feat(mcp): make search-only read tools reachable, and put the payload ceiling into reverse (#1976)

* feat(api): surface the registry's worked examples in the OpenAPI spec and generated skill

EndpointDefinition.example is required and every one of the 125 v1 endpoints
populates example.response, but generateOpenApiSpec() never emitted it. The
examples reached only the docs markdown builder, so /api/v1/openapi.json
carried none and the generated skills/accounted-api had zero json blocks in
all 12 reference files: every agent reading the spec or installing the skill
got schemas with no concrete body.

Emit example on the application/json media types (request body and 200
response) and teach the portable renderOperationMd to print it as a fenced
json block. 178 worked examples now reach the skill. SKILL.md is unchanged:
the examples land in the on-demand reference files, not the entry file.

Attached to JSON media types only, so a multipart body and a binary
application/pdf response do not advertise an example they cannot send.

Adds the one missing example.request (currency-revaluation) so the new
exhaustive coverage assertions hold.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(api): emit Retry-After on a v1 429 so the documented contract is real

The published accounted-api skill has told agents to honor Retry-After on a
429 since it shipped, but no /api/v1 route ever sent one: the wrapper's auth
failure path early-returns through v1ErrorResponseFromCode, whose finalize()
set only X-Request-Id and Gnubok-Version. Unattended clients had nothing to
pace against and had to back off blindly.

60 seconds is an exact upper bound rather than a guess: the rate limiter is a
fixed one-minute tumbling window per key row and the limited branch does not
slide it. The value moves into an exported constant next to that limiter, so
the MCP server's hardcoded '60' now reads from the same place.

Also corrects the withApiV1 doc comment, which claimed step 8 stamps
X-RateLimit-Limit. It never did.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* test(mcp): guard the tools/list payload for the namespace new installs get

The payload ratchet only ever serialized the gnubok_* projection. The
accounted_* projection is inherently larger (every tool reference gains 3
chars, ~209 tokens across the default catalog) and CLAUDE.md points new MCP
installs at exactly that namespace, so the payload a new user's client
receives was never measured. It had already drifted ~90 tokens past the
63.4K ceiling while the guarded number sat comfortably under it.

Measure both and assert on the larger. The ceiling moves to 63.6K to cover
the real worst case; this buys no new catalog surface. A second test pins the
direction of the delta so Math.max cannot silently stop describing reality.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* feat(mcp): make search-only read tools reachable, and put the payload ceiling into reverse

DECISIONS.md records on 2026-08-26 that gnubok_reconcile_match had to be
promoted back into the default catalog because "a search-only tool is
uncallable on Claude.ai". That is a client-side limit, not a server one: the
tools/call dispatcher has always resolved names against the whole tools array,
and isDefaultCatalogTool gates only what tools/list shows. So
catalogVisibility: 'search' was unusable as a payload lever for reads, and the
ceiling could only ever go up.

gnubok_call_tool gives such a client one visible name to forward through. It
is a rewrite in the dispatcher rather than a forwarding wrapper: {tool,
arguments} is rebound to the inner tool BEFORE resolution, so the scope check,
unknown-argument guard, company routing, test-key write block, staging _meta
and telemetry all apply to the real target instead of being bypassed. Reads
only; a write must be named directly so its approval contract stays visible.

Alongside it, gnubok_get_agent_briefing's outputSchema drops 7743 to 4565
chars. Four sub-schemas whose interiors were documentation rather than
contract are condensed to a permissive object plus a fuller description;
agent-briefing.test.ts already pins their runtime shape, so nothing is left
unguarded.

Net on the guarded (accounted) projection: 63 491 to 62 942 tokens, with the
new tool included. The ceiling moves 63.6K DOWN to 63.1K, the first tightening
in that ledger, and the note now says to demote a read before proposing a bump.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-08-27 17:45:40 +02:00
committed by GitHub
co-authored by Claude Opus 5 Jakob Wennberg
parent 3447da027a
commit 12ce693eb6
5 changed files with 406 additions and 136 deletions
@@ -0,0 +1,251 @@
/**
* Tests for the gnubok_call_tool bridge in the MCP dispatcher.
*
* Server-side, every tool has always been callable: `tools/call` resolves the
* name against the whole `tools` array, and `isDefaultCatalogTool` gates only
* what tools/list SHOWS. The failure was purely client-side, and DECISIONS.md
* records the consequence on 2026-08-26: `gnubok_reconcile_match` had to be
* promoted back into the default catalog because "a search-only tool is
* uncallable on Claude.ai".
*
* The bridge gives such a client one visible name to forward through. It is
* implemented as a REWRITE ahead of tool resolution rather than as a wrapper
* that calls the inner tool's execute(), because everything between resolution
* and execute (scope check, unknown-argument guard, company routing, the
* test-key write block, staging _meta, telemetry) must apply to the real
* target. These tests exist to prove it does.
*/
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { eventBus } from '@/lib/events/bus'
vi.mock('@/lib/supabase/server', () => ({
createClient: vi.fn(),
createServiceClient: vi.fn(),
}))
vi.mock('@/lib/auth/api-keys', async (importOriginal) => {
const actual = await importOriginal<typeof import('@/lib/auth/api-keys')>()
const chain: unknown = new Proxy(
{},
{
get(_t, prop) {
if (prop === 'then') {
return (resolve: (v: unknown) => void) => resolve({ data: null, error: null })
}
return () => chain
},
},
)
const membershipChain: unknown = new Proxy(
{},
{
get(_t, prop) {
if (prop === 'then') {
return (resolve: (v: unknown) => void) =>
resolve({
data: { company_id: '11111111-1111-4111-8111-111111111111', role: 'owner' },
error: null,
})
}
return () => membershipChain
},
},
)
return {
...actual,
extractBearerToken: vi.fn().mockReturnValue('test-token'),
validateApiKey: vi.fn().mockResolvedValue({
userId: 'user-1',
companyId: '11111111-1111-4111-8111-111111111111',
scopes: ['transactions:read', 'reports:read', 'pending_operations:approve'],
apiKeyId: 'key-1',
apiKeyName: 'Live Key',
mode: 'live',
}),
createServiceClientNoCookies: vi.fn(() => ({
from: (table: string) => (table === 'company_members' ? membershipChain : chain),
rpc: () => chain,
})),
}
})
vi.mock('@/lib/entitlements/has-capability', async (importOriginal) => {
const actual = await importOriginal<typeof import('@/lib/entitlements/has-capability')>()
return { ...actual, hasCapability: vi.fn().mockResolvedValue(true) }
})
import { handleMcpRequest, tools, isDefaultCatalogTool } from '../server'
import { validateApiKey, extractBearerToken } from '@/lib/auth/api-keys'
function mcpToolCall(name: string, args: Record<string, unknown> = {}): Request {
return new Request('http://localhost:3000/api/extensions/ext/mcp-server/mcp', {
method: 'POST',
headers: { 'Content-Type': 'application/json', Authorization: 'Bearer test-token' },
body: JSON.stringify({
jsonrpc: '2.0',
id: 1,
method: 'tools/call',
params: { name, arguments: args },
}),
})
}
interface ToolCalledEvent {
tool: string
success: boolean
isError: boolean
errorKind: string | null
latencyMs: number
}
function captureNextToolCalled(): Promise<ToolCalledEvent> {
return new Promise((resolve) => {
const off = eventBus.on('mcp.tool_called', (payload) => {
off()
resolve(payload as unknown as ToolCalledEvent)
})
})
}
async function parsedToolResult(
response: Response,
): Promise<{ isError: boolean; payload: Record<string, unknown> }> {
const json = await response.json()
const result = json.result as { isError?: boolean; content: { text: string }[] }
return { isError: result.isError === true, payload: JSON.parse(result.content[0].text) }
}
const bridgeTool = tools.find((t) => t.name === 'gnubok_call_tool')!
describe('gnubok_call_tool registration', () => {
it('is in the default catalog and read-only', () => {
expect(bridgeTool).toBeDefined()
expect(isDefaultCatalogTool(bridgeTool)).toBe(true)
expect(bridgeTool.annotations.readOnlyHint).toBe(true)
})
it('has no direct implementation: the dispatcher rewrite is load-bearing', async () => {
// If this ever resolves instead of throwing, the rewrite was removed and
// every bridged call would have skipped the read-only check above it.
await expect(
bridgeTool.execute({}, 'company-id', 'user-id', {} as never, { type: 'api_key' }),
).rejects.toThrow(/no direct implementation/i)
})
})
describe('gnubok_call_tool bridge', () => {
beforeEach(() => {
vi.clearAllMocks()
eventBus.clear()
})
it('forwards to the inner tool and attributes telemetry to it, not to the wrapper', async () => {
const eventPromise = captureNextToolCalled()
await handleMcpRequest(mcpToolCall('gnubok_call_tool', { tool: 'gnubok_list_skills' }))
const event = await eventPromise
expect(event.tool).toBe('gnubok_list_skills')
expect(event.errorKind).not.toBe('bridge_refused')
})
it('reaches a search-only read tool, which is the whole point', async () => {
const searchOnlyRead = tools.find(
(t) => !isDefaultCatalogTool(t) && t.annotations.readOnlyHint === true,
)!
expect(searchOnlyRead).toBeDefined()
const eventPromise = captureNextToolCalled()
await handleMcpRequest(mcpToolCall('gnubok_call_tool', { tool: searchOnlyRead.name }))
const event = await eventPromise
expect(event.tool).toBe(searchOnlyRead.name)
expect(event.errorKind).not.toBe('bridge_refused')
})
it('refuses a write target so the staging and approval contract stays visible', async () => {
const eventPromise = captureNextToolCalled()
const response = await handleMcpRequest(
mcpToolCall('gnubok_call_tool', {
tool: 'gnubok_approve_pending_operation',
arguments: { operation_id: 'op-1' },
}),
)
const { isError, payload } = await parsedToolResult(response)
expect(isError).toBe(true)
expect(JSON.stringify(payload)).toContain('gnubok_approve_pending_operation')
const event = await eventPromise
expect(event.errorKind).toBe('bridge_refused')
// Refused before execute(): nothing is staged, nothing is approved.
expect(event.latencyMs).toBe(0)
})
it('refuses a call with no tool name', async () => {
const eventPromise = captureNextToolCalled()
const response = await handleMcpRequest(mcpToolCall('gnubok_call_tool', {}))
const { isError } = await parsedToolResult(response)
expect(isError).toBe(true)
const event = await eventPromise
expect(event.errorKind).toBe('bridge_refused')
})
it('enforces the INNER tool scope, not the wrapper (which has none)', async () => {
vi.mocked(validateApiKey).mockResolvedValueOnce({
userId: 'user-1',
companyId: '11111111-1111-4111-8111-111111111111',
// Deliberately omits transactions:read, which the inner tool requires.
scopes: ['reports:read'],
apiKeyId: 'key-1',
apiKeyName: 'Narrow Key',
mode: 'live',
} as Awaited<ReturnType<typeof validateApiKey>>)
const eventPromise = captureNextToolCalled()
const response = await handleMcpRequest(
mcpToolCall('gnubok_call_tool', { tool: 'gnubok_list_cash_accounts' }),
)
const { isError } = await parsedToolResult(response)
expect(isError).toBe(true)
const event = await eventPromise
expect(event.errorKind).toBe('scope_denied')
expect(event.tool).toBe('gnubok_list_cash_accounts')
})
it('applies the unknown-argument guard to the inner tool', async () => {
const response = await handleMcpRequest(
mcpToolCall('gnubok_call_tool', {
tool: 'gnubok_list_skills',
arguments: { nonexistent_parameter: 1 },
}),
)
const { isError, payload } = await parsedToolResult(response)
expect(isError).toBe(true)
expect(JSON.stringify(payload)).toContain('nonexistent_parameter')
})
it('is closed to anonymous callers: the pre-auth gate keys on the outer name', async () => {
// gnubok_call_tool is deliberately absent from PUBLIC_TOOLS, so an
// unauthenticated client cannot use it as a lever at all. Nothing is lost:
// all three public tools are in the default catalog already.
vi.mocked(extractBearerToken).mockReturnValueOnce(null)
const response = await handleMcpRequest(
mcpToolCall('gnubok_call_tool', { tool: 'gnubok_list_skills' }),
)
expect(response.status).toBe(401)
})
it('reports an unknown inner tool through the normal unknown-tool path', async () => {
const response = await handleMcpRequest(
mcpToolCall('gnubok_call_tool', { tool: 'gnubok_not_a_real_tool' }),
)
const json = (await response.json()) as { error?: { message?: string } }
expect(json.error?.message).toContain('gnubok_not_a_real_tool')
})
})
@@ -270,10 +270,20 @@ describe('tools/list payload size guard', () => {
// nothing tested it, so this bump buys no new catalog surface. It
// re-points an existing ceiling at the payload new installs actually
// receive; the gnubok projection still sits ~320 tokens under it.
// Long-term answer to growth is leaning harder on gnubok_search_tools: if this
// fires again, prefer trimming descriptions or making a tool opt-in via search
// before bumping further.
expect(approxTokens).toBeLessThan(63_600)
// * 63.6K DOWN to 63.1K, the first tightening in this ledger. Two
// changes, net -549 tokens on the guarded (accounted) projection:
// gnubok_get_agent_briefing's outputSchema went 7,743 to 4,565 chars
// by condensing four sub-schemas whose interiors were documentation
// rather than contract (ledger_context, dimensions,
// skatteverket_connection, recommended_tools: agent-briefing.test.ts
// pins their RUNTIME shape, so nothing was left unguarded), against
// +~245 for the new gnubok_call_tool.
// Long-term answer to growth is no longer a ceiling bump. gnubok_call_tool
// makes `catalogVisibility: 'search'` usable for READ tools on hosts that
// can only invoke what tools/list showed them, which is the constraint that
// forced gnubok_reconcile_match back into the default catalog on
// 2026-08-26. Demote a read to search-only before proposing a bump.
expect(approxTokens).toBeLessThan(63_100)
})
it('keeps the accounted_* namespace as the measured worst case', () => {
+137 -131
View File
@@ -2863,6 +2863,64 @@ function projectMcpPayload<T>(value: T, namespace: McpToolNamespace): T {
// ── Tools ────────────────────────────────────────────────────
export const tools: McpTool[] = [
{
// The bridge that makes `catalogVisibility: 'search'` usable on hosts that
// can only invoke what tools/list showed them.
//
// Server-side, every tool has always been callable: the tools/call
// dispatcher resolves the name against the whole `tools` array and
// `isDefaultCatalogTool` gates only what tools/list SHOWS. The failure was
// purely client-side (Claude.ai cannot name a tool it never saw), which is
// why search-only tools shipped unreachable there.
//
// This tool is never executed. `tools/call` rewrites a
// gnubok_call_tool({tool, arguments}) request into a direct call on the
// inner tool BEFORE resolution, so scope checks, the unknown-argument
// guard, company routing, the staging contract and telemetry all apply to
// the real target rather than to a wrapper that would have bypassed them.
name: 'gnubok_call_tool',
title: 'Call a Read Tool by Name',
description:
'Invoke any read-only tool by name, including ones absent from tools/list. Find the name with gnubok_search_tools first. Writes are refused: call a write tool directly so its approval contract stays visible.',
inputSchema: {
type: 'object',
additionalProperties: false,
properties: {
tool: {
type: 'string',
description: 'Canonical name of the read-only tool to invoke, e.g. "gnubok_get_reconciliation_status".',
},
arguments: {
type: 'object',
description: "Arguments for that tool, validated against its own inputSchema. Omit for a tool that takes none.",
},
},
required: ['tool'],
},
// The response is whatever the inner tool returns, so no fixed shape can
// be declared. Every tool must carry an object outputSchema, and an open
// object is the only honest one here.
outputSchema: {
type: 'object',
additionalProperties: true,
description: 'The inner tool\'s own result, unchanged.',
},
annotations: {
readOnlyHint: true,
destructiveHint: false,
idempotentHint: true,
openWorldHint: false,
},
async execute() {
// Unreachable: the dispatcher rewrites the call before resolution. If
// this ever throws, the rewrite was removed and every call would have
// silently skipped the read-only check.
throw codedError(
'VALIDATION_ERROR',
'gnubok_call_tool is resolved by the dispatcher and has no direct implementation.',
)
},
},
{
name: 'gnubok_search_tools',
title: 'Search MCP Tools',
@@ -4403,127 +4461,19 @@ export const tools: McpTool[] = [
},
dimensions: {
type: 'object',
additionalProperties: false,
description: 'Dimension registry snapshot (kostnadsställe/projekt). OMITTED when the company has none registered; presence means lines can be tagged via the dims bag on gnubok_create_voucher.',
properties: {
enabled: { type: 'boolean', description: 'When true, dims-bag values are validated against the registry.' },
dimensions: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: {
sie_dim_no: { type: 'number' },
name: { type: 'string' },
active_value_count: { type: 'number' },
required_on_accounts: {
type: 'array',
description: 'BAS accounts with an active required-rule: postings there are refused without a value for this dimension.',
items: { type: 'string' },
},
default_on_accounts: {
type: 'array',
description: 'BAS accounts where a default/fixed rule auto-applies a value at draft creation.',
items: { type: 'string' },
},
top_values: {
type: 'array',
description: 'Up to 10 active values; full list via gnubok_list_dimension_values.',
items: {
type: 'object',
additionalProperties: false,
properties: {
code: { type: 'string' },
name: { type: 'string' },
},
required: ['code', 'name'],
},
},
},
required: ['sie_dim_no', 'name', 'active_value_count', 'required_on_accounts', 'default_on_accounts', 'top_values'],
},
},
},
required: ['enabled', 'dimensions'],
description:
'Dimension registry snapshot (kostnadsställe/projekt): an enabled flag plus the registered dimensions with their codes, counts and top values. OMITTED when the company has none registered; presence means lines can be tagged via the dims bag on gnubok_create_voucher, and enabled=true means dims-bag values are validated against the registry.',
},
ledger_context: {
type: 'object',
additionalProperties: false,
description: 'Digest of how this company books things: top-5 counterparty + top-3 supplier patterns. Full picture (account usage, explicit rules, VAT profile, conventions) in the Accounted://ledger/context resource. Evidence is historical frequency, NOT permission to auto-book: weigh seen count AND recency, never a ratio alone. OMITTED when not computable.',
properties: {
resource_uri: { type: 'string', description: 'URI of the full ledger-context resource.' },
window_from: { type: 'string', description: 'Start of the rolling stats window (ISO date).' },
posted_entries_window: { type: 'number', description: 'Posted journal entries in the window. Low = thin evidence: treat patterns as weak.' },
top_counterparty_patterns: {
type: 'array',
description: 'Most frequent booked bank-feed counterparties with dominant booking. evidence = seen N in 12m, M agreed, last booked; below 0.7 agreement excluded.',
items: {
type: 'object',
additionalProperties: false,
properties: {
counterparty: { type: 'string' },
dominant_category: { type: 'string' },
dominant_account_number: { type: ['string', 'null'] },
evidence: {
type: 'object',
additionalProperties: false,
properties: {
seen_12m: { type: 'number' },
agree: { type: 'number' },
last_booked: { type: 'string' },
},
required: ['seen_12m', 'agree', 'last_booked'],
},
},
required: ['counterparty', 'dominant_category', 'dominant_account_number', 'evidence'],
},
},
top_supplier_patterns: {
type: 'array',
description: 'Most invoiced suppliers (AP side) with dominant expense account and VAT treatment. Same evidence semantics.',
items: {
type: 'object',
additionalProperties: false,
properties: {
supplier: { type: 'string' },
dominant_account_number: { type: 'string' },
vat_treatment: { type: ['string', 'null'] },
evidence: {
type: 'object',
additionalProperties: false,
properties: {
seen_12m: { type: 'number' },
agree: { type: 'number' },
last_booked: { type: 'string' },
},
required: ['seen_12m', 'agree', 'last_booked'],
},
},
required: ['supplier', 'dominant_account_number', 'vat_treatment', 'evidence'],
},
},
},
required: ['resource_uri', 'window_from', 'posted_entries_window', 'top_counterparty_patterns', 'top_supplier_patterns'],
description:
'Digest of how this company books things: top-5 counterparty + top-3 supplier patterns, each with an evidence block (seen_12m, agree, share, last_booked) and the rolling window it was computed over. Evidence is historical frequency, NOT permission to auto-book: weigh seen count AND recency, never a ratio alone. OMITTED when not computable. Field-by-field detail, plus account usage, explicit rules, VAT profile and conventions, is in the Accounted://ledger/context resource.',
},
recommended_tools: {
type: 'array',
items: { type: 'object' },
description:
'Per-workflow tool loadouts, ordered by call sequence. Deferred-loading harnesses batch-load a whole cluster in one call (ToolSearch select:a,b,c). Static; validated against the registry.',
items: {
type: 'object',
additionalProperties: false,
properties: {
workflow: { type: 'string', description: 'Stable workflow key.' },
description: { type: 'string' },
skill: { type: 'string', description: 'Slug for gnubok_load_skill (full playbook).' },
tools: {
type: 'array',
items: { type: 'string' },
description: 'Exact tool names, ordered.',
},
},
required: ['workflow', 'description', 'skill', 'tools'],
},
'Per-workflow tool loadouts, ordered by call sequence: each entry names a workflow, describes it, and lists the exact registry tools it needs. Deferred-loading harnesses batch-load a whole cluster in one call (ToolSearch select:a,b,c). Static; validated against the registry at module load.',
},
feedback_channel: {
type: 'object',
@@ -4538,19 +4488,8 @@ export const tools: McpTool[] = [
},
skatteverket_connection: {
type: 'object',
additionalProperties: false,
description:
'Present only when a Skatteverket connection exists. needs_reconsent: only a person can fix it (BankID under Inställningar → Skatteverket); warn the user before starting SKV work.',
properties: {
status: { type: 'string', enum: ['active', 'needs_reconsent'] },
source: { type: 'string', enum: ['user', 'system'] },
connected_at: {
type: ['string', 'null'],
description: 'Personal sessions last ~65 min from this time; absent for system (ombud) connections.',
},
message: { type: 'string' },
},
required: ['status', 'source'],
'Present only when a Skatteverket connection exists. Carries status ("active" or "needs_reconsent") and the grant detail behind it. needs_reconsent: only a person can fix it (BankID under Inställningar → Skatteverket); warn the user before starting SKV work.',
},
},
required: ['company', 'user_name', 'profile_summary', 'atoms', 'memory', 'recommended_tools'],
@@ -19075,7 +19014,7 @@ function emitToolCallTelemetry(payload: {
success: boolean
isError: boolean
errorCode: string | null
errorKind: 'execution' | 'scope_denied' | 'capability_denied' | 'company_access_denied' | 'unknown_tool' | 'test_key_write_blocked' | null
errorKind: 'execution' | 'scope_denied' | 'capability_denied' | 'company_access_denied' | 'unknown_tool' | 'test_key_write_blocked' | 'bridge_refused' | null
errorMessage: string | null
requestId: string | number | null
userId: string
@@ -19543,7 +19482,7 @@ export async function handleMcpRequest(request: Request): Promise<Response> {
]
: []),
'Discovery:',
'• tools/list returns common tool schemas. Call gnubok_search_tools(query="…") for specialized tools: it ranks all capabilities; pass detail="name"|"summary"|"full" to control payload size.',
'• tools/list returns common tool schemas. Call gnubok_search_tools(query="…") for specialized tools: it ranks all capabilities; pass detail="name"|"summary"|"full" to control payload size. If your client cannot invoke a tool that is not in tools/list, reach any READ tool through gnubok_call_tool({tool, arguments}); writes must be named directly.',
'• gnubok_get_agent_briefing returns recommended_tools: ordered per-workflow tool loadouts (categorize_month, close_period, invoice_run, vat_declaration, payroll_month). If your harness defers tool loading, batch-load a whole workflow in one call (e.g. Claude Code ToolSearch select:a,b,c) instead of searching cluster by cluster.',
`• This connection can work with every non-archived company the API-key user belongs to. Call gnubok_list_companies to discover company_id values. Omit company_id to use the API key default (${companyId ?? 'none yet: this account has no company. Create it with gnubok_create_company (preview first, then confirm=true); the "onboarding" skill walks the whole setup'}); when selecting another company, repeat company_id on every company-data call, including approval.`,
'• MCP resources use the API key default company. For a selected non-default company, call gnubok_get_agent_briefing with company_id instead of relying on Accounted://company/current or other company-data resources.',
@@ -19653,18 +19592,85 @@ export async function handleMcpRequest(request: Request): Promise<Response> {
case 'tools/call': {
const rawRequestedToolName = (params as Record<string, unknown>)?.name
const requestedToolName =
const outerToolName =
typeof rawRequestedToolName === 'string' ? rawRequestedToolName : ''
const toolName = toCanonicalToolName(requestedToolName)
const rawToolArgs = ((params as Record<string, unknown>)?.arguments ?? {}) as Record<
const outerToolArgs = ((params as Record<string, unknown>)?.arguments ?? {}) as Record<
string,
unknown
>
// gnubok_call_tool bridge. Rewrite {tool, arguments} into a direct call
// on the inner tool BEFORE resolution, so the scope check, the
// unknown-argument guard, company routing, the test-key write block, the
// staging _meta and telemetry below all apply to the real target. A
// wrapper that called the inner tool's execute() itself would have
// skipped every one of them.
const viaBridge = toCanonicalToolName(outerToolName) === 'gnubok_call_tool'
const requestedToolName = viaBridge
? typeof outerToolArgs.tool === 'string'
? outerToolArgs.tool
: ''
: outerToolName
const toolName = toCanonicalToolName(requestedToolName)
const rawToolArgs = viaBridge
? ((outerToolArgs.arguments ?? {}) as Record<string, unknown>)
: outerToolArgs
const tool = tools.find((t) => t.name === toolName)
// The pre-auth gate already refused anonymous calls to anything outside
// PUBLIC_TOOLS; re-checked here so the dispatcher never depends on it.
// Ordered ahead of the bridge refusal below so an anonymous caller is
// turned away before it learns whether a named tool is read-only.
//
// The bridge cannot widen anonymous reach, and is doubly closed: the
// pre-auth gate keys on the OUTER name, and gnubok_call_tool is not in
// PUBLIC_TOOLS, so an anonymous bridged call is refused before it gets
// here; this line then re-checks the INNER name. Nothing is lost by
// that, because all three public tools are in the default catalog and
// an anonymous caller never needs the bridge to name them.
if (isAnonymous && !isPublicTool(toolName)) return unauthorized()
// The bridge reaches reads only. A write must be named directly so the
// client sees its own annotations and its staging/approval contract
// rather than a generic wrapper's. An unknown-but-named target falls
// through to the unknown-tool handler below, which lists what exists.
if (viaBridge && (!requestedToolName || (tool && tool.annotations.readOnlyHint !== true))) {
const bridgeError = toToolError(
codedError(
'VALIDATION_ERROR',
requestedToolName
? `${requestedToolName} is not a read-only tool, so gnubok_call_tool will not invoke it. Call ${requestedToolName} directly by name.`
: 'gnubok_call_tool requires a "tool" argument naming the read-only tool to invoke.',
),
{ toolName: 'gnubok_call_tool' },
)
emitToolCallTelemetry({
tool: 'gnubok_call_tool',
requiredScope: null,
actor,
latencyMs: 0,
success: false,
isError: true,
errorCode: bridgeError.error.code,
errorKind: 'bridge_refused',
errorMessage: bridgeError.error.message_sv,
requestId: id ?? null,
userId,
companyId,
})
return NextResponse.json(
jsonRpc(id ?? null, decorate({
content: [
{
type: 'text',
text: JSON.stringify(projectMcpPayload(bridgeError, toolNamespace), null, 2),
},
],
isError: true,
}))
)
}
if (!tool) {
emitToolCallTelemetry({
tool: toolName ?? '<unknown>',