mirror of
https://gitea.com/gitea/gitea-mcp.git
synced 2026-08-03 15:49:23 +02:00
fix: accept null tool arguments and bound HTTP resource use
Review follow-ups on the SDK migration. An "arguments": null is what clients send for parameterless tools like get_me, and what mcp-go accepted by returning a nil map. The new adapter rejected it with InvalidParams, which broke those calls outright. The /mcp endpoint took unlimited request bodies and never expired idle sessions, so a peer that goes away without DELETE kept its session for the process lifetime. Both are reachable before any token check, so neither can stay unbounded; the body cap sits above the SDK default to leave room for the base64 content create_or_update_file accepts. Required() smuggled a bool through the property schema map and deleted it again, colliding with the JSON Schema keyword of the same name. It now sets a field on Property, so an object property can carry its own required list. The tool contract fixture cost a manual regeneration step and four hand-maintained counts on every tool change, and a snapshot freezes defects rather than reporting them. Property assertions cover the same surface and reject a duplicate tool name, a readOnlyHint that disagrees with the register call, and a default that contradicts its own type or enum. Co-Authored-By: Claude (Opus 5) <noreply@anthropic.com>
This commit is contained in:
@@ -1,20 +1,50 @@
|
||||
package annotation
|
||||
|
||||
import "testing"
|
||||
import (
|
||||
"encoding/json"
|
||||
"maps"
|
||||
"testing"
|
||||
|
||||
"github.com/modelcontextprotocol/go-sdk/mcp"
|
||||
)
|
||||
|
||||
// The hints are what clients use to decide whether a tool needs confirmation, so
|
||||
// assert the encoded form: an omitted readOnlyHint reads as false either way, but
|
||||
// only the explicit form survives a client that checks for the key.
|
||||
func TestAnnotations(t *testing.T) {
|
||||
readOnly := ReadOnly("Read")
|
||||
if readOnly.Title != "Read" || !readOnly.ReadOnlyHint || readOnly.DestructiveHint != nil {
|
||||
t.Errorf("ReadOnly() = %#v", readOnly)
|
||||
}
|
||||
|
||||
write := Write("Write")
|
||||
if write.Title != "Write" || write.ReadOnlyHint || write.DestructiveHint != nil {
|
||||
t.Errorf("Write() = %#v", write)
|
||||
}
|
||||
|
||||
destructive := Destructive("Delete")
|
||||
if destructive.Title != "Delete" || destructive.ReadOnlyHint || destructive.DestructiveHint == nil || !*destructive.DestructiveHint {
|
||||
t.Errorf("Destructive() = %#v", destructive)
|
||||
for _, test := range []struct {
|
||||
name string
|
||||
annotations *mcp.ToolAnnotations
|
||||
want map[string]any
|
||||
}{
|
||||
{
|
||||
name: "ReadOnly",
|
||||
annotations: ReadOnly("Read"),
|
||||
want: map[string]any{"title": "Read", "readOnlyHint": true, "idempotentHint": false},
|
||||
},
|
||||
{
|
||||
name: "Write",
|
||||
annotations: Write("Write"),
|
||||
want: map[string]any{"title": "Write", "readOnlyHint": false, "idempotentHint": false},
|
||||
},
|
||||
{
|
||||
name: "Destructive",
|
||||
annotations: Destructive("Delete"),
|
||||
want: map[string]any{"title": "Delete", "readOnlyHint": false, "idempotentHint": false, "destructiveHint": true},
|
||||
},
|
||||
} {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
encoded, err := json.Marshal(test.annotations)
|
||||
if err != nil {
|
||||
t.Fatalf("json.Marshal() error = %v", err)
|
||||
}
|
||||
var got map[string]any
|
||||
if err := json.Unmarshal(encoded, &got); err != nil {
|
||||
t.Fatalf("json.Unmarshal() error = %v", err)
|
||||
}
|
||||
if !maps.Equal(got, test.want) {
|
||||
t.Errorf("annotations = %s, want %v", encoded, test.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user