Pure Composer and Task parser tools incorrectly require write access #754

Open
opened 2026-10-02 13:09:08 +00:00 by kayg · 3 comments
Owner

Context: #427 rev-mcp-api review, #484, DESIGN §41. Source base c4a61e8cf090170f35b1bed3350d9de20c83ecd5. Priority: Medium. No product edits or live reproduction in this review.

Evidence:

  • crates/plugins/notes/src/composer_api.rs:1 documents a pure preview function with no reads or writes; :219 returns project(...).
  • crates/plugins/notes/src/tasks_api.rs:91 parses Task text and returns a preview without a content write.
  • scripts/action_registry.py:146 classifies every POST except ZIP download as a mutation. Both notes_composer_parse and parse have read_only: false and destructive: true in contracts/actions.json.
  • crates/calternal-server/src/wire.rs:2375 has only the ZIP read exception. crates/calternal-cli/src/remote_commands.rs:294 requires --confirm; apps/web/src/lib/webmcp/generated.ts:88 confirms every action not marked read-only.

Impact:

A read-only API or MCP App Password cannot use the parsers. CLI and WebMCP request change confirmation for pure previews. The inventory gate still passes.

Expected:

Declare read intent for the pure parser actions once and use it in route access and adapter hints. Keep authentication, body validation and CPU bounds. CLI and WebMCP must allow the preview without change confirmation.

Regression test idea:

Add metadata assertions and read-only route tests for both parser actions. Add adapter tests that the pure previews do not ask for confirmation and do not write Home content.

Duplicate check:

Searched all issue states for notes_composer_parse, parser, read-only and parity. No specific parser-access issue found.

Context: #427 rev-mcp-api review, #484, DESIGN §41. Source base `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. Priority: Medium. No product edits or live reproduction in this review. Evidence: - `crates/plugins/notes/src/composer_api.rs:1` documents a pure preview function with no reads or writes; `:219` returns `project(...)`. - `crates/plugins/notes/src/tasks_api.rs:91` parses Task text and returns a preview without a content write. - `scripts/action_registry.py:146` classifies every POST except ZIP download as a mutation. Both `notes_composer_parse` and `parse` have `read_only: false` and `destructive: true` in `contracts/actions.json`. - `crates/calternal-server/src/wire.rs:2375` has only the ZIP read exception. `crates/calternal-cli/src/remote_commands.rs:294` requires `--confirm`; `apps/web/src/lib/webmcp/generated.ts:88` confirms every action not marked read-only. Impact: A read-only API or MCP App Password cannot use the parsers. CLI and WebMCP request change confirmation for pure previews. The inventory gate still passes. Expected: Declare read intent for the pure parser actions once and use it in route access and adapter hints. Keep authentication, body validation and CPU bounds. CLI and WebMCP must allow the preview without change confirmation. Regression test idea: Add metadata assertions and read-only route tests for both parser actions. Add adapter tests that the pure previews do not ask for confirmation and do not write Home content. Duplicate check: Searched all issue states for `notes_composer_parse`, `parser`, `read-only` and `parity`. No specific parser-access issue found.
Author
Owner

Starting work on job/notesperf, based on job/merge-round-7a at 2f4482ded066d9c5d9c59130377907f7fd2916c9. I will address the issue with focused changes and regression coverage, then report the final head SHA and verbatim gate output here.

Starting work on `job/notesperf`, based on `job/merge-round-7a` at `2f4482ded066d9c5d9c59130377907f7fd2916c9`. I will address the issue with focused changes and regression coverage, then report the final head SHA and verbatim gate output here.
Author
Owner

Evidence from the old code: scripts/action_registry.py classified every POST as mutating, including the pure /notes/composer/parse and /notes/tasks/parse previews. The new registry regression failed for both action IDs (notes_composer_parse and parse) with read_only == false. I changed the generated action intent and server route access to consume that same registry metadata; the Python regression now passes.

Evidence from the old code: `scripts/action_registry.py` classified every POST as mutating, including the pure `/notes/composer/parse` and `/notes/tasks/parse` previews. The new registry regression failed for both action IDs (`notes_composer_parse` and `parse`) with `read_only == false`. I changed the generated action intent and server route access to consume that same registry metadata; the Python regression now passes.
Author
Owner

Implemented in e016b6225: generate read-only POST scope routes from the action registry. Focused scope regression passed (1/1), action-registry unit tests passed (13/13), parity check passed. Full server unit harness found one stale Agent Skill route example; corrected source in 109b5b4cf, but host I/O prevented rebuild and rerun.

Implemented in e016b6225: generate read-only POST scope routes from the action registry. Focused scope regression passed (1/1), action-registry unit tests passed (13/13), parity check passed. Full server unit harness found one stale Agent Skill route example; corrected source in 109b5b4cf, but host I/O prevented rebuild and rerun.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#754
No description provided.