Files
DottaandPaperclip 7b35de65aa feat(mcp) [split 1/8]: add fixture demo servers (#9556)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Governed MCP access spans contracts, runtime enforcement, adapters,
UI surfaces, and operator verification
> - The parity reference PR #9534 is too large for effective automated
or human review
> - The feature therefore needs a linear stack whose individual diffs
stay below the 100-file review limit
> - This pull request is split 1/8 and focuses on fixture and demo MCP
servers
> - The benefit is a standalone, testable review boundary while
preserving byte-for-byte parity at the top of the stack

## Linked Issues or Issue Description

- Related parity reference: #9534
- Problem: Developers need deterministic local MCP fixtures and visible
demo servers without pulling in the governed production runtime.
- Proposed solution: Adds the Google Sheets and KV demo MCP packages,
fixture catalog/servers, smoke harness, guide, and the root
smoke/typecheck registration hunks.
- Alternatives considered: keeping #9534 as one 403-file review, or
rewriting the feature to manufacture seams; both were rejected in favor
of path extraction plus compile-driven boundary moves.
- Roadmap alignment: this advances the existing governed MCP/tool-access
work already represented by #9534; it does not introduce a separate
roadmap initiative.
- Stack position: base branch is `master`.
- Merge policy: merge bottom-up, in order, only after the complete
eight-PR stack has been reviewed and the top-of-stack parity gate
remains empty.
- Requested review: QA for fixture and smoke coverage; Greptile on every
PR.

## What Changed

- Adds the Google Sheets and KV demo MCP packages, fixture
catalog/servers, smoke harness, guide, and the root smoke/typecheck
registration hunks.
- Keeps this PR below 100 changed files and independently typecheckable.
- Preserves the final tree from #9534 when combined with the other seven
stack levels.

## Verification

- `pnpm typecheck`
- `pnpm --filter @paperclipai/google-sheets-mcp-server test` — 27 tests
passed
- `pnpm --filter @paperclipai/kv-demo-mcp-server test` — 12 tests passed

## Risks

- The new packages add dependencies that are intentionally not committed
to `pnpm-lock.yaml`, per repository policy.
- Stack risk: merging out of order can expose incomplete layers;
mitigate by following the documented bottom-up merge policy.
- Parity risk: later edits to an intermediate branch can drift from
#9534; mitigate by re-running the empty top-of-stack diff before merge.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, exact model ID `gpt-5.4`; runtime-managed context
window; medium reasoning with repository, shell, Git, GitHub CLI, and
code-execution tools enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] Internal references are omitted except the execution-plan link
explicitly required for this coordinated split stack
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge


## Stack Coordination

- Internal execution plan:
[PAP-13874](/PAP/issues/PAP-13874#document-plan)
- Parity reference: #9534
- Stack: #9556 → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563
- Merge bottom-up only after full-stack review and an empty parity diff
at #9563.

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-14 12:56:21 -05:00

97 lines
3.3 KiB
JavaScript

#!/usr/bin/env node
import http from "node:http";
import {
MCP_FIXTURE_PROTOCOL_VERSION,
createFixtureState,
executeFixtureTool,
listTools,
} from "../catalog.mjs";
const state = createFixtureState();
const port = Number(process.env.PORT ?? 0);
const host = process.env.HOST ?? "127.0.0.1";
function sendJson(res, statusCode, body) {
res.writeHead(statusCode, { "Content-Type": "application/json" });
res.end(JSON.stringify(body));
}
async function readJson(req) {
const chunks = [];
for await (const chunk of req) chunks.push(chunk);
const body = Buffer.concat(chunks).toString("utf8");
return body ? JSON.parse(body) : {};
}
function mcpToolResult(result) {
return {
content: [{ type: "text", text: JSON.stringify(result) }],
structuredContent: result,
};
}
function sendMcpError(res, id, code, message, data = undefined) {
sendJson(res, 200, {
jsonrpc: "2.0",
id: id ?? null,
error: { code, message, ...(data === undefined ? {} : { data }) },
});
}
const server = http.createServer(async (req, res) => {
try {
const url = new URL(req.url ?? "/", `http://${host}`);
if (req.method === "GET" && url.pathname === "/health") {
sendJson(res, 200, { ok: true, protocol: MCP_FIXTURE_PROTOCOL_VERSION, transport: "http" });
return;
}
if (req.method === "GET" && url.pathname === "/catalog") {
sendJson(res, 200, { ok: true, tools: listTools({ schemaVariant: state.schemaVariant }).filter((tool) => tool.transport === "http") });
return;
}
if (req.method === "POST" && url.pathname === "/mcp") {
const body = await readJson(req);
const params = body.params && typeof body.params === "object" ? body.params : {};
if (body.method === "tools/list") {
sendJson(res, 200, {
jsonrpc: "2.0",
id: body.id ?? null,
result: {
tools: listTools({ schemaVariant: state.schemaVariant }).filter((tool) => tool.transport === "http"),
},
});
return;
}
if (body.method !== "tools/call" || typeof params.name !== "string") {
sendMcpError(res, body.id, -32601, "Method not found");
return;
}
const response = await executeFixtureTool(params.name, params.arguments ?? {}, state, {
secrets: process.env,
});
if (!response.ok) {
sendMcpError(res, body.id, -32000, response.error?.message ?? "Fixture tool failed", response.error);
return;
}
sendJson(res, 200, { jsonrpc: "2.0", id: body.id ?? null, result: mcpToolResult(response.result) });
return;
}
if (req.method === "POST" && url.pathname === "/tools/call") {
const body = await readJson(req);
const response = await executeFixtureTool(body.name, body.input ?? {}, state, {
secrets: process.env,
});
sendJson(res, response.ok ? 200 : 422, response);
return;
}
sendJson(res, 404, { ok: false, error: { code: "not_found", message: `${req.method} ${url.pathname}` } });
} catch (error) {
sendJson(res, 500, { ok: false, error: { code: "fixture_error", message: String(error?.message ?? error) } });
}
});
server.listen(port, host, () => {
const address = server.address();
process.stdout.write(`${JSON.stringify({ event: "ready", host, port: address.port })}\n`);
});