Repository navigation
Fix MCP tool discovery for attachment filename schemas - #136
jefflaporte wants to merge 1 commit into
Conversation
Use explicit C0 and C1 control ranges so the exported JSON Schema filename pattern works without Unicode regex flags. Preserve Unicode filenames and rejection of unsafe filename characters, and cover the tools/list response with a regression test.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe ChangesAttachment filename validation
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable issue remains from this review. Merge after normal checks; official staging validation has not been reported. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The corrected pattern preserves filename restrictions and restores discovery behind existing authentication and draft-access controls. No material security risk introduced or worsened by this change was identified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Closes #135.
ChatGPT can complete OAuth for
/mcp/fullbut discover no tools becauseadd_draft_attachmentexports a filename pattern containing\p{Cc}without its required JavaScript Unicode flag. Python regex validators reject the escape, and JavaScript matching without the flag rejects valid filenames.Replace the property escape with explicit C0/C1 control ranges. This preserves filename validation, including Unicode filenames, while making the exported pattern usable without regex flags. Add a regression test against the actual
tools/listresponse.Verification
pnpm check— 965 unit tests and 225 Worker integration tests passed; two existing tests were skipped. Local Node 26 usedNODE_OPTIONS=--no-experimental-webstorageto avoid its native Web Storage conflict with browser tests.pnpm deploy:dry-run.Notes
The Biome exception is limited to the intentional control-range exclusion and includes an explanation. Scope is
hqbaseonly; this restores the existing filename contract and does not change storage or authorization. Official HQBase staging has not been run.Summary by CodeRabbit