mirror of
https://gitea.com/gitea/gitea-mcp.git
synced 2026-08-03 15:49:23 +02:00
fix: accept null tool arguments and bound HTTP resource use
Review follow-ups on the SDK migration. An "arguments": null is what clients send for parameterless tools like get_me, and what mcp-go accepted by returning a nil map. The new adapter rejected it with InvalidParams, which broke those calls outright. The /mcp endpoint took unlimited request bodies and never expired idle sessions, so a peer that goes away without DELETE kept its session for the process lifetime. Both are reachable before any token check, so neither can stay unbounded; the body cap sits above the SDK default to leave room for the base64 content create_or_update_file accepts. Required() smuggled a bool through the property schema map and deleted it again, colliding with the JSON Schema keyword of the same name. It now sets a field on Property, so an object property can carry its own required list. The tool contract fixture cost a manual regeneration step and four hand-maintained counts on every tool change, and a snapshot freezes defects rather than reporting them. Property assertions cover the same surface and reject a duplicate tool name, a readOnlyHint that disagrees with the register call, and a default that contradicts its own type or enum. Co-Authored-By: Claude (Opus 5) <noreply@anthropic.com>
This commit is contained in:
+9
-26
@@ -1,7 +1,6 @@
|
||||
package tool
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
@@ -89,30 +88,18 @@ func (t *Tool) Tools() []ServerTool {
|
||||
// MCPHandler adapts a project handler to the official SDK's low-level handler.
|
||||
func (s ServerTool) MCPHandler() mcp.ToolHandler {
|
||||
return func(ctx context.Context, req *mcp.CallToolRequest) (result *mcp.CallToolResult, err error) {
|
||||
name := ""
|
||||
if s.Tool != nil {
|
||||
name = s.Tool.Name
|
||||
}
|
||||
defer func() {
|
||||
if recovered := recover(); recovered != nil {
|
||||
panicErr := fmt.Errorf("panic recovered in %s tool handler: %v", name, recovered)
|
||||
panicErr := fmt.Errorf("panic recovered in %s tool handler: %v", s.Tool.Name, recovered)
|
||||
log.Errorf("%s", panicErr)
|
||||
result = nil
|
||||
err = &jsonrpc.Error{Code: jsonrpc.CodeInternalError, Message: panicErr.Error()}
|
||||
err = internalError(panicErr)
|
||||
}
|
||||
}()
|
||||
|
||||
if req == nil || req.Params == nil {
|
||||
return nil, invalidParamsError("missing tool call parameters")
|
||||
}
|
||||
|
||||
arguments, err := decodeArguments(req.Params.Arguments)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if s.Handler == nil {
|
||||
return nil, internalError(fmt.Errorf("tool %q has no handler", name))
|
||||
}
|
||||
|
||||
result, err = s.Handler(ctx, arguments)
|
||||
if err != nil {
|
||||
@@ -127,25 +114,21 @@ func (s ServerTool) MCPHandler() mcp.ToolHandler {
|
||||
}
|
||||
|
||||
func decodeArguments(raw json.RawMessage) (map[string]any, error) {
|
||||
trimmed := bytes.TrimSpace(raw)
|
||||
if len(trimmed) == 0 {
|
||||
// An omitted and a null "arguments" both mean the tool was called without any.
|
||||
if len(raw) == 0 || string(raw) == "null" {
|
||||
return map[string]any{}, nil
|
||||
}
|
||||
if bytes.Equal(trimmed, []byte("null")) {
|
||||
return nil, invalidParamsError("tool arguments must be an object")
|
||||
}
|
||||
|
||||
var arguments map[string]any
|
||||
if err := json.Unmarshal(trimmed, &arguments); err != nil {
|
||||
return nil, invalidParamsError(fmt.Sprintf("invalid tool arguments: %v", err))
|
||||
if err := json.Unmarshal(raw, &arguments); err != nil {
|
||||
return nil, &jsonrpc.Error{
|
||||
Code: jsonrpc.CodeInvalidParams,
|
||||
Message: fmt.Sprintf("invalid tool arguments: %v", err),
|
||||
}
|
||||
}
|
||||
return arguments, nil
|
||||
}
|
||||
|
||||
func invalidParamsError(message string) error {
|
||||
return &jsonrpc.Error{Code: jsonrpc.CodeInvalidParams, Message: message}
|
||||
}
|
||||
|
||||
func internalError(err error) error {
|
||||
return &jsonrpc.Error{Code: jsonrpc.CodeInternalError, Message: err.Error()}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user