feat(resolvemcp)!: make the server read-only by default
Tests / Integration Tests (push) Skipped
Build , Vet Test, and Lint / Build (push) Successful in 1m33s
Tests / Unit Tests (push) Successful in 2m1s
Build , Vet Test, and Lint / Run Vet Tests (1.23.x) (push) Successful in 2m36s
Build , Vet Test, and Lint / Run Vet Tests (1.24.x) (push) Successful in 2m38s
Build , Vet Test, and Lint / Lint Code (push) Successful in 2m49s
Tests / Race Detector (push) Successful in 4m31s

BREAKING CHANGE: Config.ReadOnly is now a *bool and unset means read-only.
Use ReadOnly: resolvemcp.Bool(false) to enable insert/update/delete,
annotations and function calls. Adds the Bool helper and updates docs.
This commit is contained in:
Hein
2026-10-07 14:17:56 +02:00
parent 4ed9506ad2
commit 5a3a1df3c8
9 changed files with 62 additions and 28 deletions
+6 -6
View File
@@ -56,10 +56,10 @@ func registerMetaTools(h *Handler) {
mcp.WithBoolean("include_count", mcp.Description("Also return the total number of matching rows (slower on large tables).")),
), h.handleSelect)
if !h.config.ReadOnly {
if !h.config.readOnly {
registerWriteTools(h, tableArg, idArg, filtersArg, dryRunArg, confirmArg)
}
if !h.config.ReadOnly || h.config.AllowFunctionCalls {
if !h.config.readOnly || h.config.AllowFunctionCalls {
registerFunctionTools(h, readOnly)
}
}
@@ -130,7 +130,7 @@ func (h *Handler) opsFor(r modelregistry.ModelRules) []string {
if r.CanRead {
ops = append(ops, opSelect)
}
if h.config.ReadOnly {
if h.config.readOnly {
return ops
}
if r.CanCreate {
@@ -157,7 +157,7 @@ func (h *Handler) resolveTable(args map[string]any, op string) (schema, entity s
if _, err := h.registry.GetModelByEntity(schema, entity); err != nil {
return "", "", invalidArg("unknown table %q; see list_tables", truncate(table))
}
if op != "" && op != opSelect && h.config.ReadOnly {
if op != "" && op != opSelect && h.config.readOnly {
return "", "", NewClientError(CodeForbidden, "this server is read-only: writes are disabled")
}
if op != "" {
@@ -212,7 +212,7 @@ func (h *Handler) handleDescribeTable(_ context.Context, req mcp.CallToolRequest
modelType = modelType.Elem()
}
writable := map[string]bool{}
if !h.config.ReadOnly && modelType != nil && modelType.Kind() == reflect.Struct {
if !h.config.readOnly && modelType != nil && modelType.Kind() == reflect.Struct {
for jsonKey := range reflection.BuildJSONToDBColumnMap(modelType) {
writable[jsonKey] = true
}
@@ -251,7 +251,7 @@ func (h *Handler) handleDescribeTable(_ context.Context, req mcp.CallToolRequest
"relations": info.relationNames,
"writable_columns": writableNames,
"operations": h.opsFor(rules),
"read_only": h.config.ReadOnly,
"read_only": h.config.readOnly,
"filter_operators": filterOperators,
"limits": map[string]any{
"default_limit": h.config.DefaultLimit,