diff --git a/ai_assistants.md b/ai_assistants.md index d769e1b..c1a932d 100644 --- a/ai_assistants.md +++ b/ai_assistants.md @@ -219,43 +219,6 @@ The server speaks MCP over standard input and output. --- -## By web address - -> **Status: pending.** This section describes -> [PR #1132](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1132), -> not yet merged. Nothing here works until that lands — check the PR -> before trying any of this against your own build. This section will drop -> this notice once it does. - -Some assistants connect to a server by address instead of starting it. Start -it yourself, on this computer only: - -```bash -QET_MCP_WORKSPACE=/path/to/drawings python3 qet_mcp.py --http -python3 qet_mcp.py --show-token -``` - -and give the assistant `http://127.0.0.1:8731/mcp` with the header -`Authorization: Bearer `. For example in VS Code: - -```json -{ - "servers": { - "qet": { - "type": "http", - "url": "http://127.0.0.1:8731/mcp", - "headers": { "Authorization": "Bearer ${input:qet-token}" } - } - }, - "inputs": [ - { "id": "qet-token", "type": "promptString", "description": "qet-mcp token", "password": true } - ] -} -``` - -It offers only the reading tools unless started with `--allow-edit`. Every -option and what it refuses is on the [MCP server](mcp_server#over-http) page. - ## ChatGPT, and Claude or Copilot in a web browser These reach a server only through the internet, from their own computers. diff --git a/mcp_server.md b/mcp_server.md index 429dbe6..bedd955 100644 --- a/mcp_server.md +++ b/mcp_server.md @@ -72,56 +72,6 @@ above are the only setup that matters, and both are covered below. --- -## Over HTTP - -> **Status: pending.** This section describes -> [PR #1132](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1132), -> not yet merged. Nothing here works until that lands — check the PR -> before trying any of this against your own build. This section will drop -> this notice once it does. - -Some assistants connect to a server by web address rather than starting it -themselves. `--http` serves the same tools on this computer only: - -```bash -export QET_MCP_WORKSPACE=/home/you/drawings -python3 misc/qet-mcp/qet_mcp.py --http # http://127.0.0.1:8731/mcp -python3 misc/qet-mcp/qet_mcp.py --show-token # the token a client must send -``` - -The client sends `Authorization: Bearer ` with every request; its -setup usually has a "headers" field for it (examples on -[Connecting an AI assistant](ai_assistants#by-web-address)). - -| Option | Effect | -|---|---| -| `--http [PORT]` | serve on `127.0.0.1:PORT` (default 8731). It never listens on any other address | -| `--allow-edit` | offer every tool. Without it only the eight that read a file are offered: `qet_project_info`, `qet_elements`, `qet_conductors`, `qet_items`, `qet_diff`, `qet_scan`, `qet_element_info`, `qet_element_search` | -| `--allow-origin ORIGIN` | a web page origin allowed to call, for a client that runs in a browser (repeatable) | -| `--show-token` / `--new-token` | print the token / replace it, which cuts off every client using the old one | -| `QET_MCP_TOKEN_FILE` | where the token is kept. Default: `~/.config/qet-mcp/token`; `%APPDATA%\qet-mcp\token` on Windows; `~/Library/Application Support/qet-mcp/token` on macOS | - -What it refuses, before reading a request: - -| Refused | Answer | Why | -|---|---|---| -| a `Host` other than `127.0.0.1:PORT` or `localhost:PORT` | 403 | a web page reaching a local server through a name of its own (DNS rebinding) | -| an `Origin` not allowed with `--allow-origin` | 403 | a web page you visit calling it | -| a missing or wrong token | 401 | anyone else on the machine | -| a body over 1 MB, not JSON, or a batch | 413 / 415 / 400 | | -| GET, DELETE and other methods | 405 | no event stream, no sessions | - -The token file is created readable by you only; if others can read it, the -server refuses to use it. `QET_MCP_WORKSPACE` must be set, because a server -started by hand from your home folder would otherwise serve all of it. -Every call is logged to standard error with the tool and the paths it was -given, never file contents or the token. - -It speaks the protocol versions that begin with `initialize` (2025-03-26 to -2025-11-25). Clients on the newer revision fall back to it. - ---- - ## Using it without Claude Code Added in