mcp: implement autorun, rework trust #257564
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This adds an on-by-default MCP autorun setting, which will start any new
or changed MCP servers when a chat request is sent. When the setting is
on, we will no longer show the infamous 'refresh' indicator. We also
now respond to changes in existing mcp.jsons server definitions as a
signal that we need to refresh the tools.
This also means we need a new take on trust. We don't want a
prompt-injected model to be able to add an MCP server in the workspace
that's silently run on the next chat request. For user level settings,
there's no change -- these are outside the workspace and editing by the
agent is generally disallowed.
For workspace-level servers, users are asked to trust the server the
first time they run it or whenever its definition changes. If they
decline, we won't prompt them again, but they can still manually choose
to run it later on. We also nicely group servers together to avoid a
flurry of prompts. This is what that looks like. In the case of multiple
servers, users can pick ones they wish to trust, or not.
This gets most of the way there but I need to do more testing so I will
not merge this yet.
Closes #248010