/** * Scope-based tool visibility (tool-hiding). * * design.md §2.5: a caller sees only the tools whose `requiredScope` is in their * `AuthContext`. Both transports use this so the MCP `tools/list` and the * per-caller OpenAPI document stay consistent. * * IMPORTANT: hiding is a CONVENIENCE, never the access boundary. The dispatcher * (`executeTool` → `requireScope`) is authoritative; a forced call to a hidden * tool still returns 403 (design.md §2.5). */ import type { ToolRegistry } from './registry.js'; import type { AuthContext, ToolDef } from './types.js'; /** Tools the caller is permitted to see, in registry insertion order. */ export function visibleTools( registry: ToolRegistry, ctx: AuthContext, ): ToolDef[] { const scopes = new Set(ctx.scopes); return registry.list().filter((tool) => scopes.has(tool.requiredScope)) as ToolDef< unknown, unknown >[]; }