#91 shipped read-only detection ("your real config is at <path>; the args are inert"). The natural next step, requested during the click-through: edit that file from inside BCC instead of dropping to a terminal — and treat any external config a server reads the same way, driven by ServerSpec.
Design (non-reversing)
New sidecar writer that REUSES write_config's atomic-rename + _make_backup. It must not go through apply_servers (cardinal rule: that only writes mcpServers/_disabledMcpServers). Same safety (temp + atomic rename, timestamped backup, rollback) applied to the sidecar file.
After save, re-run detection so the advisory updates live — routes through the hot-reload work (companion issue).
Validate against ServerSpec.schema — the zod enums already seeded in #90 (auth = agent|key|password|keychain, approvalMode, role, port 1–65535). Render pick-lists, not free text, so a layperson can't type auth = "sshkey". (This folds in the epic's #7 "schema pick-lists" item — note it there.)
Preserve unknown keys/comments where feasible (round-trip), like BCC already does for unknown server fields.
Dependency decision to make
Writing TOML on the py3.10 baseline: read is tomllib (3.11+) / tomli (3.10); write needs tomli-w or a hand-rolled serializer for the constrained schema. Pick one, justify, keep deps minimal (the project has kept its runtime deps lean).
Core-first
TOML read/validate/serialize + the atomic+backup sidecar writer are pure-core and fully unit-testable. The editor panel (a form for known schema fields + a raw fallback) is GUI and needs a click-through. Permission pre-flight (#93) should gate/adjust the file's mode on write.
Part of epic #94. Supersedes the standalone #7 by folding schema validation into the editor.
#91 shipped read-only detection ("your real config is at `<path>`; the args are inert"). The natural next step, requested during the click-through: **edit that file from inside BCC** instead of dropping to a terminal — and treat *any* external config a server reads the same way, driven by `ServerSpec`.
## Design (non-reversing)
- **New sidecar writer that REUSES `write_config`'s atomic-rename + `_make_backup`.** It must **not** go through `apply_servers` (cardinal rule: that only writes `mcpServers`/`_disabledMcpServers`). Same safety (temp + atomic rename, timestamped backup, rollback) applied to the sidecar file.
- **After save, re-run detection so the advisory updates live** — routes through the hot-reload work (companion issue).
- **Validate against `ServerSpec.schema`** — the zod enums already seeded in #90 (`auth` = agent|key|password|keychain, `approvalMode`, `role`, `port` 1–65535). Render **pick-lists, not free text**, so a layperson can't type `auth = "sshkey"`. (This folds in the epic's #7 "schema pick-lists" item — note it there.)
- Preserve unknown keys/comments where feasible (round-trip), like BCC already does for unknown server fields.
## Dependency decision to make
Writing TOML on the py3.10 baseline: read is `tomllib` (3.11+) / `tomli` (3.10); **write** needs `tomli-w` or a hand-rolled serializer for the constrained schema. Pick one, justify, keep deps minimal (the project has kept its runtime deps lean).
## Core-first
TOML read/validate/serialize + the atomic+backup sidecar writer are pure-core and fully unit-testable. The editor panel (a form for known schema fields + a raw fallback) is GUI and needs a click-through. Permission pre-flight (#93) should gate/adjust the file's mode on write.
Part of epic #94. Supersedes the standalone #7 by folding schema validation into the editor.
the_og
added the P1 label 2026-08-12 23:54:06 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
#91 shipped read-only detection ("your real config is at
<path>; the args are inert"). The natural next step, requested during the click-through: edit that file from inside BCC instead of dropping to a terminal — and treat any external config a server reads the same way, driven byServerSpec.Design (non-reversing)
write_config's atomic-rename +_make_backup. It must not go throughapply_servers(cardinal rule: that only writesmcpServers/_disabledMcpServers). Same safety (temp + atomic rename, timestamped backup, rollback) applied to the sidecar file.ServerSpec.schema— the zod enums already seeded in #90 (auth= agent|key|password|keychain,approvalMode,role,port1–65535). Render pick-lists, not free text, so a layperson can't typeauth = "sshkey". (This folds in the epic's #7 "schema pick-lists" item — note it there.)Dependency decision to make
Writing TOML on the py3.10 baseline: read is
tomllib(3.11+) /tomli(3.10); write needstomli-wor a hand-rolled serializer for the constrained schema. Pick one, justify, keep deps minimal (the project has kept its runtime deps lean).Core-first
TOML read/validate/serialize + the atomic+backup sidecar writer are pure-core and fully unit-testable. The editor panel (a form for known schema fields + a raw fallback) is GUI and needs a click-through. Permission pre-flight (#93) should gate/adjust the file's mode on write.
Part of epic #94. Supersedes the standalone #7 by folding schema validation into the editor.