Skip to content

fix(GEN-4808): satisfy the Rails destructive-delete gate from MCP - #28

Merged
mavxdegods merged 1 commit into
mainfrom
fix/gen-4808-mcp-confirm-token
Aug 3, 2026
Merged

mavxdegods merged 1 commit into
mainfrom
fix/gen-4808-mcp-confirm-token

Conversation

@mavxdegods

Copy link
Copy Markdown
Member

Problem

Rails (GEN-4797) gates PAT-authenticated destructive Vidsheet deletes behind a two-phase confirm: the first DELETE returns 428 with an authoritative would_destroy preview and a single-use, target-bound confirm_token.

mcp.gen.pro sends the caller's PAT (client.py → X-API-Key), so it is in the gated class by design. But no delete tool accepted a token, and client._call collapsed the 428 into an opaque GenApiError.

Every MCP column/layer/variable delete against a populated target has been failing in production. Fail-closed — nothing was destroyed — but the caller got an unactionable error with no path forward.

Fix

  • GenConfirmationRequired carries would_destroy + confirm_token; _call raises it on 428 instead of the generic error. A 428 with no usable token still fails closed.
  • gated_delete() returns the preview so the model can show the user exactly what would be deleted, then re-call with the token.
  • gen_delete_column / gen_delete_layer / gen_delete_variable take an optional confirm_token.

Deliberately does NOT auto-confirm. Rails stays the authority for target drift, expiry and one-shot consumption; an MCP tool must never manufacture a user's approval. Mirrors the proven handler in gen-agentic rails_client._delete_with_destructive_confirmation.

Verification

  • 149 tools load (mcp.list_tools()), all three expose confirm_token
  • 4/4 new tests pass
  • Red-then-green proven: removing the confirm_token parameter makes test_delete_tools_accept_confirm_token fail

Follow-up

GEN-4808 also flags the TypeScript SDK's deleteColumn/deleteLayer/deleteVariable — not in this repo, tracked separately.

🤖 Generated with Claude Code

Rails (GEN-4797) gates PAT-authenticated destructive Vidsheet deletes behind a
two-phase confirm: the first DELETE returns 428 with an authoritative
would_destroy preview and a single-use, target-bound confirm_token.

mcp.gen.pro sends the caller's PAT, so it is in the gated class by design — but
no delete tool accepted a token, and client._call collapsed the 428 into an
opaque GenApiError. Every MCP column/layer/variable delete against a populated
target has therefore been failing in production. Fail-closed (nothing was
destroyed), but the caller got an unactionable error.

- client: GenConfirmationRequired carries would_destroy + confirm_token; _call
  raises it on 428 instead of the generic error. A 428 with no usable token
  still fails closed.
- client: gated_delete() returns the preview so the model can show the user what
  would be deleted, then re-call with the token. It deliberately does NOT
  auto-confirm — Rails stays the authority for target drift, expiry and one-shot
  consumption, and a tool must never manufacture a user's approval.
- server: gen_delete_column / gen_delete_layer / gen_delete_variable take an
  optional confirm_token and route through gated_delete.

Mirrors the proven handler in gen-agentic rails_client._delete_with_destructive_confirmation.

Verified: 149 tools load; 4/4 new tests pass; removing the confirm_token
parameter makes test_delete_tools_accept_confirm_token fail (red-then-green).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@mavxdegods
mavxdegods merged commit 3398de4 into main Aug 3, 2026
2 checks passed
@mavxdegods
mavxdegods deleted the fix/gen-4808-mcp-confirm-token branch August 3, 2026 16:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants