Files
accounted/extensions/general/mcp-server/index.ts
T
Jakob Wennberg ec27228a8e style: remove em/en dashes repo-wide, add CLAUDE.md rule against them (#890)
Em dashes (—) and en dashes (–) had spread across comments, docs, tests,
and a few UI strings, reading as AI-generated boilerplate rather than
house style. Replaced each with punctuation matching its context: colon
for explanatory clauses, comma for asides, plain hyphen for numeric/legal
ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for
paired-dash asides. messages/en.json and messages/sv.json were fixed by
hand together to keep sv/en in sync.

Left untouched where the dash is the functional subject rather than
decorative punctuation: date-range-parser.ts's separator regex,
charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE
encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the
agent system-prompt files that already instruct against em dashes, and
a golden iXBRL test fixture compared byte-for-byte.

Also fixes two bugs surfaced along the way: an off-by-one in
ApiKeysPanel's scope-label split (a leftover from an earlier partial
pass), and a charset-repair test that had lost the literal en-dash it
exists to verify.

Regenerated the agent atom seed migration (skills:generate) since 27
SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes,
with an explicit carve-out for the functional-dash cases above.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04 15:58:06 +02:00

68 lines
2.5 KiB
TypeScript

import type { Extension } from '@/lib/extensions/types'
import { handleMcpRequest, tools as mcpTools } from './server'
import { isForbiddenOrigin, forbiddenOriginResponse } from './origin-guard'
import { registerAgentTools } from '@/lib/agent/tools/registry'
import type { AgentTool } from '@/lib/agent/tools/types'
// Make the same tool set available to the in-app chat agent. The chat loop
// (lib/agent/chat/*) dispatches against the core agentToolRegistry so it can
// stay decoupled from this extension's module path. Tools satisfy the
// AgentTool contract structurally: see lib/agent/tools/types.ts.
registerAgentTools(mcpTools as unknown as AgentTool[])
export const mcpServerExtension: Extension = {
id: 'mcp-server',
name: 'MCP Server',
version: '1.0.0',
settingsPanel: {
label: 'MCP-server (API)',
path: '/settings/api',
},
apiRoutes: [
{
method: 'POST',
path: '/mcp',
skipAuth: true, // Auth handled via API key in the handler
handler: async (request: Request) => {
// MCP spec MUST: validate Origin (DNS-rebinding defense). See origin-guard.ts.
if (isForbiddenOrigin(request)) return forbiddenOriginResponse()
return handleMcpRequest(request)
},
},
// MCP Streamable HTTP also needs GET for SSE and DELETE for session termination
{
method: 'GET',
path: '/mcp',
skipAuth: true,
// This server is stateless and offers no server-initiated SSE stream, so
// the Streamable HTTP spec requires 405 Method Not Allowed here. Returning
// 401 (as we previously did) makes spec-compliant clients (Claude
// connector, Claude Desktop, Cursor) treat the SSE GET as an auth failure
// and retry-loop: refresh token → re-open GET → 401 → …: which storms
// the endpoint and churns OAuth key rotation. OAuth discovery is
// bootstrapped on the POST 401 (WWW-Authenticate), not here.
handler: async (request: Request) => {
if (isForbiddenOrigin(request)) return forbiddenOriginResponse()
return new Response('Method Not Allowed', {
status: 405,
headers: { Allow: 'POST, DELETE' },
})
},
},
{
method: 'DELETE',
path: '/mcp',
skipAuth: true,
// Stateless: no sessions to terminate
handler: async (request: Request) => {
if (isForbiddenOrigin(request)) return forbiddenOriginResponse()
return new Response(null, { status: 204 })
},
},
],
eventHandlers: [],
}