fix(mcp): align read report tools with requireRepoAccess - #8375
fix(mcp): align read report tools with requireRepoAccess#8375jsdevninja wants to merge 1 commit into
Conversation
Closes JSONbored#8338. getMaintainerNoise, getAmsMinerCohort, and getActivationPreview now use requireRepoAccess like their REST mirrors and sibling read tools, instead of the live-write requireRepoApprovalQueueAccess gate reserved for approval-queue writes.
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8375 +/- ##
==========================================
- Coverage 92.17% 88.06% -4.12%
==========================================
Files 791 98 -693
Lines 79245 23855 -55390
Branches 23946 4091 -19855
==========================================
- Hits 73044 21007 -52037
+ Misses 5062 2638 -2424
+ Partials 1139 210 -929
Flags with carried forward coverage won't be shown. Click here to find out more.
|
|
Caution 🛑 LoopOver review result - fixes requiredReview updated: 2026-07-24 11:09:50 UTC
Review summary Nits — 4 non-blocking
CI checks failing
Decision drivers
Context & advisory signals — never blocks the verdict
Linked issue satisfactionAddressed Review context
Contributor next steps
Signal definitions
🧪 Chat with LoopOverAsk LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.
Full command reference: https://loopover.ai/docs/loopover-commands 🧪 Experimental — new and may change. 🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed 💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →. Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.
|
|
LoopOver is closing this pull request on the maintainer's behalf (CI is failing (validate, validate-tests (3))). This is an automated maintenance action — to pursue this change, please open a new pull request with the issues resolved. Closed PRs may be analyzed later to improve review accuracy, but they are not automatically reopened or re-reviewed. |
Summary
getMaintainerNoise,getAmsMinerCohort, andgetActivationPreviewnow callrequireRepoAccessinstead of the stricter live-writerequireRepoApprovalQueueAccess, matching their REST mirrors (requireRepoMaintainer) and every sibling read-only maintainer report tool.Scope
type(scope): short summaryConventional Commit format, for examplefix(api): restore profile access checks.CONTRIBUTING.mdand does not reintroduce GitHub Pages, VitePress,site/, orCNAME.Closes #123) — a linked open issue is required for every contributor PR.Validation
git diff --checknpm run actionlintnpm run typechecknpm run test:coveragelocally;codecov/patchrequires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.npm run test:workersnpm run build:mcpnpm run test:mcp-packnpm run ui:openapi:checknpm run ui:lintnpm run ui:typechecknpm run ui:buildnpm audit --audit-level=moderateIf any required check was skipped, explain why:
npx vitest run test/unit/mcp-read-report-gate-parity.test.ts(3 passing) andnpm run typecheckafter@loopover/enginebuild. Fulltest:ci/ coverage deferred to Linux CI (known Windows path issues on this machine). No OpenAPI/route changes.Safety
UI Evidencesection below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.UI Evidence
N/A — MCP auth gate alignment only; no visible UI change.
Notes
getRepoOutcomePatterns/getIssueQuality/getGatePrecisionalready userequireRepoAccess.