Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion services/mcp/schema/tool-definitions-all.json
Original file line number Diff line number Diff line change
Expand Up @@ -4959,7 +4959,7 @@
"feature": "sql",
"summary": "Execute an SQL query.",
"title": "Execute SQL query",
"required_scopes": ["query:read", "insight:read"],
"required_scopes": ["query:read"],
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
Expand Down
2 changes: 1 addition & 1 deletion services/mcp/schema/tool-definitions.json
Original file line number Diff line number Diff line change
Expand Up @@ -753,7 +753,7 @@
"feature": "sql",
"summary": "Execute an SQL query.",
"title": "Execute SQL query",
"required_scopes": ["query:read", "insight:read"],
"required_scopes": ["query:read"],
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
Expand Down
6 changes: 3 additions & 3 deletions services/mcp/tests/integration/mcp-protocol-suite.ts
Original file line number Diff line number Diff line change
Expand Up @@ -1253,8 +1253,8 @@ export function defineToolBehaviorTests(
// `SELECT 1 AS one` doesn't depend on any ingested data, so it works
// against a freshly-booted local stack with no seed data.
//
// The tool is gated by `query:read` + `insight:read` scopes — if the
// test API key doesn't carry them, execute-sql won't be in the
// The tool is gated by the `query:read` scope — if the
// test API key doesn't carry it, execute-sql won't be in the
// catalog and we skip rather than fail (a different test would
// catch the scope-filter regression).
Comment thread
JakeRuth marked this conversation as resolved.
it('execute-sql runs a trivial HogQL query against the upstream', async ({ skip }) => {
Expand All @@ -1264,7 +1264,7 @@ export function defineToolBehaviorTests(
}
const { tools } = await client.listTools()
if (!tools.some((t) => t.name === 'execute-sql')) {
skip('execute-sql not in catalog for this token — needs query:read + insight:read scopes.')
skip('execute-sql not in catalog for this token — needs the query:read scope.')
return
}
await client.callTool({
Expand Down
3 changes: 2 additions & 1 deletion services/mcp/tests/unit/tool-filtering.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -343,12 +343,13 @@ describe('Tool Filtering - API Scopes', () => {
})

it('should only return read tools when user has read scope', async () => {
const context = createMockContext(['insight:read', 'query:read'])
const context = createMockContext(['query:read'])
const tools = await getToolsFromContext(context)
const toolNames = tools.map((t) => t.name)

// insight-query is in the hand-written TOOL_MAP and requires query:read
expect(toolNames).toContain('insight-query')
expect(toolNames).toContain('execute-sql')

expect(toolNames).not.toContain('dashboard-create')
})
Expand Down
Loading