feat(server): MCP tools for settings, providers, git, pull requests, terminals, projects, pin order, and opening threads - #15445
Closed
maria-rcks wants to merge 20 commits into
Conversation
…re thread actions
…list keeps requestIds
…terminals, projects, pin order, and opening threads
Contributor
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR adds a large cross-cutting MCP capability spanning host access, terminals, Git, pull requests, providers, settings, approvals, and client navigation, including externally visible and destructive operations. It also changes authorization plumbing, so the scope and security-sensitive runtime impact require human review. You can add or adjust custom eligibility rules. Learn more. |
…movals, resolve team reviewers, target by focus recency
…nd Bitbucket; rank clients by real focus
…tened when chains
…dered when conditions
Collaborator
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #15428, which is stacked on #15219. GitHub can't target #15428's fork branch, so this PR is based on
t3code/mcp-oauth/thread-targetsand also shows #15428's commits. The new work is everything after #15428's commits.Problem
After #15428, an MCP client still couldn't do much of what the app does. It couldn't change settings or keybindings, check providers and quota, run git or PR actions, use terminals, browse host folders to add a project, reorder pins, or open a thread in the user's window.
Change
Each tool is a thin wrapper over the service its WS method already uses. Anything that changes the environment, runs commands, pushes code, or reveals host paths needs a full-access caller.
t3_environment_readcan include the full server settings (credentials redacted) and keybindings.t3_environment_preferences_updateaccepts any non-credential settings patch, a provider instance toggle or custom models, and keybinding upsert/remove. Credential fields,providerInstancesanddeviceHostsare rejected and stay in the Settings UI. Reads only return each provider instance'scustomModelsfrom its opaque driver config, and strip credentials from settings URLs. Keybinding rule matching in the keybindings service now compareswhenexpressions and shortcut spellings by meaning, so a listed rule always removes the stored one. The Settings UI gets the same fix.t3_provider_status(full access, since messages can carry configured URLs) returns install, auth and version per instance, plus rate-limit windows and optional token/cost usage.t3_provider_refreshre-runs the provider checks. There's no login or logout over MCP, since an agent can't complete a sign-in.t3_git_status(read-only, full access because a cold status cache fetches) andt3_git(create/switch branch, pull, and the app's commit/push/open-PR flow). There's no merge or force-push.t3_pull_request_readreturns the overview, checks, conversation or a review thread, within a character budget.t3_pull_request_updatecan comment, reply, resolve or unresolve, request reviewers, and set labels. Reviewer names are matched against the host's candidates. GitHub and Forgejo take logins as given, and on GitLab and Bitbucket an unmatched name must be the host's own id. Merge, close, review approval and title/body edits are left out.t3_terminal_list,t3_terminal_read(scrollback with escape codes stripped, full access because output can hold secrets) andt3_terminal_control(open/write/close the same terminals the panel shows). Open attaches to a running shell instead of restarting it.t3_folder_browse,t3_agent_session_scanandt3_agent_session_import. Creating a new or scratch project already works throught3_project_createandt3_thread_launch.t3_thread_organizegetsmove_pinnedandmove_activewithbeforeThreadId. The order-key helpers moved from client-runtime to@t3tools/shared/threadOrderKeys, and client-runtime re-exports them, so web and mobile are unchanged.t3_client_open_thread {threadId, panel?}goes through a newsubscribeClientIntentsstream. The window that acts is the desktop window that most recently reported focus to the preview broker (that history survives reconnects), or failing that a visible, focused window. So an outside agent in a terminal can still bring up a thread. Mobile doesn't act on it yet.t3_environment_preferences_updatecrash (Service not found: ThreadCommandExecutor), the same one-line wiring as fix(mcp): allow environment preference updates #15337.Verification
core.test.tschecks that settings reads never contain credentials.echo mcp-terminal-okwas written and read back, and the terminal was closed.move_pinnedreordered the sidebar.Not verified:
t3_gitwrites (the test checkout was dirty) andt3_pull_request_update, to avoid writing to a real PR.t3_agent_session_import.t3_client_open_threadactually navigating a focused window. It returneddelivered: true, but the test browser tab had no focus.Written by
claude-opus-5-5in Claude Code, running in T3 Code.