Deploy a shared MCP-tool permissions allowlist; detect legacy .claude/settings.json

Two related fixes, discovered together while debugging Wareco's duplicated
"Project" scope MCP entries:

1. New custom/setup/machine/settings.json template + a merge-safe deploy
   step in sync-bcquality-knowledge.ps1 (section 10): auto-approves the
   read-only/already-protocol-gated tool calls across the three
   CURABIS-managed MCP servers (businesscentral's 15 static tools, al's
   11 dev-loop tools, microsoft-learn's 3 docs tools) via
   ~/.claude/settings.json's permissions.allow -- merged into whatever
   already exists, never overwritten, since that file also carries a
   developer's personal settings. Tested against a real 298-entry
   settings.json: preserved every existing key/array untouched, added
   only the 14 genuinely-missing entries.

   Found and fixed two real bugs while building this: -AsHashtable
   doesn't exist in Windows PowerShell 5.1 (this script also runs via
   `powershell`, not just `pwsh`) -- switched to PSCustomObject +
   Add-Member. And Set-Content -Encoding utf8 writes a BOM in PS5.1 with
   no utf8NoBOM option -- switched to [System.IO.File]::WriteAllText
   with an explicit no-BOM UTF8Encoding, since the original file had no
   BOM and a JSON parser choking on one would have silently broken every
   developer's settings.json.

2. Wareco's committed .claude/settings.json still has the pre-migration
   Dynamic Tool Mode tool names (bc_actions_search/describe) and an
   enabledMcpjsonServers entry for al/businesscentral -- the latter is
   why the MCP servers panel shows them duplicated under "Project" scope
   next to the correct "User" scope registration. Added detection +
   confirmed-removal migration step (mirroring the existing .mcp.json
   migration's multi-developer coordination caveat) and Roemer station
   16 to catch this on other pre-migration repos (gtt-marine likely has
   the same file).
This commit is contained in:
Michael Dieringer 2026-08-04 07:31:46 +02:00
parent c58c3f6e0f
commit a3b79eedc2
4 changed files with 141 additions and 1 deletions

View file

@ -222,3 +222,62 @@ function Ensure-UserMcpHttpServer {
}
Ensure-UserMcpHttpServer -Name 'microsoft-learn' -Url 'https://learn.microsoft.com/api/mcp'
# --- 10. Permissions allowlist -> ~/.claude/settings.json (MERGE, never overwrite) ---
# Unlike the other artifacts above, settings.json is not pure BCQuality content -
# it also carries a developer's personal settings (theme, model, hooks, etc).
# Only merge the permissions.allow entries from the template below into whatever
# already exists; never replace the file wholesale. Scope: the three CURABIS-
# managed MCP servers only (businesscentral, al, microsoft-learn) - all either
# read-only or already gated by Smiley's own protocol checks (red/green
# confirmation, independent review), so the tool-permission prompt is redundant
# friction here, not a real safety boundary. 2026-08-03: added after a developer
# had to click through the same MCP approval prompts repeatedly across sessions.
$settingsTemplate = Join-Path $clone 'custom\setup\machine\settings.json'
$settingsDest = Join-Path $env:USERPROFILE '.claude\settings.json'
if (Test-Path $settingsTemplate) {
# NB: -AsHashtable (ConvertFrom-Json) findes kun i PowerShell 6+. Dette script
# koeres ogsaa via `powershell` (Windows PowerShell 5.1) paa udviklermaskiner,
# saa vi bruger PSCustomObject + Add-Member i stedet - virker paa begge.
$templateAllow = (Get-Content $settingsTemplate -Raw | ConvertFrom-Json).permissions.allow
$settings = $null
if (Test-Path $settingsDest) {
$raw = Get-Content $settingsDest -Raw
if ($raw -and $raw.Trim()) {
$settings = $raw | ConvertFrom-Json
}
}
if (-not $settings) { $settings = [PSCustomObject]@{} }
if (-not (Get-Member -InputObject $settings -Name 'permissions' -MemberType NoteProperty)) {
$settings | Add-Member -MemberType NoteProperty -Name 'permissions' -Value ([PSCustomObject]@{})
}
if (-not (Get-Member -InputObject $settings.permissions -Name 'allow' -MemberType NoteProperty)) {
$settings.permissions | Add-Member -MemberType NoteProperty -Name 'allow' -Value @()
}
$existingAllow = [System.Collections.Generic.List[string]]::new()
foreach ($r in @($settings.permissions.allow)) { $existingAllow.Add([string]$r) }
$added = 0
foreach ($rule in $templateAllow) {
if ($existingAllow -notcontains $rule) {
$existingAllow.Add($rule)
$added++
}
}
$settings.permissions.allow = $existingAllow.ToArray()
# NB: Set-Content -Encoding utf8 skriver en BOM i Windows PowerShell 5.1 (ingen
# utf8NoBOM-mulighed der) - fundet under test 2026-08-03: settings.json havde
# ingen BOM originalt, og en tilfoejet BOM kan knaekke JSON-parsere der laeser
# filen. [System.IO.File]::WriteAllText med en explicit no-BOM UTF8Encoding
# virker identisk paa PS5.1 og PS7.
$json = $settings | ConvertTo-Json -Depth 20
[System.IO.File]::WriteAllText($settingsDest, $json, [System.Text.UTF8Encoding]::new($false))
Write-Host "Permissions-allowlist merged ind i $settingsDest - $added ny(e) regel(er) tilfoejet."
} else {
Write-Warning "settings.json-skabelon ikke fundet i klonen, springer over."
}