mirror of
https://github.com/qelectrotech/qelectrotech-source-mirror.git
synced 2026-10-05 18:54:14 +02:00
mcp_server, ai_assistants: drop the --http sections (#1132 closed)
-37
@@ -219,43 +219,6 @@ The server speaks MCP over standard input and output.
|
||||
|
||||
---
|
||||
|
||||
## By web address
|
||||
|
||||
> **Status: pending.** This section describes
|
||||
> [PR #1132](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1132),
|
||||
> not yet merged. Nothing here works until that lands — check the PR
|
||||
> before trying any of this against your own build. This section will drop
|
||||
> this notice once it does.
|
||||
|
||||
Some assistants connect to a server by address instead of starting it. Start
|
||||
it yourself, on this computer only:
|
||||
|
||||
```bash
|
||||
QET_MCP_WORKSPACE=/path/to/drawings python3 qet_mcp.py --http
|
||||
python3 qet_mcp.py --show-token
|
||||
```
|
||||
|
||||
and give the assistant `http://127.0.0.1:8731/mcp` with the header
|
||||
`Authorization: Bearer <token>`. For example in VS Code:
|
||||
|
||||
```json
|
||||
{
|
||||
"servers": {
|
||||
"qet": {
|
||||
"type": "http",
|
||||
"url": "http://127.0.0.1:8731/mcp",
|
||||
"headers": { "Authorization": "Bearer ${input:qet-token}" }
|
||||
}
|
||||
},
|
||||
"inputs": [
|
||||
{ "id": "qet-token", "type": "promptString", "description": "qet-mcp token", "password": true }
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
It offers only the reading tools unless started with `--allow-edit`. Every
|
||||
option and what it refuses is on the [MCP server](mcp_server#over-http) page.
|
||||
|
||||
## ChatGPT, and Claude or Copilot in a web browser
|
||||
|
||||
These reach a server only through the internet, from their own computers.
|
||||
|
||||
-50
@@ -72,56 +72,6 @@ above are the only setup that matters, and both are covered below.
|
||||
|
||||
---
|
||||
|
||||
## Over HTTP
|
||||
|
||||
> **Status: pending.** This section describes
|
||||
> [PR #1132](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1132),
|
||||
> not yet merged. Nothing here works until that lands — check the PR
|
||||
> before trying any of this against your own build. This section will drop
|
||||
> this notice once it does.
|
||||
|
||||
Some assistants connect to a server by web address rather than starting it
|
||||
themselves. `--http` serves the same tools on this computer only:
|
||||
|
||||
```bash
|
||||
export QET_MCP_WORKSPACE=/home/you/drawings
|
||||
python3 misc/qet-mcp/qet_mcp.py --http # http://127.0.0.1:8731/mcp
|
||||
python3 misc/qet-mcp/qet_mcp.py --show-token # the token a client must send
|
||||
```
|
||||
|
||||
The client sends `Authorization: Bearer <token>` with every request; its
|
||||
setup usually has a "headers" field for it (examples on
|
||||
[Connecting an AI assistant](ai_assistants#by-web-address)).
|
||||
|
||||
| Option | Effect |
|
||||
|---|---|
|
||||
| `--http [PORT]` | serve on `127.0.0.1:PORT` (default 8731). It never listens on any other address |
|
||||
| `--allow-edit` | offer every tool. Without it only the eight that read a file are offered: `qet_project_info`, `qet_elements`, `qet_conductors`, `qet_items`, `qet_diff`, `qet_scan`, `qet_element_info`, `qet_element_search` |
|
||||
| `--allow-origin ORIGIN` | a web page origin allowed to call, for a client that runs in a browser (repeatable) |
|
||||
| `--show-token` / `--new-token` | print the token / replace it, which cuts off every client using the old one |
|
||||
| `QET_MCP_TOKEN_FILE` | where the token is kept. Default: `~/.config/qet-mcp/token`; `%APPDATA%\qet-mcp\token` on Windows; `~/Library/Application Support/qet-mcp/token` on macOS |
|
||||
|
||||
What it refuses, before reading a request:
|
||||
|
||||
| Refused | Answer | Why |
|
||||
|---|---|---|
|
||||
| a `Host` other than `127.0.0.1:PORT` or `localhost:PORT` | 403 | a web page reaching a local server through a name of its own (DNS rebinding) |
|
||||
| an `Origin` not allowed with `--allow-origin` | 403 | a web page you visit calling it |
|
||||
| a missing or wrong token | 401 | anyone else on the machine |
|
||||
| a body over 1 MB, not JSON, or a batch | 413 / 415 / 400 | |
|
||||
| GET, DELETE and other methods | 405 | no event stream, no sessions |
|
||||
|
||||
The token file is created readable by you only; if others can read it, the
|
||||
server refuses to use it. `QET_MCP_WORKSPACE` must be set, because a server
|
||||
started by hand from your home folder would otherwise serve all of it.
|
||||
Every call is logged to standard error with the tool and the paths it was
|
||||
given, never file contents or the token.
|
||||
|
||||
It speaks the protocol versions that begin with `initialize` (2025-03-26 to
|
||||
2025-11-25). Clients on the newer revision fall back to it.
|
||||
|
||||
---
|
||||
|
||||
## Using it without Claude Code
|
||||
|
||||
Added in
|
||||
|
||||
Reference in New Issue
Block a user