Deploy a shared MCP-tool permissions allowlist; detect legacy .claude/settings.json

Two related fixes, discovered together while debugging Wareco's duplicated
"Project" scope MCP entries:

1. New custom/setup/machine/settings.json template + a merge-safe deploy
   step in sync-bcquality-knowledge.ps1 (section 10): auto-approves the
   read-only/already-protocol-gated tool calls across the three
   CURABIS-managed MCP servers (businesscentral's 15 static tools, al's
   11 dev-loop tools, microsoft-learn's 3 docs tools) via
   ~/.claude/settings.json's permissions.allow -- merged into whatever
   already exists, never overwritten, since that file also carries a
   developer's personal settings. Tested against a real 298-entry
   settings.json: preserved every existing key/array untouched, added
   only the 14 genuinely-missing entries.

   Found and fixed two real bugs while building this: -AsHashtable
   doesn't exist in Windows PowerShell 5.1 (this script also runs via
   `powershell`, not just `pwsh`) -- switched to PSCustomObject +
   Add-Member. And Set-Content -Encoding utf8 writes a BOM in PS5.1 with
   no utf8NoBOM option -- switched to [System.IO.File]::WriteAllText
   with an explicit no-BOM UTF8Encoding, since the original file had no
   BOM and a JSON parser choking on one would have silently broken every
   developer's settings.json.

2. Wareco's committed .claude/settings.json still has the pre-migration
   Dynamic Tool Mode tool names (bc_actions_search/describe) and an
   enabledMcpjsonServers entry for al/businesscentral -- the latter is
   why the MCP servers panel shows them duplicated under "Project" scope
   next to the correct "User" scope registration. Added detection +
   confirmed-removal migration step (mirroring the existing .mcp.json
   migration's multi-developer coordination caveat) and Roemer station
   16 to catch this on other pre-migration repos (gtt-marine likely has
   the same file).
This commit is contained in:
Michael Dieringer 2026-08-04 07:31:46 +02:00
parent c58c3f6e0f
commit a3b79eedc2
4 changed files with 141 additions and 1 deletions

View file

@ -73,6 +73,7 @@ old HTTP-encoding pitfalls do not exist here).
|---|---|
| bc-mcp-bridge.js | `{BASE}/bc-mcp-bridge.js` |
| bc-mcp.config.template.json | `{BASE}/machine/bc-mcp.config.template.json` |
| settings.json (permissions template) | `{BASE}/machine/settings.json` (merged into `~/.claude/settings.json`, never overwritten wholesale — see Step 3c) |
| bcquality.agent.md | `{BASE}/templates/bcquality.agent.md` |
| immanuel.agent.md | `{AGENTS_BASE}/immanuel.agent.md` |
| carlin.agent.md | `{AGENTS_BASE}/carlin.agent.md` |
@ -720,6 +721,41 @@ independently of the `.mcp.json` migration above, since removing the *file*
doesn't affect any `.mcp.json` entry that still references the old
repo-relative walk-up form until that entry itself is migrated per step 3.
**5. `.claude/settings.json` — legacy repo-committed permissions block
(2026-08-03, same multi-developer coordination caveat as step 3)**
A repo from before the BC MCP static-tool-mode migration (2026-08-03) may
have a git-committed `.claude/settings.json` with a `permissions.allow`
block naming the OLD Dynamic Tool Mode tool names
(`mcp__businesscentral__bc_actions_search` / `bc_actions_describe` /
`bc_actions_invoke`) and/or an `enabledMcpjsonServers` entry for `al` /
`businesscentral`. Found live in the `Wareco` repo during a full developer
onboarding: the stale `enabledMcpjsonServers` entry causes the MCP servers
panel to show `al`/`businesscentral` duplicated under "Project" scope
alongside the correct "User" scope registration — confusing, and every
other CURABIS repo from before the migration likely has the same file.
If `.claude/settings.json` contains `bc_actions_search`, `bc_actions_describe`,
`bc_actions_invoke`, or an `enabledMcpjsonServers` entry for `al`/`businesscentral`:
```
⚠️ .claude/settings.json indeholder en forældet tilladelsesliste fra før
static-tool-mode-migreringen (bc_actions_search/describe/invoke er de gamle
værktøjsnavne) og/eller enabledMcpjsonServers for al/businesscentral, som
duplikerer den korrekte user-scope-registrering under "Project" i MCP-panelet.
Skal jeg fjerne den forældede permissions-blok og enabledMcpjsonServers-linjen
fra .claude/settings.json? (ja/nej) De aktuelle, korrekte værktøjsnavne bliver
i stedet dækket af ~/.claude/settings.json (maskin-globalt, Step 3c).
```
Only remove the stale entries with explicit confirmation — same reasoning
as `.mcp.json`: this file is git-committed and shared, and a developer who
hasn't migrated their own machine's `~/.claude/settings.json` yet (Step 3c)
would lose their auto-approvals if this is pulled before they have. If the
file becomes empty afterward, propose deleting it entirely in the same
confirmation.
### HEARTBEAT.md token substitution (Mode B)
When creating HEARTBEAT.md from template in Mode B: