feat(tools): one static /mcp endpoint, session chosen by bearer key - #44
Merged
Merged
Conversation
A workspace MCP config is shared by every session in a pod, so a URL that names one session routes all of them to that session's computer (seen 2026-09-29 on kiro-1040: agent-black, agent-rp1 and mac all answered from macmini). Sessions now also get OPENAB_TOOLS_MCP_ENDPOINT (http://127.0.0.1:<port>/mcp, identical everywhere) and OPENAB_TOOLS_MCP_TOKEN (the same key as in the URL). POST /mcp + Authorization: Bearer routes by key, with a constant-time non-short-circuit scan; missing, malformed and unknown keys are one 401. /mcp/{session}/{key} is unchanged. The contract documents the one-file config: Kiro expands ${VAR} in headers, not in url.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #39.
Problem. A workspace MCP config is shared by every session in a pod, so it cannot name one session in its URL. On kiro-1040 three sessions (
agent-black,agent-rp1,mac) were each attached to a different computer, yet all answeredsys_infofrom macmini, because the sharedmcp.jsonpinned/mcp/mac/<key>. Kiro does not expand${VAR}insideurl(tested), but it does insideheaders.Change.
OPENAB_TOOLS_MCP_ENDPOINT(http://127.0.0.1:<port>/mcp, identical in every session) andOPENAB_TOOLS_MCP_TOKEN, the same 64-hex key as in the URL.POST /mcpwithAuthorization: Bearer <key>routes to whichever session owns the key. The lookup is a constant-time, non-short-circuit scan. Missing, malformed or unknown keys all get one401withWWW-Authenticate: Bearer.GETreturns405, as before./mcp/{session}/{key}is unchanged.url+headers.Authorization: Bearer ${OPENAB_TOOLS_MCP_TOKEN}) as the preferred wiring.Tests. New e2e test
one_static_endpoint_routes_each_session_by_its_bearer_key: two sessions hit the same endpoint with their own keys and each gets its own fake computer (A/B). Missing, malformed, zero and truncated keys return401. A deleted session's key returns401while the other session is unaffected. On macmini: 171 unit tests and 8/8 e2e (--ignored) pass; clippy-D warningsand fmt are clean.