Files
PaperClipAI/server
nguyenm7andPaperclip 1aeba0e6c2 test(connections): mirror a real MCP-direct vendor's advertised shape
PAP-18519, an acceptance test for the connector skills shipped on
PAP-18464. Michael asked for an Enterpret connector as the test case.
There is no authorized Enterpret credential and Paperclip's connect flow
performs RFC 7591 dynamic client registration automatically, so pointing
a connect flow at the live endpoint would create a client record at a
vendor we have no relationship with. Instead this mirrors the vendor's
public, unauthenticated metadata into the existing in-process fixture
and exercises the real broker against it.

The documents are literal copies of what
https://wisdom-api.enterpret.com/server/mcp and
https://oauth.enterpret.com published on 23 September 2026, re-hosted on
the DNS-pinned IP literals this file already uses. Nothing here reaches
the vendor: no registration, no consent, no tool call.

Four things the existing fixture does not cover, each on a different
rung of the client-resolution ladder:

- The 401 challenge carries realm and scope around resource_metadata,
  not that parameter alone.
- The authorization server is on a different origin from the MCP server
  and its issuer has no path, so RFC 8414 insertion never applies.
- The authorization server advertises no Client ID Metadata Document, so
  DCR is the only rung whatever the callback origin looks like -- the
  playbook frames CIMD as gated on a public HTTPS origin, and for this
  shape that framing is not the binding constraint.
- It advertises no revocation_endpoint, and Paperclip never looks for
  one: revoke is enforced entirely locally.

Recorded adverse finding, asserted rather than described: with no
annotations to go on, name inference files all ten documented tools as
read-only, including run_graph_query and execute_cypher_query, which
execute operator-supplied queries against the vendor's customer-feedback
graph. The wizard shows ten reads and no changes.

server 70/70 in this file, server typecheck clean.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-09-23 23:39:39 +00:00
..