mirror of
https://gitea.com/gitea/gitea-mcp.git
synced 2026-08-03 15:49:23 +02:00
fix: accept null tool arguments and bound HTTP resource use
Review follow-ups on the SDK migration. An "arguments": null is what clients send for parameterless tools like get_me, and what mcp-go accepted by returning a nil map. The new adapter rejected it with InvalidParams, which broke those calls outright. The /mcp endpoint took unlimited request bodies and never expired idle sessions, so a peer that goes away without DELETE kept its session for the process lifetime. Both are reachable before any token check, so neither can stay unbounded; the body cap sits above the SDK default to leave room for the base64 content create_or_update_file accepts. Required() smuggled a bool through the property schema map and deleted it again, colliding with the JSON Schema keyword of the same name. It now sets a field on Property, so an object property can carry its own required list. The tool contract fixture cost a manual regeneration step and four hand-maintained counts on every tool change, and a snapshot freezes defects rather than reporting them. Property assertions cover the same surface and reject a duplicate tool name, a readOnlyHint that disagrees with the register call, and a default that contradicts its own type or enum. Co-Authored-By: Claude (Opus 5) <noreply@anthropic.com>
This commit is contained in:
@@ -1,53 +1,6 @@
|
||||
package operation
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"gitea.com/gitea/gitea-mcp/pkg/flag"
|
||||
)
|
||||
|
||||
// TestAllToolsHaveDescriptions ensures every registered tool sets a non-empty
|
||||
// Tool.Description, as strict MCP clients reject tools without one.
|
||||
func TestAllToolsHaveDescriptions(t *testing.T) {
|
||||
origRO, origAllow := flag.ReadOnly, flag.AllowedTools
|
||||
t.Cleanup(func() {
|
||||
flag.ReadOnly, flag.AllowedTools = origRO, origAllow
|
||||
})
|
||||
flag.ReadOnly = false
|
||||
flag.AllowedTools = nil
|
||||
|
||||
var missing []string
|
||||
for _, d := range domainTools {
|
||||
for _, st := range d.Tools() {
|
||||
if st.Tool.Description == "" {
|
||||
missing = append(missing, st.Tool.Name)
|
||||
}
|
||||
}
|
||||
}
|
||||
if len(missing) > 0 {
|
||||
t.Errorf("tools missing a description: %v", missing)
|
||||
}
|
||||
}
|
||||
|
||||
// TestDomainToolsScopesAreUniqueAndNonEmpty ensures every entry registered in
|
||||
// domainTools has a canonical, non-empty scope name and that no two domains
|
||||
// share the same scope (each domain.Tools() call is filtered by exactly one
|
||||
// scope name via flag.AllowedScopes).
|
||||
func TestDomainToolsScopesAreUniqueAndNonEmpty(t *testing.T) {
|
||||
seen := map[string]struct{}{}
|
||||
for _, d := range domainTools {
|
||||
scope := d.Scope()
|
||||
if scope == "" {
|
||||
t.Errorf("domainTools contains a domain with an empty scope")
|
||||
continue
|
||||
}
|
||||
if _, ok := seen[scope]; ok {
|
||||
t.Errorf("domainTools contains a duplicate scope %q", scope)
|
||||
continue
|
||||
}
|
||||
seen[scope] = struct{}{}
|
||||
}
|
||||
}
|
||||
import "testing"
|
||||
|
||||
func TestParseAuthToken(t *testing.T) {
|
||||
tests := []struct {
|
||||
|
||||
Reference in New Issue
Block a user