fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: anonymous client - #23

Merged
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client
Feb 12, 2026
Merged

fix: anonymous client#23
imbenrabi merged 11 commits into
mainfrom
benr/fix-anon-client

Conversation

@imbenrabi

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the “anonymous client” fallback for MCP protocol endpoints by requiring a valid mcp-client-id header, while also refactoring several modules toward a builder-based construction style and consolidating scattered helpers/types into *.utils.ts / *.types.ts files.

Changes:

  • Enforce mcp-client-id validation (reject missing/blank with 400) and update tests/docs accordingly.
  • Refactor server/transport/core/session/permissions components to use builder patterns and centralize shared utilities/types.
  • Move permission/session validation + bundle helpers into new permissions.utils.ts / session.utils.ts and add new *.types.ts modules.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
tests/validateSessionContextConfig.test.tsUpdates import path for session config validation helper.
tests/validatePermissionConfig.test.tsUpdates import path for permission config validation helper.
tests/permissionAwareFastifyTransport.test.tsAdds/updates tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/fastifyTransport.test.tsAdds tests asserting POST /mcp rejects missing/blank mcp-client-id.
tests/customEndpoints.test.tsSwitches imports to consolidated HTTP utils module.
tests/createPermissionAwareBundle.test.tsUpdates imports after permissions utils/types split.
tests/createMcpServer.test.tsUpdates transport mock to support new builder-based wiring.
src/types/index.tsRedirects CreateMcpServerOptions type import to server.types.ts.
src/types/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/session/session.utils.tsRetains session config validation; trims doc verbosity.
src/session/session.types.tsIntroduces shared session/cache types (e.g., SessionContextResult, cache options).
src/session/SessionContextResolver.tsMoves SessionContextResult to types file; adds builder; refactors resolve flow into helpers.
src/session/ClientResourceCache.tsMoves option/entry types to session.types.ts; adds builder.
src/session/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/server/server.utils.tsAdds shared utilities: startup config schema/validation, notifier adapter, meta-tools flag resolver.
src/server/server.types.tsAdds shared public server types (CreateMcpServerOptions, McpServerHandle).
src/server/createPermissionBasedMcpServer.tsRefactors into helper functions; switches to consolidated permissions/session utils; uses builder-style orchestrator/transport creation.
src/server/createMcpServer.tsExtracts types to server.types.ts; moves shared utils to server.utils.ts; uses builder-based transport/orchestrator wiring.
src/server/AGENTS.mdDocuments new helper-based flow and builder/optional-field invariant.
src/permissions/validatePermissionConfig.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/permissions.utils.tsNew consolidated permissions module: validation, bundle factory, exposure policy sanitization.
src/permissions/permissions.types.tsNew shared permission transport/bundle/context types.
src/permissions/createPermissionAwareBundle.tsRemoved; logic moved into permissions.utils.ts.
src/permissions/PermissionResolver.tsAdds builder; trims doc verbosity.
src/permissions/PermissionAwareFastifyTransport.tsRequires mcp-client-id for POST /mcp; caches by clientId; introduces builder; refactors imports to new http/permissions types/utils.
src/permissions/AGENTS.mdUpdates invariants/docs to reflect required mcp-client-id behavior and caching changes.
src/mode/mode.types.tsNew shared mode-related types/constants extracted from resolvers.
src/mode/ModuleResolver.tsUses extracted mode types/constants; adds builder; refactors resolution into helper methods.
src/mode/ModeResolver.tsUses extracted mode types; adds builder; extracts repeated validation error formatting.
src/mode/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
src/index.tsUpdates public type exports to use server.types.ts and session.types.ts; updates HTTP exports to http.utils.ts/http.types.ts.
src/http/http.utils.tsConsolidates endpoint definition/registration helpers; exports createValidationError.
src/http/http.types.tsExtracts transport/options/bundle callback and endpoint types into a shared types module.
src/http/FastifyTransport.tsRequires mcp-client-id for POST /mcp; adds builder; refactors route registration into named methods.
src/http/AGENTS.mdUpdates invariant: /mcp endpoints require mcp-client-id; custom endpoints still allow anonymous IDs.
src/core/core.types.tsNew shared core option types extracted from classes.
src/core/ToolRegistry.tsMoves options type to core.types.ts; adds builder.
src/core/ServerOrchestrator.tsSwitches to builder usage for dependencies; adds builder; refactors startup resolution helpers.
src/core/DynamicToolManager.tsMoves options type to core.types.ts; adds builder; refactors tool enabling into helpers.
src/core/AGENTS.mdUpdates maintenance reference to root AGENTS.md.
package.jsonVersion bump 0.6.10.6.2.
README.mdUpdates client-id behavior documentation (400 on missing for /mcp endpoints).
CLAUDE.mdUpdates to point contributors/agents to root AGENTS.md intent layer.
AGENTS.mdReplaces prior agent usage doc with intent-layer root, invariants, and style rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/core/ServerOrchestrator.ts Outdated
Comment threadsrc/core/DynamicToolManager.ts Outdated
Comment threadsrc/server/createPermissionBasedMcpServer.ts Outdated
Comment threadsrc/permissions/permissions.types.ts Outdated

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadsrc/session/SessionContextResolver.ts
Comment threadsrc/types/index.ts Outdated
Comment threadsrc/http/FastifyTransport.ts
Comment threadsrc/permissions/PermissionAwareFastifyTransport.ts
Comment threadsrc/server/createPermissionBasedMcpServer.ts

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 45 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

src/http/FastifyTransport.ts:274

  • req.headers["mcp-client-id"] can be string | string[] | undefined in Fastify. Casting to string and calling .trim() can throw at runtime when the header is provided multiple times (array). Normalize first (e.g., handle Array.isArray(value) / typeof value === "string") before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();

src/permissions/PermissionAwareFastifyTransport.ts:440

  • #extractClientContext() assumes req.headers["mcp-client-id"] is a string and calls .trim(). In Fastify it may be string[], which would throw at runtime (notably for custom endpoints where you still allow anonymous IDs). Consider normalizing string | string[] | undefined before trimming.
 const clientIdHeader = (
req.headers["mcp-client-id"] as string | undefined
)?.trim();
const clientId =
clientIdHeader && clientIdHeader.length > 0
? clientIdHeader
: `anon-${randomUUID()}`;

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@imbenrabi
imbenrabi merged commit 3d77688 into mainFeb 12, 2026
7 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@imbenrabi