ctx);
@@ -221,6 +222,7 @@ export function loadPluginConfig(
config = {
...config,
mcp_env_allowlist: userConfig?.mcp_env_allowlist ?? [],
};
log("Final merged config", {