yggdrasil/.scratch/mcp-server/issues/T3-read-tools-resources.md
xfy 9eac025b3e feat(mcp): 完整工具面 + token 管理 + 管理页(T2-T5 并行实现 + 合并)
T2 token 管理(src/api/mcp_tokens.rs):create/list/reveal/revoke + get_mcp_client_configs
服务端函数,均经 get_current_admin_user 鉴权;TokenLifetime 枚举(1/7/30/90天/永不过期)。
src/mcp/config.rs 生成 4 种客户端配置(Claude Code/Cursor/Cline/通用 + CLI)。
src/pages/admin/mcp.rs 令牌管理页:列表 + 新建表单 + 一次性明文展示/重查 + 撤销 +
配置片段卡片。路由 /admin/mcp,导航项加入 admin_layout。

T3 read 工具 + Resources(tools/read.rs, resources.rs):search_posts/get_post/list_tags
(read 作用域,仅已发布);published-post Resources(post://{slug},游标分页)。
search_published 提取为共享函数。

T4 write 工具(tools/{posts,comments,tags,media}.rs):create/update/publish/trash/delete_post、
评论审核、标签 CRUD、媒体 base64 上传(WebP 转码 + 去重)。复用既有 helper 的 SQL 与
缓存失效(moka + ssr_cache)。write 作用域,可读草稿。

T5 admin 工具(tools/{settings,runner}.rs):get/update_settings、run_code(沙箱执行)。
admin 作用域。

合并(server.rs):用 rmcp tool_router 的「命名路由 + 组合」模式,7 个工具组在
YggMcpServer 上 impl,combined_router 用 + 合并成单一 ServerHandler。各工具组鉴权
独立,经 Extension<Parts> 读 McpPrincipal + scope.grants 校验。

新增依赖 base64 0.22(媒体上传解码)。验证:server/web 双目标编译通过、clippy
--all-features -D warnings 干净、659 单测 + 1 集成全绿(+20 新测试)。
2026-07-28 11:53:32 +08:00

1.5 KiB

T3 — read-scope tools + Resources (full knowledge base)

Blocking edges

  • Blocks: T6 (hardening sanitizes these outputs).
  • Blocked by: T1 (mount + auth + dispatch exist).

Target files

  • src/mcp/resources.rs — Resources + templates.
  • src/mcp/tools/read.rs — full read tool set.
  • src/mcp/server.rs — register resources/templates + read tools in the handler.

Change

  1. resources/list(cursor?, limit?) — paginated PUBLISHED posts (opaque cursor; page size server-set, e.g. 50). Returns {resources: [{uri, name, mimeType: text/markdown}], nextCursor}. Invalid cursor → MCP error -32602.
  2. resources/templates/listpost://{slug} template.
  3. resources/read(uri) — resolve post://{slug} (or canonical HTTPS URL) → rendered Markdown of one published post.
  4. search_posts(query, limit?, cursor?) — full FTS via existing search helper; return ranked summaries + resource_links (content type added 2025-06-18) to matching posts.
  5. get_post(slug|id) — published only (read scope).
  6. list_tags().

Acceptance

  • resources/list paginates; nextCursor round-trips; invalid cursor errors -32602.
  • resources/read returns one post's Markdown; unknown slug → error.
  • search_posts returns ranked results with valid resource_link URIs.
  • All read tools succeed with a read-scope token; drafts are NOT visible.
  • Pure unit tests: cursor encode/decode, resource URI parsing (DB-free).
  • Both targets compile; clippy clean; existing tests pass.