Skip to content

feat(mcp): every refused query records the guard rule that refused it (#1231) - #1232

Merged
ZhuchkaTriplesix merged 2 commits into
devfrom
feat/1231-mcp-rule-ids
Oct 9, 2026
Merged

ZhuchkaTriplesix merged 2 commits into
devfrom
feat/1231-mcp-rule-ids

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Refs #1231

What was wrong

McpSqlGuard returned only a message for a refused query. The activity log kept that text, so a refusal could be read but not grouped by the rule that caught it.

Changes

  • McpSqlGuard.refusal returns a McpSqlRefusal with a stable rule id and the message. The nine refusals have ids: empty_query, single_statement, mysql_executable_comment, sqlite_pragma, read_only_only, function_not_allowed, explain_analyze_or_write, data_modifying, select_into_or_lock. check returns the same message as before.
  • The id travels with the tool error (McpToolException.rule) to the call record and into the activity entry.
  • mcp_activity gets a refusal_rule column (schema v12). Existing databases get it through an ALTER TABLE; rows written before it read as no rule.
  • Tests: each rule id has an example; a query that may run has no refusal; the message is unchanged; the activity entry round-trips the rule, and an old row reads as no rule.

Not in this PR

Not verified locally

Tests were not run locally, per the project rule.

…#1231)

The guard returned only a message, so the activity log could say what a refused
query said but not which rule caught it. Each refusal now has a stable rule id
(read_only_only, single_statement, data_modifying, ...). The id travels with the
tool error to the call record and into a new refusal_rule column of
mcp_activity (schema v12; rows written before it read as no rule). The message
the model reads does not change.
@github-actions github-actions Bot added enhancement New feature or request tests Theme parser epic P2 Medium priority / Parity & Refactoring labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request P2 Medium priority / Parity & Refactoring tests Theme parser epic

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant