{"record":{"id":"dabd737296a64610","repo":"affaan-m/ECC","slug":"the-user-memory-scope-is-disabled-for-this-mcp-server","errorCode":null,"errorMessage":"The user memory scope is disabled for this MCP server.","messagePattern":"The user memory scope is disabled for this MCP server\\.","errorType":"exception","errorClass":"JsonRpcError","httpStatus":null,"severity":"error","filePath":"scripts/memory-mcp.mjs","lineNumber":191,"sourceCode":"\nfunction resolveServiceSecurity(options = {}) {\n  const env = isRecord(options.env) ? options.env : process.env;\n  const harness = options.harness ?? env.ECC_MEMORY_HARNESS;\n  if (typeof harness !== 'string' || !SLUG_REGEXP.test(harness)) {\n    throw new Error(\n      'ECC_MEMORY_HARNESS must identify this MCP server with a lowercase harness slug.'\n    );\n  }\n  return Object.freeze({\n    harness,\n    allowUserScope: options.allowUserScope ?? env.ECC_MEMORY_ALLOW_USER_SCOPE === '1',\n  });\n}\n\nfunction assertScopesAuthorized(scopes, security) {\n  const requestedScopes = scopes || DEFAULT_RECALL_SCOPES;\n  if (!security.allowUserScope && requestedScopes.includes('user')) {\n    throw new JsonRpcError(\n      -32602,\n      'The user memory scope is disabled for this MCP server.'\n    );\n  }\n  return requestedScopes;\n}\n\nfunction textResult(payload) {\n  const text = JSON.stringify(payload, null, 2);\n  if (Buffer.byteLength(text, 'utf8') > MAX_RESPONSE_BYTES) {\n    throw new JsonRpcError(-32001, 'Memory tool response exceeds the bounded output limit.');\n  }\n  return {\n    content: [{\n      type: 'text',\n      text,\n    }],\n  };","sourceCodeStart":173,"sourceCodeEnd":209,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/memory-mcp.mjs#L173-L209","documentation":"The memory server can be started with user-scope access disabled (ECC_MEMORY_ALLOW_USER_SCOPE !== '1'). When a recall request asks for the 'user' scope (explicitly or via DEFAULT_RECALL_SCOPES), assertScopesAuthorized rejects it with JsonRpcError -32602 to keep user-private memories inaccessible in that deployment.","triggerScenarios":"A tools/call to a memory recall tool with arguments.scopes containing 'user' (or omitting scopes so DEFAULT_RECALL_SCOPES applies, which includes 'user') while security.allowUserScope is false.","commonSituations":"Client default recall scopes include 'user' but the server was launched without ECC_MEMORY_ALLOW_USER_SCOPE=1; a multi-harness setup intentionally restricts user scope; config drift between client expectations and server startup env.","solutions":["Set ECC_MEMORY_ALLOW_USER_SCOPE=1 in the MCP server env if user-scope memory is intended","Or pass explicit scopes without 'user' (e.g. [\"project\",\"shared\"]) in the tool call","Update the client's default recall scopes to exclude 'user'"],"exampleFix":"// before\n{ \"name\": \"memory-recall\", \"arguments\": { \"query\": \"auth design\" } }\n// after\n{ \"name\": \"memory-recall\", \"arguments\": { \"query\": \"auth design\", \"scopes\": [\"project\", \"shared\"] } }","handlingStrategy":"type-guard","validationCode":"const scopes = args.scopes || ['project','shared']; if (scopes.includes('user') && process.env.ECC_MEMORY_ALLOW_USER_SCOPE !== '1') throw new Error('user scope disabled on this server');","typeGuard":"const userScopeAllowed = (security, scopes) => security.allowUserScope || !(scopes || ['user']).includes('user');","tryCatchPattern":"try { const res = await client.callTool({ name: 'memory-recall', arguments }); } catch (e) { if (e.code === -32602 && /user memory scope is disabled/.test(e.message)) { arguments.scopes = ['project','shared']; return client.callTool({ name: 'memory-recall', arguments }); } throw e; }","preventionTips":["Know the server's scope policy before issuing recalls; omit 'user' unless explicitly enabled","Set ECC_MEMORY_ALLOW_USER_SCOPE=1 only when user-private memories should be reachable","Configure the client's default recall scopes to match the server's allowlist"],"tags":["mcp","permissions","scope"],"backgroundTag":"permission-denied","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}