Skip to content

[MCP] Tool registry + class-level introspection + RBAC-aware tools/list filtering #615

Description

@kylebernhardy

Scope. Build the tool registry, JSON Schema input plumbing, and the RBAC-aware tools/list filter. No real tools yet — this PR ships the framework; the operations and application profiles plug into it in #617 and #618.

Design reference. Sections "Tool-list filtering" and "Safety & Observability → Error mapping" in #465.

Acceptance criteria

  • Tool registry abstraction (addTool, removeTool, listTools(user)) with per-session caching of the filtered list.
  • Class-level verb introspection reuses the pattern at resources/openApi.ts:149-153 (prototype.method !== Resource.prototype.method).
  • User-level RBAC walk reuses the pattern at dataLayer/schemaDescribe.ts:29-49 (direct walk of user.role.permission[db].tables[table]). Does not use Resource.allowRead/Create/Update/Delete — those are instance methods bound to a record id (resources/Resource.ts:413-427).
  • tools/list paginates via opaque cursor / nextCursor; page size capped by mcp.<profile>.maxTools.
  • tools/call dispatches to a registered tool's handler; unknown tool → JSON-RPC -32601; invalid args → -32602; tool-execution error returns result.isError = true (NOT a JSON-RPC error).
  • Tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) flow through.
  • Unit tests cover: filter for super_user, structure_user, read-only role, anonymous; pagination; isError mapping; unknown-tool error.

Out of scope. No operations API integration (#617), no Resources registry integration (#618), no listChanged (#619), no rate limiting (#620).

Stacks on. #614 (transport + lifecycle).

Branch & PR conventions

Smoke test

# Register a stub tool in test, then:
curl -sS -X POST http://localhost:9925/mcp ... \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'
# Expected: { result: { tools: [<stub>], nextCursor?: ... } }, RBAC-filtered to caller's role.

Tracking. Part of #465. Sub-issue #3 of 11.

Activity

  1. added this to the milestone on May 19, 2026
  2. added
    enhancementNew feature or request
    area:componentsComponents / applications subsystem
    area:mcpModel Context Protocol (MCP) server: protocol, profiles, stdio CLI
    feature:mcp-v1Rollout of native MCP server v1 (HarperFast/harper#465). Removed when v1 closes.
    on May 19, 2026
  3. kriszyp commented on May 20, 2026

    @kriszyp
    Member

    User-Level RBAC

    I am a skeptical that we can really introspect this. Most Harper applications have highly restricted RBAC access to tables, and then programmatically grant permission to public users. And for Resource (not tables), there is no such thing as RBAC at all. So I don't know that we can really determine tools based on RBAC, the permissions will probably still need to be applied at execution time.

  4. kylebernhardy commented on May 20, 2026

    @kylebernhardy
    MemberAuthor

    User-Level RBAC

    I am a skeptical that we can really introspect this. Most Harper applications have highly restricted RBAC access to tables, and then programmatically grant permission to public users. And for Resource (not tables), there is no such thing as RBAC at all. So I don't know that we can really determine tools based on RBAC, the permissions will probably still need to be applied at execution time.

    OK a bit of fire, and see what happens. Makes sense with our programmatic implementation of allow*. Is there any harm in trying to introspect or should this be skipped for Resource class endpoints?

  5. kriszyp commented on May 24, 2026

    @kriszyp
    Member

    Is there any harm in trying to introspect

    There is no harm in trying introspect the presence of static methods, that's the right thing to do.
    There is harm in trying to introspect RBAC permissions, they will often report no permissions even though permissions may be programmatically granted.

  6. modified the milestones: , v5.1 on Jun 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:componentsComponents / applications subsystemarea:mcpModel Context Protocol (MCP) server: protocol, profiles, stdio CLIenhancementNew feature or requestfeature:mcp-v1Rollout of native MCP server v1 (HarperFast/harper#465). Removed when v1 closes.

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions