Two related fixes, discovered together while debugging Wareco's duplicated
"Project" scope MCP entries:
1. New custom/setup/machine/settings.json template + a merge-safe deploy
step in sync-bcquality-knowledge.ps1 (section 10): auto-approves the
read-only/already-protocol-gated tool calls across the three
CURABIS-managed MCP servers (businesscentral's 15 static tools, al's
11 dev-loop tools, microsoft-learn's 3 docs tools) via
~/.claude/settings.json's permissions.allow -- merged into whatever
already exists, never overwritten, since that file also carries a
developer's personal settings. Tested against a real 298-entry
settings.json: preserved every existing key/array untouched, added
only the 14 genuinely-missing entries.
Found and fixed two real bugs while building this: -AsHashtable
doesn't exist in Windows PowerShell 5.1 (this script also runs via
`powershell`, not just `pwsh`) -- switched to PSCustomObject +
Add-Member. And Set-Content -Encoding utf8 writes a BOM in PS5.1 with
no utf8NoBOM option -- switched to [System.IO.File]::WriteAllText
with an explicit no-BOM UTF8Encoding, since the original file had no
BOM and a JSON parser choking on one would have silently broken every
developer's settings.json.
2. Wareco's committed .claude/settings.json still has the pre-migration
Dynamic Tool Mode tool names (bc_actions_search/describe) and an
enabledMcpjsonServers entry for al/businesscentral -- the latter is
why the MCP servers panel shows them duplicated under "Project" scope
next to the correct "User" scope registration. Added detection +
confirmed-removal migration step (mirroring the existing .mcp.json
migration's multi-developer coordination caveat) and Roemer station
16 to catch this on other pre-migration repos (gtt-marine likely has
the same file).