GitNexus/gitnexus/src/server
svjack ccf6b4743d
Some checks are pending
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Publish / Publish to npm (push) Blocked by required conditions
Publish / Build & Push RC Docker images (push) Blocked by required conditions
Publish / Classify release event (push) Waiting to run
Publish / RC guard (marker + release-PR skip) (push) Blocked by required conditions
Publish / ci (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
feat(mcp): add read_file + grep tools (REST parity for /api/file slice + /api/grep) (#3377)
* feat(mcp): add read_file + grep tools (REST parity for /api/file slice + /api/grep)

* chore(autofix): apply prettier + eslint fixes via /autofix command

* Address PR review feedback (#3377)

- Fail read_file and grep when full source is unavailable, matching the HTTP 410 contract instead of an empty grep or a not-found on a missing checkout.
- Reject branch on those tools so a pinned index is not labeled onto checkout bytes, and stop advertising branch in their schemas.
- Point the grep hint at a 0-based read_file window, pass caseSensitive and literal through, and test the handlers.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3377)

- Keep read_file and grep in the multi-repo schema requirement without advertising branch.
- Reject negative maxLines and return integer slice bounds for fractional line positions.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3377)

- Reject a negative read_file endLine before slicing so JavaScript does not treat it as an offset from the end of the file.
- Drop the fractional startLine/endLine claim so the integer schema is the advertised contract.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3377)

- Skip indexed grep paths whose realpath leaves the checkout so a symlink cannot return lines from outside the repo.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(bench): record the 19-tool MCP roster

read_file and grep are real tools, so tools/list and GITNEXUS_TOOLS both
moved from 17 to 19. The timing ratios were already inside budget.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(mcp): share read_file and grep contracts with existing helpers

Boolean grep flags go through isFlagTrue, the whole-file cap is one constant, and checkout tools stay on the per-repo schema without advertising branch.

---------

Co-authored-by: svjack <svjack@example.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 13:16:11 +00:00
..
analyze-job.ts fix: web citation/code panel bugs and serve analyze/route hardening (#3348) 2026-09-23 13:27:22 +01:00
analyze-launch.ts feat(storage): share one index store across linked worktrees and sibling clones (#3374) 2026-09-25 11:20:12 +01:00
analyze-upload.ts feat(storage): add configurable index storage and content retention tiers (#3060) 2026-09-12 20:31:55 +00:00
analyze-worker-core.ts feat(storage): add configurable index storage and content retention tiers (#3060) 2026-09-12 20:31:55 +00:00
analyze-worker-ipc.ts feat(storage): share one index store across linked worktrees and sibling clones (#3374) 2026-09-25 11:20:12 +01:00
analyze-worker-protocol.ts fix(storage): guard stale file-lock reclamation (#3234) 2026-09-12 11:47:12 +01:00
analyze-worker.ts fix(embeddings): keep ONNX off the install and analyze critical path (#3287) 2026-09-15 12:11:47 +01:00
api.ts feat(storage): share one index store across linked worktrees and sibling clones (#3374) 2026-09-25 11:20:12 +01:00
embed-run-outcome.ts fix(embeddings): retry unparseable 200 responses and survive partial embedding failures (#2790) (#2795) 2026-08-02 20:43:59 +00:00
git-clone.ts fix(auto-sync): allow self-hosted remotes via allowed_hosts (#3391) 2026-09-27 10:18:57 +01:00
grep-params.ts feat(mcp): add read_file + grep tools (REST parity for /api/file slice + /api/grep) (#3377) 2026-09-27 13:16:11 +00:00
grep-scan.ts fix(server,web): honor the grep tool contract — real regex, fileFilter, caseSensitive (#3109) 2026-08-31 20:43:28 +01:00
grep-worker.ts fix(server,web): honor the grep tool contract — real regex, fileFilter, caseSensitive (#3109) 2026-08-31 20:43:28 +01:00
mcp-http.ts fix(serve): protect MCP route with optional bearer auth (#3100) 2026-08-30 17:12:46 +01:00
middleware.ts feat(serve): validate and port-scope the origin/proxy configuration surface (#2820) 2026-08-05 06:52:39 +01:00
ops-snapshot.ts fix: web citation/code panel bugs and serve analyze/route hardening (#3348) 2026-09-23 13:27:22 +01:00
private-ip.ts fix(ip): Scope write-route origin guard to server's own bound host (#2172) 2026-06-13 09:24:03 +01:00
public-repo-id.ts fix: web citation/code panel bugs and serve analyze/route hardening (#3348) 2026-09-23 13:27:22 +01:00
repo-projection.ts fix: web citation/code panel bugs and serve analyze/route hardening (#3348) 2026-09-23 13:27:22 +01:00
sse-progress.ts fix: web citation/code panel bugs and serve analyze/route hardening (#3348) 2026-09-23 13:27:22 +01:00
update-controller.ts chore: release v1.6.11 (#3177) 2026-09-04 20:02:37 +01:00
upload-ingest.ts fix(core): ensure path prefix and traversal guards support root directories (#2559) 2026-07-20 08:12:15 +01:00
upload-paths.ts fix(server): resolve clone/upload/mapping roots from GITNEXUS_HOME (#2229) 2026-06-18 17:39:44 +01:00
upload-sweep.ts feat(storage): add configurable index storage and content retention tiers (#3060) 2026-09-12 20:31:55 +00:00
validation.ts fix(core): ensure path prefix and traversal guards support root directories (#2559) 2026-07-20 08:12:15 +01:00