mcp修复
This commit is contained in:
1 parent
801c0af692
commit
3080b17d02
9 files changed
+378
-73
No files matched your search
@@ -3,13 +3,12 @@
|
||||
"mcpServers": {
|
||||
"fire-safety-ymd-spatial-readonly": {
|
||||
"transport": "http",
|
||||
"protocolVersion": "2025-06-18",
|
||||
"url": "https://<fire-safety-server-domain>/mcp",
|
||||
"method": "POST",
|
||||
"headers": {
|
||||
"Authorization": "Bearer ${FIRE_SAFETY_MCP_AUTH_TOKEN}",
|
||||
"Content-Type": "application/json",
|
||||
"Accept": "application/json"
|
||||
"Accept": "application/json, text/event-stream"
|
||||
},
|
||||
"tools": {
|
||||
"allow": [
|
||||
@@ -25,6 +24,7 @@
|
||||
},
|
||||
"runtimeNotes": {
|
||||
"authTokenSource": "Use a separate per-environment high-entropy secret; never reuse the SuperAgent Open API Key.",
|
||||
"protocolCompatibility": "SuperAgent cannot configure protocolVersion here. The fire-safety-ymd server follows the proven th-hotel-simple-superagent compatibility profile: it does not use initialize.params.protocolVersion or MCP-Protocol-Version as version refusal gates and always returns protocolVersion 2025-06-18. This is a compatibility response, not support for arbitrary client versions or a latest-version target. Do not add a protocol-version or protocol-header setting.",
|
||||
"scopeSource": "The all or town-allowlist data scope is configured on the fire-safety-ymd server and is never supplied by tool arguments.",
|
||||
"safety": "Results are planning evidence only. Invalid source geometries are excluded, so results may be incomplete. Availability, passability, command-post suitability, live team positions and assembly sites require field confirmation."
|
||||
}
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
|
||||
| 项 | 内容 |
|
||||
| --- | --- |
|
||||
| 状态 | 代码已实现;实库严格 readiness 与本地 7 工具冒烟已通过,公网/SuperAgent 联调待执行 |
|
||||
| 状态 | 代码已实现;实库严格 readiness 与本地 7 工具冒烟已通过;同一 SuperAgent 中 `th-hotel-simple-superagent` 已稳定启用/调用并作为兼容档案参照;公网 `/mcp` 已到达 Go,但旧版本门禁曾返回错误,消防服务的兼容档案仍需部署后按完整调用链重测 |
|
||||
| Endpoint | `POST /mcp` |
|
||||
| MCP 版本 | `2025-06-18` |
|
||||
| MCP 响应版本 | 固定返回 `2025-06-18` |
|
||||
| 传输 | 单 JSON 请求/响应;不提供服务端 SSE |
|
||||
| 数据源 | PostgreSQL/PostGIS,固定只读查询 |
|
||||
|
||||
@@ -20,6 +20,18 @@ flowchart LR
|
||||
|
||||
SuperAgent Open API Key 用于本服务调用 SuperAgent;MCP Token 用于 SuperAgent 回调本服务。两者方向、权限和生命周期不同,必须使用不同 Secret。
|
||||
|
||||
## SuperAgent 兼容档案
|
||||
|
||||
SuperAgent 当前不能在 MCP 服务配置中填写或固定 `protocolVersion`;配置只需要 URL、HTTP 方法和独立 Bearer。已稳定接通的 `th-hotel-simple-superagent` 不读取 `initialize.params.protocolVersion`,也不读取或校验 `MCP-Protocol-Version` Header,而是固定返回 `2025-06-18`,并正常执行 `notifications/initialized`、`tools/list` 和 `tools/call`;工具结果同时提供 `structuredContent`。消防 MCP 按同一已验证档案接入,目标是打通工具调用,不是追求最新协议。
|
||||
|
||||
本服务端固定返回 `2025-06-18`:
|
||||
|
||||
- 可解析的 JSON-RPC `initialize` 中,`params.protocolVersion` 的缺失、空值、非字符串或其他值,都不单独触发版本拒绝,响应中的 `result.protocolVersion` 始终为 `2025-06-18`。
|
||||
- `MCP-Protocol-Version` Header 的缺失或值同样不作为版本拒绝门禁;SuperAgent 配置中无需增加该 Header 或任何版本字段。
|
||||
- 固定返回 `2025-06-18` 不表示服务实现或声明支持客户端填写的任意版本,也不把 `2025-03-26`、`2025-11-25` 列为实现目标;这是为了兼容已稳定接通的客户端。
|
||||
|
||||
上述兼容只放宽版本元数据,不放宽 HTTP 方法、JSON-RPC 结构、独立 Bearer、`Content-Type`、非空 `Origin`、工具 schema、只读 SQL、服务端数据范围或字段脱敏边界。日志仅记录 `direct_success`(客户端值恰为 `2025-06-18`)或 `compatibility_success`(版本字段缺失或其他值被兼容处理),不记录客户端原始版本值。
|
||||
|
||||
## 首版工具
|
||||
|
||||
| 工具 | 数据表 | 能回答 | 不能回答 |
|
||||
@@ -119,11 +131,27 @@ FIRE_SAFETY_MCP_ENABLED=true
|
||||
curl -sS http://127.0.0.1:8080/mcp \
|
||||
-H "Authorization: Bearer ${FIRE_SAFETY_MCP_AUTH_TOKEN}" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-H 'Accept: application/json' \
|
||||
-H 'Accept: application/json, text/event-stream' \
|
||||
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"manual-probe","version":"1"}}}'
|
||||
```
|
||||
|
||||
随后发送 `notifications/initialized`、`tools/list` 和受控测试地名/坐标的 `tools/call`。联调不得使用真实火情或未授权精确坐标。
|
||||
初始化响应中的 `result.protocolVersion` 应固定为 `2025-06-18`。后续请求不需要携带协议版本 Header;如果客户端自行携带,服务端也不以其值作为版本拒绝条件:
|
||||
|
||||
```bash
|
||||
curl -sS http://127.0.0.1:8080/mcp \
|
||||
-H "Authorization: Bearer ${FIRE_SAFETY_MCP_AUTH_TOKEN}" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-H 'Accept: application/json, text/event-stream' \
|
||||
-d '{"jsonrpc":"2.0","method":"notifications/initialized"}'
|
||||
|
||||
curl -sS http://127.0.0.1:8080/mcp \
|
||||
-H "Authorization: Bearer ${FIRE_SAFETY_MCP_AUTH_TOKEN}" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-H 'Accept: application/json, text/event-stream' \
|
||||
-d '{"jsonrpc":"2.0","id":2,"method":"tools/list"}'
|
||||
```
|
||||
|
||||
再发送受控测试地名/坐标的 `tools/call`,同样无需配置或携带版本 Header。SuperAgent 的真正验收顺序是 `initialize` → `notifications/initialized`(HTTP 202)→ `tools/list`(7 个固定工具)→ 至少一个受控只读 `tools/call`;只看到 initialize 成功不能宣称 MCP 已接通。联调不得使用真实火情或未授权精确坐标。
|
||||
|
||||
SuperAgent 侧配置模板见 [`superagent-mcp-client.example.json`](superagent-mcp-client.example.json)。
|
||||
|
||||
@@ -140,7 +168,8 @@ SuperAgent 侧配置模板见 [`superagent-mcp-client.example.json`](superagent-
|
||||
## 当前联调门禁
|
||||
|
||||
- 样例 SQL 不可执行,也不可提交;其中包含破坏性 DDL 和受限联系人数据。
|
||||
- 2026-09-05 已完成受控 SRID 元数据迁移和严格 audit:8 表共 4,055 条记录,4,048 条非空几何均为 SRID 4326,SRID/类型/范围硬门禁通过。7 条空几何、35 条无效面几何以及 7 张缺 GiST 索引表仍按预期告警;真实 `tools/call` 尚未执行,因此当前仍不能宣称 MCP 的业务结果已经联调验证。
|
||||
- 2026-09-05 已完成受控 SRID 元数据迁移和严格 audit:8 表共 4,055 条记录,4,048 条非空几何均为 SRID 4326,SRID/类型/范围硬门禁通过。7 条空几何、35 条无效面几何以及 7 张缺 GiST 索引表仍按预期告警;本地实库 7 个 `tools/call` 已执行并通过,但公网 SuperAgent `tools/call` 尚未执行,因此当前仍不能宣称公网 MCP 业务联调完成。
|
||||
- 用户提供的 SuperAgent 现场截图证明公网 `/mcp` 请求已经到达 Go 服务,Bearer、`Content-Type` 和 JSON-RPC 前置校验通过;随后旧版本门禁返回错误。该历史截图没有捕获客户端版本字段是否存在、类型和值。同一 SuperAgent 中 `th-hotel-simple-superagent` 已稳定调用是兼容档案的参照,但不是消防 MCP 的成功证据;部署后仍需观察 `direct_success` 或 `compatibility_success`,并完成 initialize → initialized → tools/list → 至少一个 tools/call。
|
||||
- 缺少适用于距离表达式的 GiST 索引时可做小数据开发联调,但生产前必须补齐并验证查询计划。
|
||||
- 地名包含匹配当前没有专用名称索引;真实数据量下先验证查询耗时,后续再决定标准地名表、别名词典或 `pg_trgm` 索引。
|
||||
- 用户身份、动态区域授权和持久审计仍是后续 checkpoint;当前一个 MCP Token 只对应一个静态数据库全范围或镇街白名单。
|
||||
@@ -150,7 +179,7 @@ SuperAgent 侧配置模板见 [`superagent-mcp-client.example.json`](superagent-
|
||||
服务仅监听 `127.0.0.1:18080`,使用运行时只读 PostGIS 账号和显式 `all` 数据范围完成测试;未输出联系人、完整业务记录或测试坐标。
|
||||
|
||||
- `GET /health` 返回 200;无 Token 的 `POST /mcp` 返回 401。
|
||||
- `initialize` 协商 MCP `2025-06-18`;initialized notification 返回 202;`tools/list` 返回全部 7 个工具。
|
||||
- `initialize` 固定返回 MCP `2025-06-18`;版本字段/Header 不作为拒绝门禁,initialized notification 返回 202;`tools/list` 返回全部 7 个工具,并至少完成一个受控 `tools/call`。该记录仍需目标机和真实消防 Profile 提供公网证据。
|
||||
- 使用“观水镇”得到 10 个地点候选,并选取一个精确匹配的 `recorded_point` 蓄水池记录,仅作为获授权测试坐标。
|
||||
- 网格上下文返回 1 条;水源、指挥部候选和通道各返回 10 条;责任中队返回 1 条;风险区域返回 9 条。
|
||||
- 7 个响应的 `structuredContent` 与文本 JSON 投影一致,空间参考均为 EPSG:4326,计数与数据数组一致,不包含已禁止的联系人类字段键。
|
||||
|
||||
Reference in new issue
Block a user