-
Notifications
You must be signed in to change notification settings - Fork 41
feat: add readOnly flag #130
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
cc2bec5
e34b873
937edfc
c6a928c
aefccf7
9270c4f
669f044
a2819fb
de8e999
efbf964
17ab204
9612966
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -150,6 +150,7 @@ The MongoDB MCP Server can be configured using multiple methods, with the follow | |
| `connectionString` | MongoDB connection string for direct database connections (optional users may choose to inform it on every tool call) | | ||
| `logPath` | Folder to store logs | | ||
| `disabledTools` | An array of tool names, operation types, and/or categories of tools that will be disabled. | | ||
| `readOnly` | When set to true, only allows read and metadata operation types, disabling create/update/delete operations | | ||
|
||
#### `logPath` | ||
|
||
|
@@ -181,6 +182,19 @@ Operation types: | |
- `read` - Tools that read resources, such as find, aggregate, list clusters, etc. | ||
- `metadata` - Tools that read metadata, such as list databases, list collections, collection schema, etc. | ||
|
||
#### Read-Only Mode | ||
|
||
The `readOnly` configuration option allows you to restrict the MCP server to only use tools with "read" and "metadata" operation types. When enabled, all tools that have "create", "update" or "delete" operation types will not be registered with the server. | ||
|
||
This is useful for scenarios where you want to provide access to MongoDB data for analysis without allowing any modifications to the data or infrastructure. | ||
|
||
You can enable read-only mode using: | ||
|
||
- **Environment variable**: `export MDB_MCP_READ_ONLY=true` | ||
- **Command-line argument**: `--readOnly` | ||
|
||
When read-only mode is active, you'll see a message in the server logs indicating which tools were prevented from registering due to this restriction. | ||
|
||
### Atlas API Access | ||
|
||
To use the Atlas API tools, you'll need to create a service account in MongoDB Atlas: | ||
|
@@ -221,6 +235,7 @@ export MDB_MCP_API_CLIENT_SECRET="your-atlas-client-secret" | |
export MDB_MCP_CONNECTION_STRING="mongodb+srv://username:[email protected]/myDatabase" | ||
|
||
export MDB_MCP_LOG_PATH="/path/to/logs" | ||
|
||
``` | ||
|
||
#### Command-Line Arguments | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -9,7 +9,7 @@ import { UserConfig } from "../config.js"; | |
|
||
export type ToolArgs<Args extends ZodRawShape> = z.objectOutputType<Args, ZodNever>; | ||
|
||
export type OperationType = "metadata" | "read" | "create" | "delete" | "update" | "cluster"; | ||
export type OperationType = "metadata" | "read" | "create" | "delete" | "update"; | ||
export type ToolCategory = "mongodb" | "atlas"; | ||
|
||
export abstract class ToolBase { | ||
|
@@ -109,7 +109,11 @@ export abstract class ToolBase { | |
// Checks if a tool is allowed to run based on the config | ||
protected verifyAllowed(): boolean { | ||
let errorClarification: string | undefined; | ||
if (this.config.disabledTools.includes(this.category)) { | ||
|
||
// Check read-only mode first | ||
if (this.config.readOnly && !["read", "metadata"].includes(this.operationType)) { | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. keeping it like this so we don't alter the configured disallowed tools. i also think adding the virtual "write" would be an extra layer of complexity for users that id' like to avoid. the other thing we could do is remove this check and set the disallowed operation types during initalization, I can do that if you prefer, but I don't have a strong opinion! There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. (cc @nirinchev ) There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think this is totally fine! One thing I noticed is that the SDK recently added the ability to enable/disable tools - modelcontextprotocol/typescript-sdk#247. We should probably look into it post-public-preview and see if it makes sense to use that mechanism instead. Might also be interesting to see if there'd be a way to allow users to dynamically update the server config without restarting it. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. nice, yep, that'd be awesome, I think in VSCode it gives you a checklist so I think it's possible depending on the tool already |
||
errorClarification = `read-only mode is enabled, its operation type, \`${this.operationType}\`,`; | ||
} else if (this.config.disabledTools.includes(this.category)) { | ||
errorClarification = `its category, \`${this.category}\`,`; | ||
} else if (this.config.disabledTools.includes(this.operationType)) { | ||
errorClarification = `its operation type, \`${this.operationType}\`,`; | ||
|
Uh oh!
There was an error while loading. Please reload this page.