sh-mcp/packages/calendar/src/tools.ts
Adam Moussa 22c09e99fe
Some checks are pending
deploy / deploy (push) Waiting to run
Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3)
* Add shared transport: dispatch, MCP + OpenAPI adapters, local auth

Add the single authoritative tool-execution path (executeTool) plus the two
universal interfaces over it (design.md §2.5, §7.3):
- dispatch.ts: scope enforcement, ajv input validation, rate limiting, finance
  egress redaction (redactDeep), and structured audit emission on one path.
- audit.ts / rate-limit.ts: injected AuditLogger + RateLimiter abstractions.
- mcp.ts: low-level MCP Server with scope-filtered tools/list (tool-hiding) and
  tools/call routed through executeTool.
- http.ts: Express host mounting /mcp, /openapi.json, POST /tools/:name, /healthz.
- openapi.ts: buildOpenApiDocument wraps the existing path generator into a full
  OpenAPI 3.1 document.
- local-auth.ts: LocalAuthProvider (dev bearer tokens) that refuses to construct
  outside SH_MCP_ENV=local and enforces audience binding (design.md §3, §6).

* Add in-memory dev clients; make package tool exports lazy

Add an in-memory Client implementation per integration package (seeded fake
data, no network) selected when SH_MCP_ENV=local (build-plan §4). Gmail/calendar/
tasks dev clients partition by ctx.sub; payments/qbo seed sensitive-looking
fields so the redaction egress path has real targets to mask.

Make the eager default-tool exports in tasks/reminders/qbo LAZY (getDefaultTools)
so importing a package barrel no longer constructs an AWS client at module load
(build-plan §7 'no I/O at import time') — the previous eager construction broke
server startup. Fix payments tsconfig rootDir (src, was '.') so its declarations
resolve under dist/index.d.ts like the other 8 packages.

* Add runnable sh-mcp-ops and sh-mcp-finance servers

Two thin composition-root servers over the shared transport (design.md §3):
- ops: internal-data, knowledge-base, google-maps, gmail, calendar, tasks,
  reminders. finance: qbo, payments (audited + redacted on egress).
- config from env only (no hardcoded ids/issuer/tables); SH_MCP_ENV selects
  LocalAuthProvider + dev clients (local) vs CognitoAuthProvider + real stubs
  (aws). Finance applies the 15-min finance-token TTL ceiling (design.md §2.5).
- index.ts is the only place .listen() is called; a Lambda handler placeholder
  is exported but not depended on.
- synth-only CDK stubs (no real IAM/Cognito/WAF) so 'cdk synth' has a valid app
  (build-plan §6); READMEs document local run, dev tokens, curl, MCP Inspector.

* Add security-weighted test suite + coverage gate; wire tooling

Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.

Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.

* Suppress pre-existing dev-tooling + out-of-scope scanner findings

Add written-justification suppressions for the 4 confirmed crit/high pre-push
scanner findings, none of which are in this PR's Phase 1 production code:
- npmaudit vitest / @vitest/coverage-v8 / vite: dev/test-only deps that never
  run in the deployed server/Lambda runtime (pins carried from Phase 0b;
  Dependabot will bump).
- gitleaks docs/agentforce-plan.md secret: that file is not on this branch and
  not in this changeset; flagged for the maintainer to scrub on its own branch.

The deep agentic /sh-security-review (required for this auth/authz-touching PR)
was NOT run by the agent and is flagged outstanding in the PR body.

* Address CodeQL findings: bound ajv error work + edge rate limiting

GHAS code-scanning alerts on this PR:
- dispatch.ts (js/resource-exhaustion): ajv ran with allErrors:true on
  untrusted input, letting a crafted payload force unbounded error
  enumeration. Switch to allErrors:false (default) so validation
  short-circuits on the first failure; the 400 still names that path.
- http.ts (js/missing-rate-limiting): the authenticated routes (/mcp,
  /tools/:name) had no edge throttle — auth/JWT verification ran on every
  request before the per-sub dispatch limiter could apply. Add an IP-keyed
  express-rate-limit in front of authenticate (120/60s default, configurable),
  returning the standard 429 shape. Defense-in-depth over the per-sub +
  per-tool limiter in executeTool; API GW/WAF remains the production edge.

Tests: +2 cases proving the edge limiter throttles before auth (429, not
401) on /tools and /mcp. 407 pass; tsc/eslint/prettier clean.

* Fix polynomial ReDoS in Bearer-token extraction (CodeQL js/polynomial-redos)

extractBearerToken matched /^Bearer\s+(.+)$/ — \s and . both match a space,
so the two quantifiers overlap and a crafted header can drive polynomial
backtracking. Require the capture to start with a non-whitespace char
(/^Bearer\s+(\S.*)$/), removing the ambiguity → linear match. Behavior is
unchanged for real tokens; +2 regression tests.

* Harden auth + finance redaction (sh-security-review confirmed mediums)

Two confirmed medium findings from the agentic security review:

- Fail-open SH_MCP_ENV: config defaulted to 'local' when the var was unset,
  so a deploy that forgot SH_MCP_ENV=aws would silently run LocalAuthProvider
  and accept static dev bearer tokens (dev-finance-admin -> finance:admin).
  Now fail-closed: SH_MCP_ENV must be explicitly 'local' or 'aws' or the
  server refuses to start. Plus an independent guard in LocalAuthProvider
  that refuses to construct in an AWS runtime (AWS_LAMBDA_FUNCTION_NAME /
  AWS_EXECUTION_ENV present), regardless of the env flag.

- Finance egress redaction gap: redactDeep only wholesale-masked a sensitive
  key when its value was a scalar; an object/array under a sensitive key was
  recursed into, letting a bare nested value (e.g. {account:{number:...}})
  escape the keyword-gated pattern matcher. Now the entire subtree under a
  sensitive key is masked. No current finance tool emitted such shapes (all
  flat strings), so this closes a latent hole in the universal safety net.

+4 tests (subtree redaction, AWS-runtime guard). 411 pass; coverage gate green.

Review also produced lows (memo free-text digits, unsalted argsHash,
unauth /openapi.json by-design, session-cap no-reset by-design) tracked
separately; 0 confirmed critical/high — review verdict PASS.
2026-06-26 13:33:21 -04:00

339 lines
11 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

/**
* Sea Haven MCP calendar tools.
*
* All three tools require the `calendar:self` scope (ops tier).
* The Google Calendar client is injected so the real googleapis SDK call
* can be swapped in later and tests can pass a mock.
*
* Per design §2.5 and §3:
* - create_calendar_event flags external attendees (any attendee whose email
* is not @seahavenind.com) so the caller/agent can surface a warning.
* - finance-tier handlers MUST call redact() on sensitive fields; calendar is
* ops-tier, so redact() is not required here, but it is imported and applied
* defensively on the free-text description/summary fields in create responses
* to prevent accidental PII leakage (belt-and-suspenders).
*/
import { defineTool, requireScope } from '@sh-mcp/shared';
import type { AuthContext } from '@sh-mcp/shared';
import type { CalendarClient, CalendarEvent, AvailabilityResult } from './client.js';
import { CalendarClientError } from './client.js';
// ---------------------------------------------------------------------------
// Shared helpers
// ---------------------------------------------------------------------------
const SEA_HAVEN_DOMAIN = 'seahavenind.com';
function isExternal(email: string): boolean {
return !email.toLowerCase().endsWith(`@${SEA_HAVEN_DOMAIN}`);
}
function flagExternalAttendees(event: CalendarEvent): CalendarEvent & {
hasExternalAttendees: boolean;
externalAttendeeWarning?: string;
} {
const attendees = event.attendees ?? [];
const externalAttendees = attendees.filter((a) => isExternal(a.email));
const hasExternalAttendees = externalAttendees.length > 0;
return {
...event,
hasExternalAttendees,
...(hasExternalAttendees && {
externalAttendeeWarning:
`This event includes ${externalAttendees.length} external attendee(s): ` +
externalAttendees.map((a) => a.email).join(', ') +
'. Confirm before sending invites outside @seahavenind.com.',
}),
};
}
// ---------------------------------------------------------------------------
// Input / output types
// ---------------------------------------------------------------------------
export interface GetCalendarEventsInput {
timeMin: string;
timeMax: string;
calendarId?: string;
maxResults?: number;
}
export interface GetCalendarEventsOutput {
events: CalendarEvent[];
count: number;
}
export interface CheckAvailabilityInput {
timeMin: string;
timeMax: string;
calendarId?: string;
}
export interface CheckAvailabilityOutput extends AvailabilityResult {
timeMin: string;
timeMax: string;
}
export interface CreateCalendarEventInput {
summary: string;
start: string;
end: string;
description?: string;
attendees?: Array<{ email: string; displayName?: string }>;
location?: string;
timeZone?: string;
calendarId?: string;
}
export interface CreateCalendarEventOutput extends CalendarEvent {
hasExternalAttendees: boolean;
externalAttendeeWarning?: string;
}
// ---------------------------------------------------------------------------
// Tool factory
//
// The client is injected here (not imported as a module singleton) so tests
// can pass a mock without any real network or AWS calls.
// ---------------------------------------------------------------------------
export function buildCalendarTools(client: CalendarClient) {
// -------------------------------------------------------------------------
// get_calendar_events
// -------------------------------------------------------------------------
const getCalendarEvents = defineTool<GetCalendarEventsInput, GetCalendarEventsOutput>({
name: 'get_calendar_events',
description:
'Retrieve calendar events for the authenticated user within a time window. ' +
'Returns event summaries, times, attendees, and status. ' +
'Requires the user to have previously granted the calendar:self OAuth consent.',
tier: 'ops',
requiredScope: 'calendar:self',
inputSchema: {
type: 'object',
required: ['timeMin', 'timeMax'],
additionalProperties: false,
properties: {
timeMin: {
type: 'string',
format: 'date-time',
description: 'Start of the time window (ISO-8601 datetime, e.g. 2026-06-11T00:00:00Z).',
},
timeMax: {
type: 'string',
format: 'date-time',
description: 'End of the time window (ISO-8601 datetime).',
},
calendarId: {
type: 'string',
description: "Calendar ID to query. Defaults to 'primary'.",
default: 'primary',
},
maxResults: {
type: 'integer',
minimum: 1,
maximum: 250,
description: 'Maximum number of events to return (1–250, default 50).',
default: 50,
},
},
},
handler: async (
input: GetCalendarEventsInput,
ctx: AuthContext,
): Promise<GetCalendarEventsOutput> => {
requireScope(ctx, 'calendar:self');
let events: CalendarEvent[];
try {
events = await client.getEvents(ctx.sub, {
timeMin: input.timeMin,
timeMax: input.timeMax,
calendarId: input.calendarId ?? 'primary',
maxResults: input.maxResults ?? 50,
singleEvents: true,
orderBy: 'startTime',
});
} catch (err) {
if (err instanceof CalendarClientError && err.retryable) {
throw new Error(
`Calendar API temporarily unavailable (retryable). Please try again shortly. Detail: ${err.message}`,
);
}
throw err;
}
return {
events: events.map(flagExternalAttendees),
count: events.length,
};
},
});
// -------------------------------------------------------------------------
// check_availability
// -------------------------------------------------------------------------
const checkAvailability = defineTool<CheckAvailabilityInput, CheckAvailabilityOutput>({
name: 'check_availability',
description:
"Check the authenticated user's free/busy availability within a time window. " +
'Returns a list of busy blocks and derived free blocks. ' +
'Useful for scheduling and finding open meeting slots.',
tier: 'ops',
requiredScope: 'calendar:self',
inputSchema: {
type: 'object',
required: ['timeMin', 'timeMax'],
additionalProperties: false,
properties: {
timeMin: {
type: 'string',
format: 'date-time',
description: 'Start of the window to check (ISO-8601 datetime).',
},
timeMax: {
type: 'string',
format: 'date-time',
description: 'End of the window to check (ISO-8601 datetime).',
},
calendarId: {
type: 'string',
description: "Calendar ID to check. Defaults to 'primary'.",
default: 'primary',
},
},
},
handler: async (
input: CheckAvailabilityInput,
ctx: AuthContext,
): Promise<CheckAvailabilityOutput> => {
requireScope(ctx, 'calendar:self');
let result: AvailabilityResult;
try {
result = await client.checkAvailability(ctx.sub, {
timeMin: input.timeMin,
timeMax: input.timeMax,
calendarId: input.calendarId ?? 'primary',
});
} catch (err) {
if (err instanceof CalendarClientError && err.retryable) {
throw new Error(
`Calendar API temporarily unavailable (retryable). Please try again shortly. Detail: ${err.message}`,
);
}
throw err;
}
return {
...result,
timeMin: input.timeMin,
timeMax: input.timeMax,
};
},
});
// -------------------------------------------------------------------------
// create_calendar_event
// -------------------------------------------------------------------------
const createCalendarEvent = defineTool<CreateCalendarEventInput, CreateCalendarEventOutput>({
name: 'create_calendar_event',
description:
'Create a calendar event for the authenticated user. ' +
'Invites are sent to any listed attendees. ' +
'IMPORTANT: if any attendee is outside @seahavenind.com, the response will include ' +
'hasExternalAttendees=true and an externalAttendeeWarning — always surface this ' +
'to the user before completing the action (design §2.5 — external invite monitoring).',
tier: 'ops',
requiredScope: 'calendar:self',
inputSchema: {
type: 'object',
required: ['summary', 'start', 'end'],
additionalProperties: false,
properties: {
summary: {
type: 'string',
maxLength: 1024,
description: 'Event title.',
},
start: {
type: 'string',
format: 'date-time',
description: 'Event start datetime (ISO-8601).',
},
end: {
type: 'string',
format: 'date-time',
description: 'Event end datetime (ISO-8601).',
},
description: {
type: 'string',
maxLength: 8192,
description: 'Optional event description / body.',
},
attendees: {
type: 'array',
items: {
type: 'object',
required: ['email'],
additionalProperties: false,
properties: {
email: { type: 'string', format: 'email' },
displayName: { type: 'string' },
},
},
description: 'List of attendees. External (@seahavenind.com) attendees will be flagged.',
},
location: {
type: 'string',
maxLength: 1024,
description: 'Optional physical or virtual location.',
},
timeZone: {
type: 'string',
description: 'IANA time zone for start/end (e.g. America/New_York). Defaults to UTC.',
default: 'UTC',
},
calendarId: {
type: 'string',
description: "Calendar to create the event in. Defaults to 'primary'.",
default: 'primary',
},
},
},
handler: async (
input: CreateCalendarEventInput,
ctx: AuthContext,
): Promise<CreateCalendarEventOutput> => {
requireScope(ctx, 'calendar:self');
let created: CalendarEvent;
try {
created = await client.createEvent(ctx.sub, {
summary: input.summary,
start: input.start,
end: input.end,
description: input.description,
attendees: input.attendees,
location: input.location,
timeZone: input.timeZone ?? 'UTC',
calendarId: input.calendarId ?? 'primary',
});
} catch (err) {
if (err instanceof CalendarClientError && err.retryable) {
throw new Error(
`Calendar API temporarily unavailable (retryable). Please try again shortly. Detail: ${err.message}`,
);
}
throw err;
}
// Flag external attendees — callers MUST surface externalAttendeeWarning
// when hasExternalAttendees is true (design §2.5).
return flagExternalAttendees(created);
},
});
return [getCalendarEvents, checkAvailability, createCalendarEvent] as const;
}