Repository navigation
feat: MCP server —— 用户经 /mcp 用 Bearer token 直连选题雷达 - #98
Merged
Merged
Conversation
官方 mcp SDK 2.3.0 实现 2026-07-28 无状态协议并自动兼容旧客户端;四个只读 工具镜像 skill/scoring agent 端点;认证复用个人 API token 体系;scoring 的 schema 转换辅助函数上移到 service 层供 REST 与 MCP 共用。
GHSA-54p9-h82j-f925(6.9.0 存在,6.9.1 已修)。该依赖经 yarl/aiohttp 链路 存在于 main 的锁文件,非 #95 新引入;顺手在动锁文件的 PR 里修掉,让 security-scan 的后端半边回到绿。
score_items 强制 1-50 条(与 REST/文档承诺一致);verifier 显式 commit 让 session 续期与 last_used_at 更新不被回滚;生产 Host 白名单补端口 通配防误杀;补六组参数越界用例并修正两处测试弱点;文档措辞改为 「无破坏性写」。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
给 TopicEye 增加 MCP(Model Context Protocol)server 入口:用户在网站生成个人 API token 后,在 Claude Code / ZCode 等 agent 客户端配置 Bearer header,即可直接调用
get_today_picks/get_daily_report/get_trends/score_items四个工具查询选题雷达。基于官方mcp==2.3.0,实现 2026-07-28 最新无状态协议,同一 server 自动向下协商 2025-03-26 / 2025-06-18 / 2025-11-25 旧客户端。Fixes #95
Area
TokenVerifier桥接get_user_for_token)MCP_ENABLED开关默认开)变更结构
backend/app/mcp/(与 api/v1 平级的入口层,遵守同一分层纪律)main.py挂载/mcp(json_response + stateless_http);lifespan 接管session_manager.run()rate_limit.py加 "/mcp 60/min";生产按SITE_BASE_URL开 DNS-rebinding 防护(含端口通配netloc:*)Verification
tests/test_mcp_server.py20/20(认证桥接/工具逻辑/HTTP 401 门/无状态全链路/六组参数越界)make layering✅check_agent_docs✅ruff check+format✅py_compile✅make test-backend:既有基建 flake(测试基建:模块级 engine 池化连接跨事件循环复用,全量套件概率性 mass-E #97,cross-loop 池化连接,纯 main 子集同样复现)之外绿次 EXIT=0;CI 六项为权威Verifier verdict(独立测评,2026-10-07)
静态复核(独立 agent,全新鲜上下文):approve-with-comments → 发现项已全部闭合。
score_items未强制 1-50 条(文档承诺 vs 实现缺口)→ 已修(参数级Field(min_length=1, max_length=50))+ 6 组越界用例netloc:*)动态测评(真实服务 + 官方 SDK 客户端,14 项全部通过):
www-authenticate(RFC 6750/9728 发现链);RFC 9728 PRM 元数据正确,SITE_BASE_URL→issuer/resource链路贯通MCP_ENABLED=false→/mcp404结论:approve。 复核发现全部闭合后重跑 20/20 通过。
已知预存红(非本 PR 引入,均显式登记)
security-scan前端半边:eslint 链 6 high(AGENTS.md 4.4)+ 新近 brace-expansion/sharp advisory;package.json/package-lock.json未触碰ruff format --check对app/api/v1/contents.py、tests_oauth_patch/test_account_link_security.py的 drift(main 同样存在;CI backend-lint 不含 format 检查)非目标(v2 候选)
写操作工具、trending 热榜/证据下钻工具、OAuth 授权服务器(自动授权)、前端「连接 MCP」引导页。