f929c58c6b
* Add CSV output for list tools under insiders mode * fix: resolve rebase feature flag conflicts Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Simplify feature-flag handling: collapse CSV dual-variant + skip filtering when no checker (#2516) * refactor: generic toolset+name sort, clarify feature flag intent Address review feedback on #2450: - Collapse the three near-identical sort helpers in pkg/inventory/filters.go into a generic sortByToolsetThenName so adding new inventory item types doesn't require copying the comparator. - Expand the doc comments on the three *WithoutFeatureFiltering helpers to spell out why they exist: HTTP mode builds a static (process-wide) inventory as an upper bound, but per-request feature flags from headers (X-MCP-Features, X-MCP-Insiders) are evaluated later, so feature-flagged variants must be preserved here. - Strengthen the doc comment on ResolveFeatureFlags to make the contract explicit: user-supplied flags are validated against AllowedFeatureFlags, but insiders expansion deliberately is not — InsidersFeatureFlags may include server-controlled flags that are not user-toggleable. CORS comments are intentionally left for the PR author. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs(feature-flags): clarify allowed and insiders sets are independent Also add tests covering: - a user-toggleable flag (FeatureFlagIssuesGranular) that insiders does not turn on automatically - insiders mode not turning on user-only allowed flags Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * refactor(inventory): collapse three *WithoutFeatureFiltering helpers into StaticUpperBound The three parallel methods (AvailableToolsWithoutFeatureFiltering, AvailableResourceTemplatesWithoutFeatureFiltering, AvailablePromptsWithoutFeatureFiltering) were always called as a triple in exactly two places: HTTP buildStaticInventory and its test mirror. They exist because the dual-variant pattern (sibling tools with mirrored FeatureFlagEnable / FeatureFlagDisable on the same name, e.g. CSV output) makes feature filtering at static-build time impossible — both variants must be kept and resolved per-request. Replace the three with one method, Inventory.StaticUpperBound(ctx), that returns (tools, resources, prompts) and carries the rationale in its doc comment. Reduces API surface, eliminates the triplication, and makes the single "skip feature filtering" concept obvious to readers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * refactor: simplify feature-flag handling Two related simplifications, both about treating insiders as a meta flag that expands once at startup and then stops mattering: - Collapse CSV's dual-variant pattern into a single tool whose handler performs a runtime feature-flag check via deps.IsFeatureEnabled. CSV is a pure response-format toggle, not a schema change, so it does not need the dual-name pattern that genuine schema variants (granular issues/PRs) still use. - When no feature checker is installed, skip feature-flag filtering and return the full upper bound. The static HTTP inventory now uses plain AvailableTools/Resources/Prompts; the per-request inventory always installs a checker, so MCP registration (which serves a tool name once) always sees a deduplicated set. The bespoke StaticUpperBound helper and the isToolEnabledWithFeatureFlags split go away. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * ci(mcp-diff): add insiders + per-feature configs The mcp-diff matrix now includes: - --insiders (and --insiders --read-only) - one config per github.AllowedFeatureFlags entry, generated by script/print-mcp-diff-configs so new user-controllable flags get diffed automatically without editing the workflow Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs(insiders): explain feature-flag resolution for contributors Adds a 'How feature flags are resolved' section covering: - Insiders is a meta flag, like 'all'/'default' for toolsets - User input -> allowlist filter -> insiders expansion -> server-side fallback (remote only) - AllowedFeatureFlags vs InsidersFeatureFlags are independent - How to add a new feature flag, including the TestGitHubPackageDoesNotReadInsidersMode guard Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * refactor(inventory): make feature-flag gating a regular ToolFilter Move tool feature-flag evaluation out of isToolEnabled and into a ToolFilter installed at the head of the pipeline by Build() when WithFeatureChecker received a non-nil checker. The 'no checker = no filtering' contract is now expressed structurally (the filter isn't installed) instead of by a runtime nil check inside the helper. Resources and prompts have no filter pipeline, so they call the now-pure featureFlagAllowed helper behind an explicit r.featureChecker != nil guard at the iteration site. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * perf(inventory): cache extracted toolset IDs in sort comparator Avoid evaluating the extractor closures up to three times per comparison. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: correct MCP features header in cors * docs: regenerate README for CSV output toolset Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: remove duplicate MCPFeaturesHeader from CORS headers * ci(mcp-diff): add streamable-http job with header-based configs Adds a sibling mcp-diff-http job that exercises the streamable-http transport against a shared HTTP server, with per-config settings supplied via X-MCP-* request headers — mirroring how the remote server is invoked in production (server-side defaults + per-user header overrides). The config generator gains a -transport flag: - stdio (default, unchanged behaviour) - http-headers (emits headers-only configs targeting a shared server) Two new combined entries layer multiple headers together as a smoke test for header-merging regressions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: regenerate after merging main Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Sam Morrow <info@sam-morrow.com> Co-authored-by: sammorrowdrums <sammorrowdrums@github.com>
299 lines
9.8 KiB
Go
299 lines
9.8 KiB
Go
package github
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"time"
|
|
|
|
ghErrors "github.com/github/github-mcp-server/pkg/errors"
|
|
"github.com/github/github-mcp-server/pkg/ifc"
|
|
"github.com/github/github-mcp-server/pkg/inventory"
|
|
"github.com/github/github-mcp-server/pkg/scopes"
|
|
"github.com/github/github-mcp-server/pkg/translations"
|
|
"github.com/github/github-mcp-server/pkg/utils"
|
|
"github.com/google/jsonschema-go/jsonschema"
|
|
"github.com/modelcontextprotocol/go-sdk/mcp"
|
|
"github.com/shurcooL/githubv4"
|
|
)
|
|
|
|
// GetMeUIResourceURI is the URI for the get_me tool's MCP App UI resource.
|
|
const GetMeUIResourceURI = "ui://github-mcp-server/get-me"
|
|
|
|
// UserDetails contains additional fields about a GitHub user not already
|
|
// present in MinimalUser. Used by get_me context tool but omitted from search_users.
|
|
type UserDetails struct {
|
|
Name string `json:"name,omitempty"`
|
|
Company string `json:"company,omitempty"`
|
|
Blog string `json:"blog,omitempty"`
|
|
Location string `json:"location,omitempty"`
|
|
Email string `json:"email,omitempty"`
|
|
Hireable bool `json:"hireable,omitempty"`
|
|
Bio string `json:"bio,omitempty"`
|
|
TwitterUsername string `json:"twitter_username,omitempty"`
|
|
PublicRepos int `json:"public_repos"`
|
|
PublicGists int `json:"public_gists"`
|
|
Followers int `json:"followers"`
|
|
Following int `json:"following"`
|
|
CreatedAt time.Time `json:"created_at"`
|
|
UpdatedAt time.Time `json:"updated_at"`
|
|
PrivateGists int `json:"private_gists,omitempty"`
|
|
TotalPrivateRepos int64 `json:"total_private_repos,omitempty"`
|
|
OwnedPrivateRepos int64 `json:"owned_private_repos,omitempty"`
|
|
}
|
|
|
|
// GetMe creates a tool to get details of the authenticated user.
|
|
func GetMe(t translations.TranslationHelperFunc) inventory.ServerTool {
|
|
return NewTool(
|
|
ToolsetMetadataContext,
|
|
mcp.Tool{
|
|
Name: "get_me",
|
|
Description: t("TOOL_GET_ME_DESCRIPTION", "Get details of the authenticated GitHub user. Use this when a request is about the user's own profile for GitHub. Or when information is missing to build other tool calls."),
|
|
Annotations: &mcp.ToolAnnotations{
|
|
Title: t("TOOL_GET_ME_USER_TITLE", "Get my user profile"),
|
|
ReadOnlyHint: true,
|
|
},
|
|
// Use json.RawMessage to ensure "properties" is included even when empty.
|
|
// OpenAI strict mode requires the properties field to be present.
|
|
InputSchema: json.RawMessage(`{"type":"object","properties":{}}`),
|
|
Meta: mcp.Meta{
|
|
"ui": map[string]any{
|
|
"resourceUri": GetMeUIResourceURI,
|
|
"visibility": []string{"model", "app"},
|
|
},
|
|
},
|
|
},
|
|
nil,
|
|
func(ctx context.Context, deps ToolDependencies, _ *mcp.CallToolRequest, _ map[string]any) (*mcp.CallToolResult, any, error) {
|
|
client, err := deps.GetClient(ctx)
|
|
if err != nil {
|
|
return utils.NewToolResultErrorFromErr("failed to get GitHub client", err), nil, nil
|
|
}
|
|
|
|
user, res, err := client.Users.Get(ctx, "")
|
|
if err != nil {
|
|
return ghErrors.NewGitHubAPIErrorResponse(ctx,
|
|
"failed to get user",
|
|
res,
|
|
err,
|
|
), nil, nil
|
|
}
|
|
|
|
// Create minimal user representation instead of returning full user object
|
|
minimalUser := MinimalUser{
|
|
Login: user.GetLogin(),
|
|
ID: user.GetID(),
|
|
ProfileURL: user.GetHTMLURL(),
|
|
AvatarURL: user.GetAvatarURL(),
|
|
Details: &UserDetails{
|
|
Name: user.GetName(),
|
|
Company: user.GetCompany(),
|
|
Blog: user.GetBlog(),
|
|
Location: user.GetLocation(),
|
|
Email: user.GetEmail(),
|
|
Hireable: user.GetHireable(),
|
|
Bio: user.GetBio(),
|
|
TwitterUsername: user.GetTwitterUsername(),
|
|
PublicRepos: user.GetPublicRepos(),
|
|
PublicGists: user.GetPublicGists(),
|
|
Followers: user.GetFollowers(),
|
|
Following: user.GetFollowing(),
|
|
CreatedAt: user.GetCreatedAt().Time,
|
|
UpdatedAt: user.GetUpdatedAt().Time,
|
|
PrivateGists: user.GetPrivateGists(),
|
|
TotalPrivateRepos: user.GetTotalPrivateRepos(),
|
|
OwnedPrivateRepos: user.GetOwnedPrivateRepos(),
|
|
},
|
|
}
|
|
|
|
result := MarshalledTextResult(minimalUser)
|
|
if deps.IsFeatureEnabled(ctx, FeatureFlagIFCLabels) {
|
|
if result.Meta == nil {
|
|
result.Meta = mcp.Meta{}
|
|
}
|
|
result.Meta["ifc"] = ifc.LabelGetMe()
|
|
}
|
|
return result, nil, nil
|
|
},
|
|
)
|
|
}
|
|
|
|
type TeamInfo struct {
|
|
Name string `json:"name"`
|
|
Slug string `json:"slug"`
|
|
Description string `json:"description"`
|
|
}
|
|
|
|
type OrganizationTeams struct {
|
|
Org string `json:"org"`
|
|
Teams []TeamInfo `json:"teams"`
|
|
}
|
|
|
|
func GetTeams(t translations.TranslationHelperFunc) inventory.ServerTool {
|
|
return NewTool(
|
|
ToolsetMetadataContext,
|
|
mcp.Tool{
|
|
Name: "get_teams",
|
|
Description: t("TOOL_GET_TEAMS_DESCRIPTION", "Get details of the teams the user is a member of. Limited to organizations accessible with current credentials"),
|
|
Annotations: &mcp.ToolAnnotations{
|
|
Title: t("TOOL_GET_TEAMS_TITLE", "Get teams"),
|
|
ReadOnlyHint: true,
|
|
},
|
|
InputSchema: &jsonschema.Schema{
|
|
Type: "object",
|
|
Properties: map[string]*jsonschema.Schema{
|
|
"user": {
|
|
Type: "string",
|
|
Description: t("TOOL_GET_TEAMS_USER_DESCRIPTION", "Username to get teams for. If not provided, uses the authenticated user."),
|
|
},
|
|
},
|
|
},
|
|
},
|
|
[]scopes.Scope{scopes.ReadOrg},
|
|
func(ctx context.Context, deps ToolDependencies, _ *mcp.CallToolRequest, args map[string]any) (*mcp.CallToolResult, any, error) {
|
|
user, err := OptionalParam[string](args, "user")
|
|
if err != nil {
|
|
return utils.NewToolResultError(err.Error()), nil, nil
|
|
}
|
|
|
|
var username string
|
|
if user != "" {
|
|
username = user
|
|
} else {
|
|
client, err := deps.GetClient(ctx)
|
|
if err != nil {
|
|
return utils.NewToolResultErrorFromErr("failed to get GitHub client", err), nil, nil
|
|
}
|
|
|
|
userResp, res, err := client.Users.Get(ctx, "")
|
|
if err != nil {
|
|
return ghErrors.NewGitHubAPIErrorResponse(ctx,
|
|
"failed to get user",
|
|
res,
|
|
err,
|
|
), nil, nil
|
|
}
|
|
username = userResp.GetLogin()
|
|
}
|
|
|
|
gqlClient, err := deps.GetGQLClient(ctx)
|
|
if err != nil {
|
|
return utils.NewToolResultErrorFromErr("failed to get GitHub GQL client", err), nil, nil
|
|
}
|
|
|
|
var q struct {
|
|
User struct {
|
|
Organizations struct {
|
|
Nodes []struct {
|
|
Login githubv4.String
|
|
Teams struct {
|
|
Nodes []struct {
|
|
Name githubv4.String
|
|
Slug githubv4.String
|
|
Description githubv4.String
|
|
}
|
|
} `graphql:"teams(first: 100, userLogins: [$login])"`
|
|
}
|
|
} `graphql:"organizations(first: 100)"`
|
|
} `graphql:"user(login: $login)"`
|
|
}
|
|
vars := map[string]any{
|
|
"login": githubv4.String(username),
|
|
}
|
|
if err := gqlClient.Query(ctx, &q, vars); err != nil {
|
|
return ghErrors.NewGitHubGraphQLErrorResponse(ctx, "Failed to find teams", err), nil, nil
|
|
}
|
|
|
|
var organizations []OrganizationTeams
|
|
for _, org := range q.User.Organizations.Nodes {
|
|
orgTeams := OrganizationTeams{
|
|
Org: string(org.Login),
|
|
Teams: make([]TeamInfo, 0, len(org.Teams.Nodes)),
|
|
}
|
|
|
|
for _, team := range org.Teams.Nodes {
|
|
orgTeams.Teams = append(orgTeams.Teams, TeamInfo{
|
|
Name: string(team.Name),
|
|
Slug: string(team.Slug),
|
|
Description: string(team.Description),
|
|
})
|
|
}
|
|
|
|
organizations = append(organizations, orgTeams)
|
|
}
|
|
|
|
return MarshalledTextResult(organizations), nil, nil
|
|
},
|
|
)
|
|
}
|
|
|
|
func GetTeamMembers(t translations.TranslationHelperFunc) inventory.ServerTool {
|
|
return NewTool(
|
|
ToolsetMetadataContext,
|
|
mcp.Tool{
|
|
Name: "get_team_members",
|
|
Description: t("TOOL_GET_TEAM_MEMBERS_DESCRIPTION", "Get member usernames of a specific team in an organization. Limited to organizations accessible with current credentials"),
|
|
Annotations: &mcp.ToolAnnotations{
|
|
Title: t("TOOL_GET_TEAM_MEMBERS_TITLE", "Get team members"),
|
|
ReadOnlyHint: true,
|
|
},
|
|
InputSchema: &jsonschema.Schema{
|
|
Type: "object",
|
|
Properties: map[string]*jsonschema.Schema{
|
|
"org": {
|
|
Type: "string",
|
|
Description: t("TOOL_GET_TEAM_MEMBERS_ORG_DESCRIPTION", "Organization login (owner) that contains the team."),
|
|
},
|
|
"team_slug": {
|
|
Type: "string",
|
|
Description: t("TOOL_GET_TEAM_MEMBERS_TEAM_SLUG_DESCRIPTION", "Team slug"),
|
|
},
|
|
},
|
|
Required: []string{"org", "team_slug"},
|
|
},
|
|
},
|
|
[]scopes.Scope{scopes.ReadOrg},
|
|
func(ctx context.Context, deps ToolDependencies, _ *mcp.CallToolRequest, args map[string]any) (*mcp.CallToolResult, any, error) {
|
|
org, err := RequiredParam[string](args, "org")
|
|
if err != nil {
|
|
return utils.NewToolResultError(err.Error()), nil, nil
|
|
}
|
|
|
|
teamSlug, err := RequiredParam[string](args, "team_slug")
|
|
if err != nil {
|
|
return utils.NewToolResultError(err.Error()), nil, nil
|
|
}
|
|
|
|
gqlClient, err := deps.GetGQLClient(ctx)
|
|
if err != nil {
|
|
return utils.NewToolResultErrorFromErr("failed to get GitHub GQL client", err), nil, nil
|
|
}
|
|
|
|
var q struct {
|
|
Organization struct {
|
|
Team struct {
|
|
Members struct {
|
|
Nodes []struct {
|
|
Login githubv4.String
|
|
}
|
|
} `graphql:"members(first: 100)"`
|
|
} `graphql:"team(slug: $teamSlug)"`
|
|
} `graphql:"organization(login: $org)"`
|
|
}
|
|
vars := map[string]any{
|
|
"org": githubv4.String(org),
|
|
"teamSlug": githubv4.String(teamSlug),
|
|
}
|
|
if err := gqlClient.Query(ctx, &q, vars); err != nil {
|
|
return ghErrors.NewGitHubGraphQLErrorResponse(ctx, "Failed to get team members", err), nil, nil
|
|
}
|
|
|
|
var members []string
|
|
for _, member := range q.Organization.Team.Members.Nodes {
|
|
members = append(members, string(member.Login))
|
|
}
|
|
|
|
return MarshalledTextResult(members), nil, nil
|
|
},
|
|
)
|
|
}
|