feat(resolvemcp): add read-only mode and function allowlist

- Config.ReadOnly disables insert/update/delete/annotation tools, reports only
  select in list_tables/describe_table and tells the agent it cannot write
- Config.AllowFunctionCalls keeps function tools on a read-only server
- Config.AllowedFunctions limits list_functions/call_function to named
  functions (empty allows all); others are reported as unknown
- reflect read-only mode in the usage guide and exported catalogue
This commit is contained in:
Hein
2026-10-07 14:15:14 +02:00
parent 431b674162
commit 4ed9506ad2
7 changed files with 274 additions and 12 deletions
+13 -1
View File
@@ -108,6 +108,15 @@ func (h *Handler) function(name string) (Function, bool) {
return f, ok
}
// functionAllowed reports whether Config.AllowedFunctions lets the function through.
func (h *Handler) functionAllowed(name string) bool {
if h.allowedFns == nil {
return true
}
_, ok := h.allowedFns[name]
return ok
}
// visibleFunctions returns the functions the caller may call, sorted by name.
func (h *Handler) visibleFunctions(ctx context.Context) []Function {
h.functions.mu.RLock()
@@ -119,6 +128,9 @@ func (h *Handler) visibleFunctions(ctx context.Context) []Function {
sort.Slice(out, func(i, j int) bool { return out[i].Name < out[j].Name })
visible := out[:0]
for _, f := range out {
if !h.functionAllowed(f.Name) {
continue
}
if f.Authorize == nil || f.Authorize(ctx) == nil {
visible = append(visible, f)
}
@@ -236,7 +248,7 @@ func (h *Handler) executeCall(ctx context.Context, name string, rawArgs map[stri
defer cancel()
f, ok := h.function(name)
if !ok {
if !ok || !h.functionAllowed(name) {
return nil, invalidArg("unknown function %q", truncate(name))
}
hookCtx := &HookContext{Context: ctx, Handler: h, Entity: name, Operation: "call_function", Tx: h.db}