openpencil/crates
Kayshen-X 6de61689df fix(web): attach bridge token to the mcp server settings fetch
The Task 7 token audit missed a daemon-bound network call:
`agent_settings_mcp_server.rs::request_mcp_server_update` POSTs
`/api/mcp/server` via `window.fetch` (Reflect::get) and attached no
`X-OpenPencil-Token`. In managed mode (VS Code webview) the daemon's
auth gate rejects the request (fails closed), silently breaking the
MCP server start/stop toggle in the settings modal.

Fix: build the request URL from `daemon_base()` (absolute, matching
every other daemon call site in the crate) instead of a bare relative
path, and attach the token via a new shared `live_sync::daemon_token_for`
helper — factored out of `attach_daemon_headers` so XHR and non-XHR
call sites can't drift on the leak-guard policy (token only when set
AND the URL targets the daemon).

Corrected audit (grep -rn "XmlHttpRequest|fetch|Request::new"
crates/op-host-web/src, network-issuing sites only): 5 sites total —
the 4 live_sync XHR helpers + web_model_catalog + web_ai_transport +
iconify_web's fetch_text all already tokened via attach_daemon_headers
(iconify_web additionally verified to withhold the token from the
public Iconify CDN target); agent_settings_mcp_server's window.fetch
was the sole untokened site and is now fixed. No other window.fetch /
Request::new call sites exist in the crate.

Verification: cargo check --target wasm32-unknown-unknown -p
op-host-web --no-default-features --features canvaskit (pass, 1
pre-existing unrelated warning) / --features web (pass, clean);
cargo clippy -p op-host-web --all-targets -- -D warnings (pass, clean).
2026-07-17 01:17:08 +08:00
..
op-acp
op-ai feat(agent): unify generation UX and CLI providers 2026-07-15 03:48:29 +08:00
op-ai-skills fix(orchestrator): preserve and repair progress rings 2026-07-15 03:29:39 +08:00
op-cli fix(ci): clear Rust workflow blockers 2026-07-15 22:47:39 +08:00
op-codegen test: decouple document fixtures from product releases 2026-07-15 21:17:20 +08:00
op-config-store
op-design-lint fix(orchestrator): preserve and repair progress rings 2026-07-15 03:29:39 +08:00
op-editor-core feat(editor): sync gate state machine and bridge protocol codec 2026-07-16 23:13:34 +08:00
op-editor-host-core fix(ci): clear Rust workflow blockers 2026-07-15 22:47:39 +08:00
op-editor-ui fix(canvas): align generating label icon with text 2026-07-16 21:19:58 +08:00
op-figma perf(figma): cut import clone amplification 2026-07-11 10:04:41 +08:00
op-git
op-host-desktop feat(web): managed serve-web contract with handshake and parent-death lease 2026-07-16 23:28:08 +08:00
op-host-native test: decouple document fixtures from product releases 2026-07-15 21:17:20 +08:00
op-host-services feat(web): postMessage bridge with token bootstrap and conflict resolution 2026-07-17 01:06:14 +08:00
op-host-web fix(web): attach bridge token to the mcp server settings fetch 2026-07-17 01:17:08 +08:00
op-host-web-server feat(web): managed serve-web contract with handshake and parent-death lease 2026-07-16 23:28:08 +08:00
op-i18n feat(agent): unify generation UX and CLI providers 2026-07-15 03:48:29 +08:00
op-mcp fix(mcp): harden batch design and image semantics 2026-07-14 00:29:59 +08:00
op-opmerge
op-orchestrator fix(orchestrator): center resolved radial content 2026-07-15 23:49:58 +08:00
op-pen-loader test: decouple document fixtures from product releases 2026-07-15 21:17:20 +08:00
op-process-io
op-rpc-transport
op-smoke chore(smoke): audit rubric and loop-vs-orchestrator A/B harness 2026-07-12 02:56:43 +08:00
op-web-sdk perf(sdk): share scene via rc and idle the raf pump when clean 2026-07-10 22:56:25 +08:00
CLAUDE.md fix(orchestrator): preserve and repair progress rings 2026-07-15 03:29:39 +08:00