QONTO-WP-0003-T02: MCP tool catalog on the shared capability core
Add qonto_org_summary, qonto_list_transactions, and qonto_cost_run_rate_hints MCP tools, all routed through CapabilityService with protocol="mcp" -- same PolicyEngine.decide() path as REST, same deny-reason vocabulary. Skip snapshot_bundle as an MCP tool (REST already covers the composite read; not a separate privilege). CapabilityService now threads protocol through _execute/_emit_audit instead of hardcoding "rest". cost_run_rate_hints gets its own service method since it's an independent policy capability, not only a snapshot sub-field. Actor identity reuses REST's X-Actor-* header convention via a shared auth.actor_claims_from_headers(), read from the MCP Context's request when present. Fixed streamable_http_path defaulting to "/mcp", which doubled to "/mcp/mcp" once mounted under the "/mcp" prefix. Verified end-to-end with the mcp SDK's streamablehttp_client against the live fixture-backed server: tool list, allow/deny paths, and X-Actor-ID flowing through to the audit log exactly like REST. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
ba2612682f
commit
b4b1dc1c7b
7 changed files with 284 additions and 29 deletions
|
|
@ -26,6 +26,14 @@ Phase 1 runtime is implemented:
|
|||
- REST endpoints: `/v1/health`, `/v1/accounts`, `/v1/transactions`, `/v1/snapshot`
|
||||
- audit metadata, rate limiting, concurrency bounds, tests
|
||||
|
||||
Phase 2 (MCP surface, `workplans/QONTO-WP-0003-mcp-surface.md`) is in
|
||||
progress: a streamable-HTTP MCP adapter is mounted at `/mcp` on the same
|
||||
capability core and policy kernel as REST, with tools `qonto_org_summary`,
|
||||
`qonto_list_transactions`, and `qonto_cost_run_rate_hints`. Client auth is
|
||||
still the REST-style `X-Actor-*` header convention; real OIDC/workload auth,
|
||||
the shared multi-harness client config snippet, and the `finance-qonto-read`
|
||||
tool profile are not yet implemented.
|
||||
|
||||
Current verification:
|
||||
|
||||
- `PYTHONPATH=src ../state-hub/.venv/bin/python -m pytest` → `16 passed`
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue