Skip to content
Merged
Show file tree
Hide file tree
Changes from 5 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions packages/cli/src/commands/mcp/list.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ import { createTransport, debugLogger } from '@google/gemini-cli-core';
import { Client } from '@modelcontextprotocol/sdk/client/index.js';
import { ExtensionStorage } from '../../config/extensions/storage.js';
import { ExtensionManager } from '../../config/extension-manager.js';
import { McpServerEnablementManager } from '../../config/mcp/index.js';

vi.mock('../../config/settings.js', async (importOriginal) => {
const actual =
Expand All @@ -45,6 +46,8 @@ vi.mock('@google/gemini-cli-core', async (importOriginal) => {
CONNECTED: 'CONNECTED',
CONNECTING: 'CONNECTING',
DISCONNECTED: 'DISCONNECTED',
BLOCKED: 'BLOCKED',
DISABLED: 'DISABLED',
},
Storage: Object.assign(
vi.fn().mockImplementation((_cwd: string) => ({
Expand All @@ -54,6 +57,7 @@ vi.mock('@google/gemini-cli-core', async (importOriginal) => {
})),
{
getGlobalSettingsPath: () => '/tmp/gemini/settings.json',
getGlobalGeminiDir: () => '/tmp/gemini',
},
),
GEMINI_DIR: '.gemini',
Expand Down Expand Up @@ -96,6 +100,12 @@ describe('mcp list command', () => {
beforeEach(() => {
vi.resetAllMocks();
vi.spyOn(debugLogger, 'log').mockImplementation(() => {});
McpServerEnablementManager.resetInstance();
// Use a mock for isFileEnabled to avoid reading real files
vi.spyOn(
McpServerEnablementManager.prototype,
'isFileEnabled',
).mockResolvedValue(true);

mockTransport = { close: vi.fn() };
mockClient = {
Expand Down Expand Up @@ -304,4 +314,29 @@ describe('mcp list command', () => {
),
);
});

it('should display blocked status for servers in excluded list', async () => {
const defaultMergedSettings = mergeSettings({}, {}, {}, {}, true);
mockedLoadSettings.mockReturnValue({
merged: {
...defaultMergedSettings,
mcp: {
excluded: ['blocked-server'],
},
mcpServers: {
'blocked-server': { command: '/test/server' },
},
},
isTrusted: true,
});

await listMcpServers();

expect(debugLogger.log).toHaveBeenCalledWith(
expect.stringContaining(
'blocked-server: /test/server (stdio) - Blocked',
),
);
expect(mockedCreateTransport).not.toHaveBeenCalled();
});
});
48 changes: 42 additions & 6 deletions packages/cli/src/commands/mcp/list.ts
Original file line number Diff line number Diff line change
Expand Up @@ -6,17 +6,25 @@

// File for 'gemini mcp list' command
import type { CommandModule } from 'yargs';
import { type MergedSettings, loadSettings } from '../../config/settings.js';
import type { MCPServerConfig } from '@google/gemini-cli-core';
import {
type MergedSettings,
loadSettings,
type LoadedSettings,
} from '../../config/settings.js';
import {
MCPServerStatus,
createTransport,
debugLogger,
applyAdminAllowlist,
getAdminBlockedMcpServersMessage,
} from '@google/gemini-cli-core';
import type { MCPServerConfig } from '@google/gemini-cli-core';
import { Client } from '@modelcontextprotocol/sdk/client/index.js';
import { ExtensionManager } from '../../config/extension-manager.js';
import {
canLoadServer,
McpServerEnablementManager,
} from '../../config/mcp/index.js';
import { requestConsentNonInteractive } from '../../config/extensions/consent.js';
import { promptForSetting } from '../../config/extensions/extensionSettings.js';
import { exitCli } from '../utils.js';
Expand Down Expand Up @@ -61,9 +69,8 @@ export async function getMcpServersFromConfig(
async function testMCPConnection(
serverName: string,
config: MCPServerConfig,
settings: LoadedSettings,
): Promise<MCPServerStatus> {
const settings = loadSettings();

// SECURITY: Only test connection if workspace is trusted or if it's a remote server.
// stdio servers execute local commands and must never run in untrusted workspaces.
const isStdio = !!config.command;
Expand Down Expand Up @@ -135,15 +142,36 @@ async function testMCPConnection(
async function getServerStatus(
serverName: string,
server: MCPServerConfig,
settings: LoadedSettings,
): Promise<MCPServerStatus> {
const mcpEnablementManager = McpServerEnablementManager.getInstance();
const loadResult = await canLoadServer(serverName, {
adminMcpEnabled: settings.merged.admin?.mcp?.enabled ?? true,
allowedList: settings.merged.mcp?.allowed,
excludedList: settings.merged.mcp?.excluded,
enablement: mcpEnablementManager.getEnablementCallbacks(),
});

if (!loadResult.allowed) {
if (
loadResult.blockType === 'admin' ||
loadResult.blockType === 'allowlist' ||
loadResult.blockType === 'excludelist'
) {
return MCPServerStatus.BLOCKED;
}
return MCPServerStatus.DISABLED;
}

// Test all server types by attempting actual connection
return testMCPConnection(serverName, server);
return testMCPConnection(serverName, server, settings);
}

export async function listMcpServers(settings?: MergedSettings): Promise<void> {
const { mcpServers, blockedServerNames } =
await getMcpServersFromConfig(settings);
const serverNames = Object.keys(mcpServers);
const loadedSettings = loadSettings();

if (blockedServerNames.length > 0) {
const message = getAdminBlockedMcpServersMessage(
Expand All @@ -165,7 +193,7 @@ export async function listMcpServers(settings?: MergedSettings): Promise<void> {
for (const serverName of serverNames) {
const server = mcpServers[serverName];

const status = await getServerStatus(serverName, server);
const status = await getServerStatus(serverName, server, loadedSettings);

let statusIndicator = '';
let statusText = '';
Expand All @@ -178,6 +206,14 @@ export async function listMcpServers(settings?: MergedSettings): Promise<void> {
statusIndicator = chalk.yellow('…');
statusText = 'Connecting';
break;
case MCPServerStatus.BLOCKED:
statusIndicator = chalk.red('⛔');
statusText = 'Blocked';
break;
case MCPServerStatus.DISABLED:
statusIndicator = chalk.gray('○');
statusText = 'Disabled';
break;
case MCPServerStatus.DISCONNECTED:
default:
statusIndicator = chalk.red('✗');
Expand Down
4 changes: 4 additions & 0 deletions packages/core/src/tools/mcp-client.ts
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,10 @@ export enum MCPServerStatus {
CONNECTING = 'connecting',
/** Server is connected and ready to use */
CONNECTED = 'connected',
/** Server is blocked via configuration and cannot be used */
BLOCKED = 'blocked',
/** Server is disabled and cannot be used */
DISABLED = 'disabled',
}

/**
Expand Down