You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 0e700c9
Browse filesBrowse the repository at this point in the historyBrowse files
fix(mcp-bridge): harden argument handling for routed tools (#349)
## Summary
Harden argument handling in the MCP bridge for the routed tools:
browser, cloud, comms and ml. These tools share a cartridge and are told
apart by a routing key derived from the tool name. After this change the
tool name alone decides the route, and arguments that a routed tool's
`inputSchema` does not declare are refused with `-32602`.
## 📌 New pins
Head SHA: **f01e55a72ab4a3ec8f2edbdbefff9b29200db8cb**. This PR adds or
changes no action, lockfile or container pins.
## Changes
- `mcp-bridge/lib/dispatcher.js`:
- New `ROUTED_TOOLS` table (tool name → cartridge plus routing key). It
replaces four `switch` arms. The routing key is written after the
caller's arguments.
- New `validateRoutedArgs` and `declaredArgs`. The hardening gate
refuses arguments that a routed tool's `inputSchema` does not declare.
- The gate also refuses non-object `arguments`.
- JSDoc added to `dispatchTool`, `hardeningGate` and the new helpers.
- Scope: non-routed tools are unchanged. `coord_send` reads
`sender_role`, which no schema declares, so applying the check to every
tool would break it.
- `mcp-bridge/tests/routing_args_test.js` (new, 16 tests). Each routed
tool still reaches its cartridge with the right key. An argument cannot
change the routing key. Undeclared arguments are refused. Non-routed
handling is unchanged. `fetch` is stubbed for this file only and
restored afterwards, because bun shares one process across files.
- `.github/workflows/e2e.yml` (node, deno and bun unit lines) and
`package.json` `test` now include the new file.
## RSR Quality Checklist
### Required
- [x] Tests pass. node `--test`: 68/68 across the four bridge test
files. `bun test`: 68/68. `deno test`: 68/68.
- [ ] Code is formatted: no formatter is configured for `mcp-bridge/`
JS. The code follows the surrounding style by hand.
- [ ] Linter is clean: no JS linter runs on `mcp-bridge/` locally. CI
scanners will report on this PR.
- [x] No banned language patterns. Plain ESM JS, as in the existing
bridge. Nothing new in TS, Python or Go. The `npm test` script line
already existed and only gained a file name.
- [x] No `unsafe` blocks: there is no Rust or Zig in this change.
- [x] No banned functions.
- [x] SPDX headers: the new test file carries `MPL-2.0`. The modified
files keep theirs.
- [x] No secrets, credentials or `.env` files.
### As Applicable
- [ ] `.machine_readable/*` not updated: project state and integrations
are unchanged.
- [ ] Documentation not updated: the advertised tool schemas are
unchanged. Only calls that already violated those schemas are now
refused.
- [ ] `TOPOLOGY.md` not updated: architecture is unchanged.
- [ ] CHANGELOG / release notes: to follow with the patch release that
ships this fix.
- [ ] New dependencies: none.
- [ ] ABI/FFI: not touched.
## Testing
- `node --test
mcp-bridge/tests/{routing_args,dispatch,http_transport,path_claims}_test.js`:
68 pass, 0 fail.
- `bun test` (same files): 68 pass, 0 fail. `deno test --allow-read
--allow-env --allow-run --allow-net` (same files): 68 passed.
- Control: `routing_args_test.js` against `origin/main`'s
`dispatcher.js` gives 8 pass and 8 fail. Every routing and
undeclared-argument test fails there; the well-formed-call and
non-routed tests pass.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_019j8She9eTFx54r6aL6sCHP
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
# Scoped perms matching main.js's shebang, NOT -A: the boot smoke
218
218
# must exercise the exact permission set a real install uses, or it
219
219
# would mask a missing-grant bug that scoped users would hit.
220
220
boot: deno run --allow-net --allow-env --allow-read mcp-bridge/main.js
221
221
- runtime: bun
222
-
unit: bun test mcp-bridge/tests/dispatch_test.js mcp-bridge/tests/http_transport_test.js mcp-bridge/tests/path_claims_test.js
222
+
unit: bun test mcp-bridge/tests/dispatch_test.js mcp-bridge/tests/http_transport_test.js mcp-bridge/tests/path_claims_test.js mcp-bridge/tests/routing_args_test.js
0 commit comments