Fix/mcp fixes and bugs (#518)

* feat(voucher): add create voucher and correct entry previews; update commit methods

* feat: add support for pending operations in API key scopes and OAuth client management

- Introduced new API key scopes for reading and approving pending operations.
- Updated the scope groups to include pending operations.
- Added new tools for listing and managing pending operations.
- Implemented OAuth client registration and revocation endpoints.
- Created a UI panel for managing OAuth clients, including registration and revocation.
- Added tests for pending operations tools and OAuth allowlist functionality.
- Implemented a database migration for OAuth client registrations with appropriate policies and constraints.

* feat: Implement OAuth client registration rate limiting and enhance security measures

- Added IP-based rate limiting to the OAuth client registration endpoint to prevent enumeration attacks.
- Introduced a service-role client for allowlist lookups, ensuring trust boundaries are maintained.
- Updated error responses to be uniform across different types of redirect URI validation failures.
- Enhanced tests to reflect changes in OAuth scope handling, ensuring fallback to read-only scopes when no scopes are provided.
- Improved handling of high-risk pending operations, requiring explicit confirmation for approvals.
- Added audit logging for OAuth client revocations and pending operation approvals/rejections to maintain a security audit trail.
- Refactored API key scope management to include default read-only scopes for OAuth-issued keys and added segregation-of-duties checks.
This commit is contained in:
Mattsson
2026-05-18 19:02:42 +02:00
committed by GitHub
parent d27c3dd3dc
commit 16164ea14c
26 changed files with 2363 additions and 154 deletions
+18 -3
View File
@@ -82,6 +82,16 @@ export interface CommitResult {
export interface CommitOptions {
/** Email address used as cc on send_invoice (typically the human user's email). */
userEmail?: string
/**
* commit_method recorded on any journal_entries created by this operation.
* Must match the CHECK constraint on journal_entries.commit_method:
* 'user_accept' | 'bulk_accept' | 'timing_ceiling' | 'migration' | 'legacy'.
* Single-approval route passes 'user_accept' (default); bulk-approval passes
* 'bulk_accept'. Defaults to 'user_accept' since the dispatcher is only
* invoked from human-approval paths after agent auto-commit was removed
* (migration 20260505190027_drop_agent_auto_commit).
*/
commitMethod?: 'user_accept' | 'bulk_accept'
}
// ── Helper: ensure fiscal period covers the date ──────────────────
@@ -1628,7 +1638,8 @@ async function commitCreateVoucher(
supabase: SupabaseClient,
userId: string,
companyId: string,
params: Record<string, unknown>
params: Record<string, unknown>,
opts: CommitOptions = {}
): Promise<ExecutorResult> {
const entryDate = params.entry_date as string
const description = params.description as string
@@ -1681,7 +1692,11 @@ async function commitCreateVoucher(
notes: (params.notes as string) || undefined,
lines,
},
'mcp_create_voucher'
// commit_method records HOW it was committed, not who staged it. MCP-
// staged ops still go through human approval, so 'user_accept' (or
// 'bulk_accept' from the bulk route) is the correct value. The DB CHECK
// constraint rejects anything else (migration 20260420120001).
opts.commitMethod ?? 'user_accept'
)
return {
@@ -1981,7 +1996,7 @@ export async function commitPendingOperation(
result = await commitImportSie(supabase, userId, companyId, pendingOp.params)
break
case 'create_voucher':
result = await commitCreateVoucher(supabase, userId, companyId, pendingOp.params)
result = await commitCreateVoucher(supabase, userId, companyId, pendingOp.params, opts)
break
case 'correct_entry':
result = await commitCorrectEntry(supabase, userId, companyId, pendingOp.params)