Files
PaperClipAI/packages/google-sheets-mcp-server/src/http.ts
T
DottaandPaperclip 7b35de65aa feat(mcp) [split 1/8]: add fixture demo servers (#9556)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Governed MCP access spans contracts, runtime enforcement, adapters,
UI surfaces, and operator verification
> - The parity reference PR #9534 is too large for effective automated
or human review
> - The feature therefore needs a linear stack whose individual diffs
stay below the 100-file review limit
> - This pull request is split 1/8 and focuses on fixture and demo MCP
servers
> - The benefit is a standalone, testable review boundary while
preserving byte-for-byte parity at the top of the stack

## Linked Issues or Issue Description

- Related parity reference: #9534
- Problem: Developers need deterministic local MCP fixtures and visible
demo servers without pulling in the governed production runtime.
- Proposed solution: Adds the Google Sheets and KV demo MCP packages,
fixture catalog/servers, smoke harness, guide, and the root
smoke/typecheck registration hunks.
- Alternatives considered: keeping #9534 as one 403-file review, or
rewriting the feature to manufacture seams; both were rejected in favor
of path extraction plus compile-driven boundary moves.
- Roadmap alignment: this advances the existing governed MCP/tool-access
work already represented by #9534; it does not introduce a separate
roadmap initiative.
- Stack position: base branch is `master`.
- Merge policy: merge bottom-up, in order, only after the complete
eight-PR stack has been reviewed and the top-of-stack parity gate
remains empty.
- Requested review: QA for fixture and smoke coverage; Greptile on every
PR.

## What Changed

- Adds the Google Sheets and KV demo MCP packages, fixture
catalog/servers, smoke harness, guide, and the root smoke/typecheck
registration hunks.
- Keeps this PR below 100 changed files and independently typecheckable.
- Preserves the final tree from #9534 when combined with the other seven
stack levels.

## Verification

- `pnpm typecheck`
- `pnpm --filter @paperclipai/google-sheets-mcp-server test` — 27 tests
passed
- `pnpm --filter @paperclipai/kv-demo-mcp-server test` — 12 tests passed

## Risks

- The new packages add dependencies that are intentionally not committed
to `pnpm-lock.yaml`, per repository policy.
- Stack risk: merging out of order can expose incomplete layers;
mitigate by following the documented bottom-up merge policy.
- Parity risk: later edits to an intermediate branch can drift from
#9534; mitigate by re-running the empty top-of-stack diff before merge.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, exact model ID `gpt-5.4`; runtime-managed context
window; medium reasoning with repository, shell, Git, GitHub CLI, and
code-execution tools enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] Internal references are omitted except the execution-plan link
explicitly required for this coordinated split stack
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge


## Stack Coordination

- Internal execution plan:
[PAP-13874](/PAP/issues/PAP-13874#document-plan)
- Parity reference: #9534
- Stack: #9556 → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563
- Merge bottom-up only after full-stack review and an empty parity diff
at #9563.

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-14 12:56:21 -05:00

130 lines
4.1 KiB
TypeScript

import { createServer, type IncomingMessage, type Server, type ServerResponse } from "node:http";
import { StreamableHTTPServerTransport } from "@modelcontextprotocol/sdk/server/streamableHttp.js";
import { createGoogleSheetsMcpServer } from "./index.js";
import type { GoogleSheetsMcpConfig } from "./config.js";
import { createGoogleSheetsClient, type GoogleSheetsClient } from "./google-client.js";
export interface GoogleSheetsMcpHttpOptions {
config: GoogleSheetsMcpConfig;
client?: GoogleSheetsClient;
/** Optional shared secret required on the MCP route when provided. */
token?: string | null;
}
export interface GoogleSheetsMcpHttpServer {
server: Server;
/** Resolves to the bound port once listening. */
listen: (port: number, host?: string) => Promise<number>;
close: () => Promise<void>;
}
const MCP_PATH = "/mcp";
function sendJson(res: ServerResponse, status: number, body: unknown): void {
const payload = JSON.stringify(body);
res.writeHead(status, {
"content-type": "application/json",
"content-length": Buffer.byteLength(payload),
});
res.end(payload);
}
function presentedToken(req: IncomingMessage): string | null {
const header = req.headers.authorization;
if (header?.startsWith("Bearer ")) return header.slice("Bearer ".length).trim();
return null;
}
async function readJsonBody(req: IncomingMessage): Promise<unknown> {
const chunks: Buffer[] = [];
let size = 0;
for await (const chunk of req) {
const buffer = chunk as Buffer;
size += buffer.length;
if (size > 1_000_000) throw new Error("Request body too large.");
chunks.push(buffer);
}
if (chunks.length === 0) return undefined;
const raw = Buffer.concat(chunks).toString("utf8").trim();
if (!raw) return undefined;
return JSON.parse(raw);
}
async function handleMcp(
req: IncomingMessage,
res: ServerResponse,
config: GoogleSheetsMcpConfig,
client: GoogleSheetsClient,
): Promise<void> {
let parsedBody: unknown;
try {
parsedBody = req.method === "POST" ? await readJsonBody(req) : undefined;
} catch (error) {
sendJson(res, 400, {
jsonrpc: "2.0",
error: { code: -32700, message: error instanceof Error ? error.message : "Parse error" },
id: null,
});
return;
}
const { server } = createGoogleSheetsMcpServer(config, { client });
const transport = new StreamableHTTPServerTransport({ sessionIdGenerator: undefined });
res.on("close", () => {
void transport.close();
void server.close();
});
await server.connect(transport);
await transport.handleRequest(req, res, parsedBody);
}
export function createGoogleSheetsMcpHttpServer(
options: GoogleSheetsMcpHttpOptions,
): GoogleSheetsMcpHttpServer {
const requiredToken = options.token?.trim() || null;
const client = options.client ?? createGoogleSheetsClient(options.config.serviceAccount);
const server = createServer((req, res) => {
void (async () => {
try {
const url = new URL(req.url ?? "/", "http://localhost");
if (url.pathname !== MCP_PATH) {
sendJson(res, 404, { error: "Not found." });
return;
}
if (requiredToken && presentedToken(req) !== requiredToken) {
sendJson(res, 401, { error: "Unauthorized. Provide GOOGLE_SHEETS_MCP_TOKEN." });
return;
}
await handleMcp(req, res, options.config, client);
} catch (error) {
if (!res.headersSent) {
sendJson(res, 500, { error: error instanceof Error ? error.message : "Internal error." });
} else {
res.end();
}
}
})();
});
return {
server,
listen: (port, host = "127.0.0.1") =>
new Promise<number>((resolve, reject) => {
server.once("error", reject);
server.listen(port, host, () => {
server.off("error", reject);
const address = server.address();
resolve(typeof address === "object" && address ? address.port : port);
});
}),
close: () =>
new Promise<void>((resolve, reject) => {
server.close((error) => (error ? reject(error) : resolve()));
}),
};
}