MCP: rota writes take no acting_user #120
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#120
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
From the surface parity report (2026-08-18), defect 9.
set_rota_slotandoverride_dayattribute the mutation to the API-key credential itself, unlike the other reward-adjacent MCP writes which acceptacting_user. MEAL_ASSIGNED notifications will name the credential principal instead of the person who asked.Where:
internal/mcp/tools.go.Fix: accept
acting_useron both rota write tools, same ascomplete_itemand friends.Delivered in PR #142 (merged): the MCP rota write tools now take acting_user, and the audit trail records actor=acting user with subject=the API key. Verified over a live /mcp session.