allowedMcpServers.ts ×7

Frontier kind: Code frontier

unlabeled · c_cbe5f05ae7f7

20 tests · 5080 LOC · 27 files · introduces 0 tests · 80 LOC · 1 file

Introduces — evidence that enters the hierarchy at this concept

Code
7 ranges80 lines · 1 files
Tests
0 tests

Contains — complete concept membership

All code (extent)
733 ranges5080 lines · 27 files · Browse complete extent
All tests (intent)
20 testsBrowse complete intent

Neighbourhood graph

The orange circle is the focus. Violet and green circles are every ancestor and descendant, broader and narrower, at any distance; blue squares and pink diamonds are the introduced files and exact introduced tests of every visible concept, not only the focus's. Arrows point from broader to narrower concepts and bridge only concepts omitted from this view. Undirected links show source or test introduction. Concept and file size follows LOC; exact test nodes use test-count units.

Introduced files, introduced tests, and structurally relevant concept specialization

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the native relationship evidence on this page.

Introduced files, introduced tests, and structurally relevant concept specializationallowedMcpServersService.ts ×1 · 3 introduced LOCallowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService isAllowed matches an installable stdio server by its command|occurrence=1 · 0 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×1 · 2 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×4 · 9 introduced LOCallowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService denylist blocks by remote URL wildcard even without an allowlist|occurrence=1 · 0 introduced LOCallowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService allowlist permits only matching servers|occurrence=1 · 0 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×1 · 1 introduced LOCallowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService denylist blocks a matching server even when it is also allowed|occurrence=1 · 0 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×1 · 1 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×1 · 2 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×1 · 5 introduced LOCallowedMcpServersService…allowedMcpServersService.ts ×7 · 40 introduced LOCallowedMcpServersService…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed deny blocks even when no allowlist is configured|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by local command as an ordered argument list|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×1 · 3 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by remote URL with wildcards, case-insensitively|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched exact URL pattern matches only that URL|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 1 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×5 · 26 introduced LOCallowedMcpServers.ts ×5allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed allowlist permits only matching servers|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×2 · 9 introduced LOCallowedMcpServers.ts ×2allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed deny takes precedence over allow|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed empty allowlist blocks everything as NotAllowed|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed no lists configured allows everything|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by server name|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 1 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers coerces non-arrays to undefined|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers empty array is preserved|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×2 · 2 introduced LOCallowedMcpServers.ts ×2allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched undefined and empty match nothing|occurrence=1 · 0 introduced LOCallowedMcpServers.test|t…allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 2 introduced LOCallowedMcpServers.ts ×1allowedMcpServers.ts ×1 · 1 introduced LOCallowedMcpServers.ts ×1strings.ts ×101 · 542 introduced LOCstrings.ts ×101cancellation.ts ×18 · 90 introduced LOCcancellation.ts ×18event.ts ×93 · 864 introduced LOCevent.ts ×93utils.ts ×3 · 9 introduced LOCutils.ts ×3linkedList.ts ×13 · 44 introduced LOClinkedList.ts ×13lifecycle.ts ×2 · 4 introduced LOClifecycle.ts ×2lifecycle.ts ×4 · 8 introduced LOClifecycle.ts ×4lifecycle.ts ×6 · 16 introduced LOClifecycle.ts ×6lazy.ts ×1 · 2 introduced LOClazy.ts ×1lazy.ts ×3 · 37 introduced LOClazy.ts ×3lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1uint.ts ×2 · 43 introduced LOCuint.ts ×2lifecycle.ts ×1 · 3 introduced LOClifecycle.ts ×1map.ts ×97 · 3334 introduced LOCmap.ts ×97src/vs/base/common/arrays.ts · 949 LOCcommon/arrays.tssrc/vs/base/common/arraysFind.ts · 226 LOCcommon/arraysFind.tssrc/vs/base/common/assert.ts · 91 LOCcommon/assert.tssrc/vs/base/common/cache.ts · 153 LOCcommon/cache.tssrc/vs/base/common/cancellation.ts · 206 LOCcommon/cancellation.tssrc/vs/base/common/charCode.ts · 450 LOCcommon/charCode.tssrc/vs/base/common/collections.ts · 176 LOCcommon/collections.tssrc/vs/base/common/errors.ts · 357 LOCcommon/errors.tssrc/vs/base/common/event.ts · 1964 LOCcommon/event.tssrc/vs/base/common/functional.ts · 32 LOCcommon/functional.tssrc/vs/base/common/iterator.ts · 194 LOCcommon/iterator.tssrc/vs/base/common/lazy.ts · 57 LOCcommon/lazy.tssrc/vs/base/common/lifecycle.ts · 974 LOCcommon/lifecycle.tssrc/vs/base/common/linkedList.ts · 151 LOCcommon/linkedList.tssrc/vs/base/common/map.ts · 1016 LOCcommon/map.tssrc/vs/base/common/marshallingIds.ts · 33 LOCcommon/marshallingIds.tssrc/vs/base/common/path.ts · 1589 LOCcommon/path.tssrc/vs/base/common/platform.ts · 281 LOCcommon/platform.tssrc/vs/base/common/process.ts · 76 LOCcommon/process.tssrc/vs/base/common/stopwatch.ts · 41 LOCcommon/stopwatch.tssrc/vs/base/common/strings.ts · 1413 LOCcommon/strings.tssrc/vs/base/common/types.ts · 410 LOCcommon/types.tssrc/vs/base/common/uint.ts · 59 LOCcommon/uint.tssrc/vs/base/common/uri.ts · 754 LOCcommon/uri.tssrc/vs/base/test/common/utils.ts · 107 LOCcommon/utils.tssrc/vs/nls.ts · 244 LOCvs/nls.tssrc/vs/platform/mcp/common/allowedMcpServers.ts · 145 LOCcommon/allowedMcpServers…src/vs/platform/mcp/common/allowedMcpServersService.ts · 69 LOCcommon/allowedMcpServers…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed allowlist permits only matching servers|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed allowlist permits only matching servers|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed deny blocks even when no allowlist is configured|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed deny blocks even when no allowlist is configured|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed deny takes precedence over allow|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed deny takes precedence over allow|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed empty allowlist blocks everything as NotAllowed|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed empty allowlist blocks everything as NotAllowed|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed no lists configured allows everything|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers checkMcpServerAllowed no lists configured allows everything|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers coerces non-arrays to undefined|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers coerces non-arrays to undefined|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers drops malformed and multi-field matcher entries|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers drops malformed and multi-field matcher entries|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers empty array is preserved|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers getMcpServerMatchers empty array is preserved|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched exact URL pattern matches only that URL|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched exact URL pattern matches only that URL|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by local command as an ordered argument list|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by local command as an ordered argument list|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by remote URL with wildcards, case-insensitively|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by remote URL with wildcards, case-insensitively|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by server name|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched matches by server name|occurrence=1allowedMcpServers.test|t…allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched undefined and empty match nothing|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServers.test|title=AllowedMcpServers isMcpServerMatched undefined and empty match nothing|occurrence=1allowedMcpServers.test|t…allowedMcpServersService.test|title=AllowedMcpServersService allowlist permits only matching servers|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService allowlist permits only matching servers|occurrence=1allowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService allows any server when nothing is configured|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService allows any server when nothing is configured|occurrence=1allowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService blocks all servers when access is None|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService blocks all servers when access is None|occurrence=1allowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService denylist blocks a matching server even when it is also allowed|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService denylist blocks a matching server even when it is also allowed|occurrence=1allowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService denylist blocks by remote URL wildcard even without an allowlist|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService denylist blocks by remote URL wildcard even without an allowlist|occurrence=1allowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService isAllowed matches an installable remote server by its URL|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService isAllowed matches an installable remote server by its URL|occurrence=1allowedMcpServersService…allowedMcpServersService.test|title=AllowedMcpServersService isAllowed matches an installable stdio server by its command|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/mcp/test/common/allowedMcpServersService.test|title=AllowedMcpServersService isAllowed matches an installable stdio server by its command|occurrence=1allowedMcpServersService…Focused concept · allowedMcpServers.ts ×7 · 80 introduced LOCallowedMcpServers.ts ×7

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the native relationship evidence on this page while the interactive map is unavailable.

Native relationship evidence

Every exact file and test below is linked only from the concept that introduces it.

Introduced tests

Every collected test enters the hierarchy at exactly one concept.

No tests are introduced at this concept. Its intent tests are introduced by other concepts.

Introduced code

Every collected source range enters the hierarchy at exactly one concept.

1 file ranked by introduced lines: 80 introduced LOC across 7 ranges. Expand a file to inspect source; the > gutter marks introduced lines.

src/vs/platform/mcp/common/allowedMcpServers.ts 80 introduced LOC · 7 ranges

Open complete file

1 > /*--------------------------------------------------------------------------------------------- allowedMcpServers.ts
2 > * Copyright (c) Microsoft Corporation. All rights reserved.
3 > * Licensed under the MIT License. See License.txt in the project root for license information.
4 > *--------------------------------------------------------------------------------------------*/
5 >
6 > import { equals } from '../../../base/common/arrays.js';
7 > import { escapeRegExpCharacters } from '../../../base/common/strings.js';
8 > import { isObject, isString } from '../../../base/common/types.js';
9 >
10 > /**
11 > * A single entry in the `chat.mcp.allowedServers` allowlist. Identifies an MCP server by exactly
12 > * one strategy: its configured name, a remote server URL pattern (supporting `*` wildcards), or a
13 > * local stdio command invocation (matched as an ordered argument list). Delivered as JSON via user
14 > * settings or enterprise managed settings and validated at match time, so only the field matching
15 > * the intended strategy is meaningful.
16 > */
17 > export interface IMcpServerMatcher {
18 > readonly serverName?: string;
19 > readonly serverUrl?: string;
20 > readonly serverCommand?: readonly string[];
21 > }
22 >
23 > /**
24 > * Normalized identity of an MCP server used for allowlist matching. Both the install-time and the
25 > * runtime enforcement paths reduce their server representation to this shape: `url` is set for
26 > * remote (HTTP/SSE) servers and `command` (the full `[command, ...args]` invocation) for local
27 > * stdio servers.
28 > */
29 > export interface IMcpServerIdentity {
30 > readonly name: string;
31 > readonly url?: string;
32 > readonly command?: readonly string[];
33 > }
34 >
35 > /**
36 > * The result of evaluating an MCP server against the allow/deny lists.
37 > */
38 > export const enum McpServerAllowResult {
39 > /** Permitted: not denied, and either no allowlist is configured or it matches one. */
40 > Allowed,
41 > /** Blocked because it matches a deny entry (deny always wins). */
42 > Denied,
43 > /** Blocked because an allowlist is configured and it matches no entry. */
44 > NotAllowed,
45 > }
46 >
47 > /**
48 > * Coerces a resolved `chat.mcp.allowedServers` / `chat.mcp.deniedServers` configuration value into a
49 > * list of matchers. Returns `undefined` (meaning "not configured") when the value is not an array —
50 > * which is also how an unset setting surfaces (the registered `null` default). Malformed matcher
51 > * entries (non-objects, or entries that do not carry exactly one valid matching field) are dropped
52 > * so a bad payload degrades to "no match" rather than throwing during matching.
53 > */
54 > export function getMcpServerMatchers(value: unknown): readonly IMcpServerMatcher[] | undefined {
55 if (!Array.isArray(value)) {
56 return undefined;
58 return value.filter(isValidMatcher);
59 }
61 function isValidMatcher(entry: unknown): entry is IMcpServerMatcher {
62 if (!isObject(entry)) {
70 return (hasName ? 1 : 0) + (hasUrl ? 1 : 0) + (hasCommand ? 1 : 0) === 1;
71 }
73 > /**
74 > * Whether the server identity matches at least one of the given matchers. A `undefined` or empty
75 > * matcher list matches nothing.
76 > */
77 > export function isMcpServerMatched(matchers: readonly IMcpServerMatcher[] | undefined, identity: IMcpServerIdentity): boolean {
78 return !!matchers && matchers.some(matcher => matchesMatcher(matcher, identity));
79 }
81 > /**
82 > * Evaluates an MCP server against the allow and deny lists. Deny always takes precedence; an unset
83 > * (`undefined`) allowlist imposes no restriction, while a configured allowlist requires a match.
84 > */
85 > export function checkMcpServerAllowed(allowlist: readonly IMcpServerMatcher[] | undefined, denylist: readonly IMcpServerMatcher[] | undefined, identity: IMcpServerIdentity): McpServerAllowResult {
86 if (isMcpServerMatched(denylist, identity)) {
87 return McpServerAllowResult.Denied;
92 return McpServerAllowResult.Allowed;
93 }
95 function matchesMatcher(matcher: IMcpServerMatcher, identity: IMcpServerIdentity): boolean {
96 if (isString(matcher.serverName)) {
105 return false;
106 }
108 > /**
109 > * Matches a URL against a pattern that may contain `*` wildcards. Matching is case-insensitive,
110 > * anchored to the whole string, and every non-wildcard character is matched literally.
111 > *
112 > * Wildcard reach is region-aware so an authority wildcard cannot swallow the path: a `*` inside
113 > * the authority region (scheme + `//` + host/port, i.e. everything before the first `/` of the
114 > * path) matches any run of non-`/` characters, while a `*` in the path/query region matches any
115 > * run of characters. This prevents patterns like `https://*.example.com/*` from matching a URL
116 > * whose real host is untrusted, e.g. `https://evil.test/.example.com/tool`.
117 > */
118 function matchesUrlPattern(pattern: string, url: string): boolean {
119 const regexSource = buildUrlPatternRegexSource(pattern);
124 }
125 }
127 function buildUrlPatternRegexSource(pattern: string): string {
128 // The authority region spans from the start of the pattern up to (but not including) the first