Skip to content

feat(tools): one static /mcp endpoint, session chosen by bearer key - #44

Merged
chaodu-agent merged 1 commit into
mainfrom
feat/tools-mcp-bearer
Sep 29, 2026
Merged

chaodu-agent merged 1 commit into
mainfrom
feat/tools-mcp-bearer

Conversation

@chaodu-agent

Copy link
Copy Markdown
Collaborator

Refs #39.

Problem. A workspace MCP config is shared by every session in a pod, so it cannot name one session in its URL. On kiro-1040 three sessions (agent-black, agent-rp1, mac) were each attached to a different computer, yet all answered sys_info from macmini, because the shared mcp.json pinned /mcp/mac/<key>. Kiro does not expand ${VAR} inside url (tested), but it does inside headers.

Change.

  • Sessions also get OPENAB_TOOLS_MCP_ENDPOINT (http://127.0.0.1:<port>/mcp, identical in every session) and OPENAB_TOOLS_MCP_TOKEN, the same 64-hex key as in the URL.
  • POST /mcp with Authorization: Bearer <key> routes to whichever session owns the key. The lookup is a constant-time, non-short-circuit scan. Missing, malformed or unknown keys all get one 401 with WWW-Authenticate: Bearer. GET returns 405, as before.
  • /mcp/{session}/{key} is unchanged.
  • CLIENT-CONTRACT §9.3 now documents the one-file config (url + headers.Authorization: Bearer ${OPENAB_TOOLS_MCP_TOKEN}) as the preferred wiring.

Tests. New e2e test one_static_endpoint_routes_each_session_by_its_bearer_key: two sessions hit the same endpoint with their own keys and each gets its own fake computer (A/B). Missing, malformed, zero and truncated keys return 401. A deleted session's key returns 401 while the other session is unaffected. On macmini: 171 unit tests and 8/8 e2e (--ignored) pass; clippy -D warnings and fmt are clean.

A workspace MCP config is shared by every session in a pod, so a URL that names one session routes all of them to that session's computer (seen 2026-09-29 on kiro-1040: agent-black, agent-rp1 and mac all answered from macmini). Sessions now also get OPENAB_TOOLS_MCP_ENDPOINT (http://127.0.0.1:<port>/mcp, identical everywhere) and OPENAB_TOOLS_MCP_TOKEN (the same key as in the URL). POST /mcp + Authorization: Bearer routes by key, with a constant-time non-short-circuit scan; missing, malformed and unknown keys are one 401. /mcp/{session}/{key} is unchanged. The contract documents the one-file config: Kiro expands ${VAR} in headers, not in url.
@chaodu-agent
chaodu-agent merged commit 9e14640 into main Sep 29, 2026
18 checks passed
@chaodu-agent
chaodu-agent deleted the feat/tools-mcp-bearer branch September 29, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant