Skip to content

feat(mcp): bearer-tokened MCP server exposing search to agents#296

Draft
salmonumbrella wants to merge 3 commits into
maathimself:mainfrom
salmonumbrella:search/split-3-mcp-rebased
Draft

feat(mcp): bearer-tokened MCP server exposing search to agents#296
salmonumbrella wants to merge 3 commits into
maathimself:mainfrom
salmonumbrella:search/split-3-mcp-rebased

Conversation

@salmonumbrella

Copy link
Copy Markdown
Contributor

Split 3/3 of #283, stacked on #294#295 — the diff shows their commits until they merge; review the last commit only (feat(mcp): bearer-tokened MCP server exposing search to agents). I'll rebase as the stack lands. One new backend dependency: @modelcontextprotocol/sdk.

Summary

  • Streamable-HTTP /mcp endpoint: SHA-256-hashed bearer tokens minted in Profile, Origin-validated, rate-limited. 12 tools including semantic_search_messages and search_in_message; every call is scoped to the token owner's accounts; deletion is staged-only (migrations 0040–0041).
  • Adds the MCP-only search seams kept out of the earlier PRs: trusted caller-supplied account scoping, the body-scope FTS leg, strictVector, loadVector, and the chunk-excerpt read path (chunkmatch/textExcerpt).
  • nginx /mcp proxy blocks (SSE-friendly, no buffering); token minting UI in Profile, in all 7 locales.

With this PR merged, the combined tree is byte-identical to the reviewed #283 head (3773150) modulo the rebase onto current main — the three-way split re-partitions that exact tree, it does not rewrite it.

Testing


Contributor License Agreement

By submitting this pull request I confirm that:

  • I have read and agree to the Contributor License Agreement.
  • My contribution is my own original work (or I have identified any third-party material and confirmed it is compatible with the CLA).
  • I have the right to submit this contribution under the terms of the CLA.

🤖 Generated with Claude Code

salmonumbrella and others added 3 commits July 18, 2026 21:42
Results ranked by relevance instead of date-only: subject > sender > body
(setweight A-D + ts_rank_cd), prefix matching as you type, quoted phrases,
served by a GIN index over a trigger-maintained search_fts column. Backfill
runs as a resumable background drainer (fast-DDL migrations 0035-0037, no
boot-blocking rewrite); not-yet-backfilled rows fall back to the previous
query path. Body text is materialized by a provider-gated background IMAP
drainer with circuit breakers, poison-message forward progress, and
progress reporting. Filter-only queries stay date-ordered.

No infrastructure changes - runs on stock postgres:16-alpine.

Split 1/3 of maathimself#283.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tor)

Explicit opt-in embeddings pipeline against any OpenAI-compatible
/v1/embeddings endpoint (key encrypted at rest, host-validated, masked on
read). Fingerprinted generations (config change => clean rebuild), a
crash-safe fill worker, per-dimension HNSW partial indexes, re-embedding of
late-arriving bodies. Query side adds hybrid BM25+ANN reciprocal-rank
fusion behind an in-input Semantic toggle; lexical stays the default, with
silent fallback while the index builds. Settings UI with explicit privacy
copy and live Test/Build progress, in all 7 locales. Migrations 0038-0039.
Includes the search-eval harness that produced the published quality
numbers, and its explain/total diagnostics seams.

Infra: compose moves postgres:16-alpine -> pgvector/pgvector:pg16 (same
PG16 major). Run REINDEX DATABASE once after the first boot: the
musl -> glibc collation change can misorder existing text btree indexes;
the app logs a loud warning when it detects this.

Split 2/3 of maathimself#283, stacked on the weighted-FTS PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Streamable-HTTP /mcp endpoint (SHA-256-hashed tokens minted in Profile,
Origin-validated, rate-limited) exposing 12 tools including
semantic_search_messages and search_in_message. Every call is scoped to
the token owner's accounts; deletion is staged-only. Adds the MCP-only
search seams (trusted account scoping, body-scope FTS leg, strictVector,
loadVector), the chunk-excerpt read path, migrations 0040-0041, and one
new backend dependency: @modelcontextprotocol/sdk.

Split 3/3 of maathimself#283, stacked on the semantic-embeddings PR. The stacked
tree is byte-identical to the reviewed maathimself#283 head (3773150).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant