Filesystem permission pre-flight for credential-bearing configs (0600/0700) + one-click fix (P1) #93

Closed
opened 2026-08-12 02:34:28 -04:00 by the_og · 0 comments
Owner

Why (P1 — validation)

ssh-mcp refuses to start if its config is group/world readable (mode & 0o077 → throws, requiring dir 0700 / file 0600). A GUI user has no idea what chmod 600 means — they get a dead server. Generalise: any config file that carries credentials should be permission-checked.

What

  • Check the mode of a server's credential-bearing config/sidecar.
  • Explain in plain language what's wrong.
  • Offer a one-click "fix permissions" button (chmod 600 file / 700 dir).

Acceptance

Pure-core mode check + fix helper (skip/degrade gracefully on Windows where POSIX modes don't apply), unit-tested (fixture: config at 0644 → block + explain + offer fix). Minimal GUI surface. Depends on ServerSpec/sidecar paths (#91) to know which file to check.

Part of the ssh-mcp field-notes epic.

## Why (P1 — validation) `ssh-mcp` refuses to start if its config is group/world readable (`mode & 0o077` → throws, requiring dir `0700` / file `0600`). A GUI user has no idea what `chmod 600` means — they get a dead server. Generalise: **any** config file that carries credentials should be permission-checked. ## What - Check the mode of a server's credential-bearing config/sidecar. - Explain in plain language what's wrong. - Offer a one-click "fix permissions" button (chmod 600 file / 700 dir). ## Acceptance Pure-core mode check + fix helper (skip/degrade gracefully on Windows where POSIX modes don't apply), unit-tested (fixture: config at 0644 → block + explain + offer fix). Minimal GUI surface. Depends on ServerSpec/sidecar paths (#91) to know which file to check. Part of the ssh-mcp field-notes epic.
the_og added the P1 label 2026-08-12 02:34:28 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: the_og/better-claude-config#93