MCP: rota writes take no acting_user #120

Closed
opened 2026-08-18 10:45:23 +00:00 by nalum · 1 comment
Owner

From the surface parity report (2026-08-18), defect 9.

set_rota_slot and override_day attribute the mutation to the API-key credential itself, unlike the other reward-adjacent MCP writes which accept acting_user. MEAL_ASSIGNED notifications will name the credential principal instead of the person who asked.

Where: internal/mcp/tools.go.

Fix: accept acting_user on both rota write tools, same as complete_item and friends.

From the surface parity report (2026-08-18), defect 9. `set_rota_slot` and `override_day` attribute the mutation to the API-key credential itself, unlike the other reward-adjacent MCP writes which accept `acting_user`. MEAL_ASSIGNED notifications will name the credential principal instead of the person who asked. Where: `internal/mcp/tools.go`. Fix: accept `acting_user` on both rota write tools, same as `complete_item` and friends.
Author
Owner

Delivered in PR #142 (merged): the MCP rota write tools now take acting_user, and the audit trail records actor=acting user with subject=the API key. Verified over a live /mcp session.

Delivered in PR #142 (merged): the MCP rota write tools now take acting_user, and the audit trail records actor=acting user with subject=the API key. Verified over a live /mcp session.
nalum closed this issue 2026-08-18 16:46:46 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#120
No description provided.