An admin policy helper can no longer chain to another policy helper.
What's wrong with this entry?
Settings returned by an administrator's policy helper executable now have both policyHelper and policyHelpers stripped before validation, with a warning logged for each, so a helper cannot point at a further helper. Previously the key was only discarded after validation.
- The salvage pass over the helper's parsed output now only rescues individual MCP server entries, and keeps a malformed field whole so the strict schema rejects it instead of quietly dropping it.
policyHelper: stripped ${f} from helper output (no recursion), policyHelpers
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.235
Wider environment scrubbing before a policy helper is spawned
Both mention policy helper
-
v2.1.235
A remote-armed policy helper's output is discarded if it is revoked mid-run
Both mention policy helper
-
v2.1.235
Stricter rules for policy helpers arriving over remote settings
Both mention policy helper