Skip to content

fix(mcp): align read report tools with requireRepoAccess - #8375

Closed
jsdevninja wants to merge 1 commit into
JSONbored:mainfrom
jsdevninja:fix/mcp-read-report-gate-parity
Closed

fix(mcp): align read report tools with requireRepoAccess#8375
jsdevninja wants to merge 1 commit into
JSONbored:mainfrom
jsdevninja:fix/mcp-read-report-gate-parity

Conversation

@jsdevninja

Copy link
Copy Markdown
Contributor

Summary

  • Closes getMaintainerNoise/getAmsMinerCohort/getActivationPreview use a stricter MCP gate than their documented REST mirror #8338: getMaintainerNoise, getAmsMinerCohort, and getActivationPreview now call requireRepoAccess instead of the stricter live-write requireRepoApprovalQueueAccess, matching their REST mirrors (requireRepoMaintainer) and every sibling read-only maintainer report tool.
  • Inline comments updated to describe the correct gate. Write/approval-queue tools are untouched.
  • In-process regression test: cached COLLABORATOR/owner scope succeeds when live collaborator lookup fails; non-maintainer sessions are still rejected on all three tools.

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage locally; codecov/patch requires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:build
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

  • Focused validation: npx vitest run test/unit/mcp-read-report-gate-parity.test.ts (3 passing) and npm run typecheck after @loopover/engine build. Full test:ci / coverage deferred to Linux CI (known Windows path issues on this machine). No OpenAPI/route changes.

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

N/A — MCP auth gate alignment only; no visible UI change.

Notes

  • Analogues: getRepoOutcomePatterns / getIssueQuality / getGatePrecision already use requireRepoAccess.

Closes JSONbored#8338. getMaintainerNoise, getAmsMinerCohort, and
getActivationPreview now use requireRepoAccess like their REST
mirrors and sibling read tools, instead of the live-write
requireRepoApprovalQueueAccess gate reserved for approval-queue
writes.
@jsdevninja
jsdevninja requested a review from JSONbored as a code owner July 24, 2026 11:01
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jul 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.06%. Comparing base (2ae66d6) to head (300c497).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8375      +/-   ##
==========================================
- Coverage   92.17%   88.06%   -4.12%     
==========================================
  Files         791       98     -693     
  Lines       79245    23855   -55390     
  Branches    23946     4091   -19855     
==========================================
- Hits        73044    21007   -52037     
+ Misses       5062     2638    -2424     
+ Partials     1139      210     -929     
Flag Coverage Δ
shard-1 45.86% <0.00%> (-7.80%) ⬇️
shard-2 40.81% <100.00%> (-10.03%) ⬇️
shard-3 ?

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/mcp/server.ts 57.96% <100.00%> (-38.65%) ⬇️

... and 693 files with indirect coverage changes

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 24, 2026
@loopover-orb

loopover-orb Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Caution

🛑 LoopOver review result - fixes required

Review updated: 2026-07-24 11:09:50 UTC

2 files · 1 AI reviewer · no blockers · CI failing · blocked

🛑 Suggested Action - Fix Blockers

Review summary
The AI review returned non-blocking notes for this change but did not include a separate narrative summary. Review the nits below before deciding this PR.

Nits — 4 non-blocking
  • The two FAILED CI checks (validate, validate-tests (3)) show no detail, and given the branch is 2 commits behind default, this is more likely explained by drift from the base branch than a defect in this diff — worth rebasing before merge to confirm.
  • test/unit/mcp-read-report-gate-parity.test.ts declares seedOwnedRepo as async but never awaits anything conditionally inside branches beyond the calls shown — fine as-is, just flagging for readability that the helper name could clarify it seeds an owner-associated repo only.
  • Rebase onto the current default branch (2 commits behind) to rule out the undetailed validate / validate-tests (3) failures before merge.
  • Consider adding a short assertion in the regression test that requireRepoApprovalQueueAccess (or the live collaborator check) is still invoked by a sibling write tool, to make the parity claim self-verifying rather than just asserting non-invocation on the read tools.

CI checks failing

  • validate
  • validate-tests (3)

Decision drivers

  • ✅ Code review — No blockers (1 reviewer)
  • ✅ Gate result — Passing (No configured blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #8338
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (1 linked issue).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 210 registered-repo PR(s), 127 merged, 39 issue(s).
Contributor context ✅ Confirmed Gittensor contributor jsdevninja; Gittensor profile; 210 PR(s), 39 issue(s).
Improvement ✅ Minor risk: clean · value: minor · LLM: moderate
Linked issue satisfaction

Addressed
The diff changes all three handlers to call requireRepoAccess instead of requireRepoApprovalQueueAccess, updates the stale inline comments to describe the correct gate and REST mirror, and adds an in-process regression test verifying cached-maintainer success despite a failing live collaborator lookup plus rejection for non-maintainer sessions.

Review context
  • Author: jsdevninja
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: JavaScript, Swift, C, CSS, MDX, Python, TypeScript, Vue
  • Official Gittensor activity: 210 PR(s), 39 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Triage stale or unlinked PRs.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb

loopover-orb Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

LoopOver is closing this pull request on the maintainer's behalf (CI is failing (validate, validate-tests (3))). This is an automated maintenance action — to pursue this change, please open a new pull request with the issues resolved. Closed PRs may be analyzed later to improve review accuracy, but they are not automatically reopened or re-reviewed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

getMaintainerNoise/getAmsMinerCohort/getActivationPreview use a stricter MCP gate than their documented REST mirror

1 participant