{"record":{"id":"17a5647d825c78ab","repo":"Hmbown/CodeWhale","slug":"source-is-disabled-or-its-workspace-is-untrusted","errorCode":null,"errorMessage":"Source is disabled or its workspace is untrusted","messagePattern":"Source is disabled or its workspace is untrusted","errorType":"validation","errorClass":"anyhow","httpStatus":null,"severity":"error","filePath":"crates/tui/src/mcp/external_import.rs","lineNumber":684,"sourceCode":") -> anyhow::Result<ImportReceipt> {\n    anyhow::ensure!(\n        matches!(decision, ImportDecision::Approve | ImportDecision::Decline),\n        \"Choose approve or decline\"\n    );\n    let (candidate, revision) = super::mutate_config(context.mcp_path, Some(revision), |config| {\n        let (candidates, _) = context.discover();\n        let candidate = candidates\n            .into_iter()\n            .find(|candidate| candidate_id(candidate) == id)\n            .ok_or_else(|| {\n                anyhow::anyhow!(\"Reviewed source is unavailable; refresh the import preview\")\n            })?;\n        anyhow::ensure!(\n            candidate.content_hash == hash,\n            \"Source changed; refresh the import preview\"\n        );\n        if decision == ImportDecision::Approve {\n            anyhow::ensure!(\n                !source_blocked(context, &candidate),\n                \"Source is disabled or its workspace is untrusted\"\n            );\n            anyhow::ensure!(\n                !context.merged()?.servers.contains_key(&candidate.name)\n                    && !config.servers.contains_key(&candidate.name),\n                \"A managed, project or plugin connector already uses this name\"\n            );\n            let mut server = candidate.server.clone();\n            server.enabled = false;\n            server.disabled = true;\n            config.servers.insert(candidate.name.clone(), server);\n        }\n        Ok(candidate)\n    })?;\n    let decisions = HashMap::from([(candidate.name.clone(), decision)]);\n    let now = std::time::SystemTime::now()\n        .duration_since(std::time::UNIX_EPOCH)","sourceCodeStart":666,"sourceCodeEnd":702,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/mcp/external_import.rs#L666-L702","documentation":"On approval, codewhale re-checks `source_blocked(context, &candidate)` just before committing. If the source is disabled or its workspace is not trusted at apply time, the import is refused — the preview-time trust state is re-verified to avoid importing from a source that became untrusted.","triggerScenarios":"Approving an import where, at apply time, the candidate's source is marked disabled in the merged view, or the workspace containing the source file is not in the trusted-workspace set (e.g. trust was revoked or the file moved to an untrusted directory).","commonSituations":"User declined a workspace-trust prompt earlier; the source config lives in a new project directory that has not been marked trusted; an admin policy disabled the source after the preview.","solutions":["Trust the workspace the source lives in (respond to the trust prompt or add it to trusted workspaces), then re-apply.","Re-enable the disabled source if it should be imported.","Re-run `/mcp import` to regenerate a preview that reflects the current trust/disabled state."],"exampleFix":"// before (untrusted workspace)\ncodewhale mcp import approve <token>\n// after\ncodewhale workspace trust /path/to/project\ncodewhale mcp import approve <token>","handlingStrategy":"validation","validationCode":"let (candidates, _) = context.discover();\nif let Some(c) = candidates.iter().find(|c| candidate_id(c) == id) {\n    if source_blocked(&context, c) {\n        eprintln!(\"source is blocked: enable it or trust the workspace first\");\n    }\n}","typeGuard":null,"tryCatchPattern":"match apply_reviewed_import(...) {\n    Err(e) if e.to_string().contains(\"disabled or its workspace is untrusted\") => {\n        // trust the workspace / re-enable source, then retry\n    }\n    other => other?,\n}","preventionTips":["Trust project workspaces before generating import previews","Check source enabled state before approving","Review workspace trust settings when source files move between projects"],"tags":["security","trust","validation"],"backgroundTag":"insufficient-permissions","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}