feat: dedicated paliad MCP — replace supabase-MCP-with-SQL-wrapper for Paliadin DB access #37
Open
opened 2026-05-12 11:56:56 +00:00 by mAi
·
0 comments
No Branch/Tag Specified
main
mai/planck/coder-b5-b6-train-share
mai/archimedes/fixer-port-engine
mai/maxwell/coder-b4-akte-mode
mai/lorenz/coder-b3-event-triggered
mai/euler/fixer-builder-add
mai/brunel/fixer-prod-500s-after-b1
mai/galileo/coder-b1-b2-mvp-train
mai/pasteur/fixer-pkg-litigationplann
mai/newton/coder-b0-scenario-db
mai/edison/inventor-prd-columnar
mai/knuth/coder-workflow-tracker
mai/atlas/inventor-extend-tools
mai/cronus/inventor-unified
mai/atlas/inventor-deadline-system
mai/atlas/inventor-followup-rules
mai/athena/consultant-deadline
mai/brunel/fixer-dark-mode-support
mai/knuth/coder-cronus-fristenrechn
mai/ritchie/coder-mig-153-proceeding
mai/atlas/inventor-proceeding
mai/cronus/inventor-fristenrechner
mai/curie/coder-mig152-clone-dedupe
mai/darwin/researcher-lexy-draft
mai/knuth/coder-dedupe-null
mai/cronus/coder-composer-slice-f
mai/cronus/coder-composer-slice-e
mai/cronus/coder-composer-slice-d
mai/curie/coder-slice-b6-url-rename
mai/curie/coder-slice-b5-go-rename
mai/cronus/coder-composer-slice-c
mai/curie/coder-slice-b4-destructive-drop
mai/cronus/coder-composer-slice-b
mai/cronus/coder-composer-slice-a
mai/cronus/inventor-prd-for
mai/knuth/coder-verfahrensablauf
mai/ritchie/coder-make-backup
mai/diesel/fixer-dark-mode-css
mai/curie/coder-slice-b3-read-cutover
mai/diesel/fixer-verfahrensablauf
mai/curie/coder-slice-b2-dual-write
mai/cronus/coder-slice-d-scenarios
mai/knuth/coder-backfill-applies
mai/hermes/gitster-verfahrensablauf
mai/cronus/coder-berufung-labels-refactor
mai/diesel/hotfix-2-mig-134-missing
mai/curie/coder-slice-b1-procedural-events
mai/cronus/coder-slice-c-upc-snapshot
mai/brunel/hotfix-rename-upc-apl
mai/cronus/coder-slice-b3-primary-party
mai/cronus/coder-slice-b2-catalog-query
mai/cronus/inventor-litigation-slice-b
mai/curie/researcher-slice-b-zero
mai/cronus/inventor-litigation
mai/artemis/gitster-remove-admin
mai/ritchie/coder-sort-post-trigger
mai/knuth/coder-conditional-label
mai/hermes/coder-verfahrensablauf
mai/brunel/rebase-121-conditional
mai/knuth/coder-conditional-rule
mai/hermes/gitster-dark-mode-fix
mai/ritchie/coder-submission-form
mai/artemis/gitster-re-surface
mai/brunel/fixer-views-any-filters
mai/cronus/coder-cicd-slice-a
mai/knuth/coder-wave-1-tier-1-rule
mai/ritchie/coder-upc-damages-add
mai/cronus/inventor-ci-cd-pre
mai/brunel/rebase-108-language
mai/hermes/gitster-admin-rules-list
mai/artemis/gitster-submission
mai/icarus/gitster-verfahrensablauf
mai/orpheus/gitster-search-input
mai/atlas/coder-event-card-choices-slice-ab
mai/hermes/gitster-date-range
mai/demeter/gitster-submission
mai/knuth/coder-hl-patents-style
mai/hermes/gitster-draft-editor
mai/atlas/inventor-per-event-card
mai/knuth/coder-deadline-rule-tier
mai/cronus/coder-procedural-events-slice-a
mai/hermes/gitster-deadline-form
mai/artemis/gitster-add-missing-i18n
mai/demeter/gitster-paliadin-chat
mai/brunel/wave0-tier0-deadline-fixes
mai/artemis/coder-docker-compose-yml
mai/icarus/coder-inbox-overhaul-slice-a
mai/atlas/coder-date-range-picker-slice-a
mai/brunel/fixer-de-inf-lg-cfi
mai/cronus/inventor-procedural
mai/hermes/gitster-event-type-modal
mai/cronus/coder-backup-mode
mai/curie/researcher-bulletproof
mai/hermes/gitster-draft-editor-focus-jump
mai/cronus/inventor-backup-mode
mai/hermes/gitster-submissions
mai/artemis/gitster-deadline-form
mai/brunel/fixer-submission-preview
mai/brunel/fixer-test-data-reset
mai/artemis/gitster-approval-withdraw
mai/demeter/gitster-events
mai/hermes/gitster-sidebar-loses
mai/hermes/gitster-browse-a
mai/brunel/fixer-submissions-demo
mai/icarus/inventor-inbox-overhaul
mai/atlas/inventor-symmetric-date
mai/artemis/gitster-demote-daten
mai/hermes/gitster-team-view-mailto
mai/knuth/coder-global-schriftsatze
mai/knuth/coder-schriftsatze
mai/ritchie/coder-author-demo-docx
mai/knuth/coder-add-schriftsatze
mai/knuth/coder-add-checklist
mai/knuth/coder-anchor-lookup-must
mai/tesla/dashboard-resize-clamp
mai/knuth/coder-demote-projekt
mai/knuth/coder-paliadin-chat
mai/knuth/coder-print-views
mai/knuth/coder-add-proceeding
mai/knuth/coder-submission
mai/ritchie/coder-extend-team-email
mai/knuth/coder-changelog-catch-up
mai/tesla/dashboard-overlap
mai/pasteur/fixercoder-dashboard
mai/newton/inventor-configurable
mai/dirac/inventorcoder-user
mai/gauss/inventorcoder-team-admin
mai/kepler/inventorcoder-project
mai/darwin/roadmap-ccr-en
mai/euler/coder-small-ux-polish
mai/darwin/fristenrechner-cleanup
mai/darwin/fixercoder-priority-bug
mai/leibniz/inventor-caldav-multi
mai/hertz/inventor-unified-modal
mai/archimedes/inventor-excel-data
mai/boltzmann/inventor-gap-tolerant
mai/copernicus/submission-slice-1
mai/fermi/interactive-session
mai/hertz/inventor-suggest-changes
mai/copernicus/inventor-submission
mai/mendel/test-strategy-slice-1
mai/mendel/inventor-test-strategy
mai/ampere/custom-views-improvements
mai/joule/mig-097-apply-huygens-s
mai/ohm/workstream-b-rename
mai/huygens/workstream-a-backfill
mai/kelvin/t-204-phase-2-proceeding
mai/bohr/ingest-t-paliad-203-rule
mai/curie/fristenrechner-gap
mai/maxwell/inbox-grey-out
mai/rutherford/slice-9-follow-up-b-re
mai/dirac/slice-9-follow-up-a
mai/bose/determinator-cascade-slice-3
mai/bose/determinator-cascade-slice-2
mai/bose/determinator-row-cascade
mai/lorenz/fristen-phase-3-slice-9
mai/curie/fristen-phase-3-slice-12
mai/planck/aichat-phase-b-paliad
mai/young/fristen-phase-3-slice-11b
mai/lorenz/fristen-phase-3-slice-11a
mai/lorenz/fristen-phase-3-slice-10
mai/lorenz/fristen-phase-3-slice-8
mai/lorenz/fristen-phase-3-slice-7
mai/lorenz/fristen-phase-3-slice-6
mai/lorenz/fristen-phase-3-slice-5
mai/lorenz/fristen-phase-3-slice-4
mai/lorenz/fristen-phase-3-slice-3
mai/lorenz/fristen-phase-3-slice-2
mai/lorenz/fristen-phase-3-slice-1
mai/pauli/fristen-phase2-design
mai/tesla/project-timeline-chart
mai/pauli/fristen-logic-audit
mai/pauli/determinator-b1-row-by
mai/noether/tools-cleanup-slice-1
mai/kelvin/inventor-tools-surface
mai/planck/paliadin-per-user-rls
mai/maxwell/bug-bundle-filterbar
mai/faraday/project-timeline-chart
mai/schroedinger/smarttimeline-slice-4
mai/bohr/smarttimeline-slice-3
mai/gauss/smarttimeline-slice-2
mai/riemann/filterbar-phase-2-slice
mai/lagrange/smarttimeline-design-the
mai/curie/researcher-determinator
mai/noether/collapse-regel-typ-on
mai/riemann/inventor-universal
mai/minkowski/project-level-our-side
mai/dirac/inventor-inline-paliadin
mai/feynman/fristenrechner
mai/minkowski/navbar-dashboard-reorg
mai/shannon/approval-rework
mai/einstein/consultant-deadline-data
mai/curie/researcher-upc-rop-audit
mai/noether/paliadin-real-claude
mai/noether/inventor-paliadin
mai/hilbert/inventor-approval-policy
mai/shannon/bug-frist-due-date
mai/fritz/bug-fristen-termine
mai/godel/inventor-projects-page
mai/fritz/bug-paliadin-chat
mai/kepler/inventor-profession-vs
mai/noether/inventor-paliadin-in-app
mai/fritz/bulk-team-email-send-to
mai/noether/inventor-local-chat-for
mai/noether/inventor-data-display
mai/fritz/bug-derived-team-members
mai/fritz/bug-sidebar-visibly
mai/noether/inventor-project
mai/shannon/bug-project-team-add
mai/cronus/inventor-dual-control
mai/fritz/bug-edit-mode-on
mai/cronus/inventor-holidays-per
mai/ritchie/phase-h-ai-deadline
No results found.
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: m/paliad#37
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
t-paliad-156 shipped per-user RLS by wrapping every
paliad.*query inBEGIN; SET LOCAL ROLE authenticated; SET LOCAL request.jwt.claims = '...'; <q>; ROLLBACK;and reaching the DB through the generic supabase MCP atystudio.msbls.de. RLS now enforces visibility properly, but the trust boundary is at the prompt layer — SKILL.md says "never query paliad.* without the wrapper", and one forgotten wrapper means a leak. The MCP itself doesn't know about paliad's auth model; it just executes whatever SQL it gets, assupabase_admin(BYPASSRLS) before our wrapper kicks in.A dedicated paliad MCP moves the trust boundary from prompt-discipline to tool-availability: remove
mcp__supabase__execute_sqlfrom the paliadin pane entirely; onlymcp__paliad__*tools exist. Forgetting the wrapper becomes impossible because the unsafe surface is gone.What we get
request.jwt.claimsserver-side once, claude callspaliad_whats_on_my_plate()without any SET LOCAL boilerplate.references/sql-recipes.mdeither disappears or shrinks to an advanced "raw SQL escape hatch" section (clearly walled off).data.*or other schemas. The connection pool authenticates as a role with USAGE onpaliadonly.(user_id, tool_name, args, row_count). Way better than parsing wrapped SQL./api/paliadin/suggest/*HTTP endpoints from t-paliad-161 (deadline / appointment suggestions, approval-pipeline) becomepaliad_suggest_deadline(...)MCP tools. Same auth, same audit, no curl-in-tmux dance.Prior art in m's stack
We already run two MCPs in production, with very different shapes:
mBrian MCP —
~/dev/mBrian/src/mcp/server.tsget_node,list_nodes,create_node,get_edges,get_backlinks,find_similar,get_neighbors, etc. ~30 tools, each with a zod schema and a one-line description that doubles as the recipe.mAi MCP —
~/dev/mAi/internal/api/mcp_handler.go+cmd_mcp_memory.gomcp.godefines the wire format directly).~/.local/bin/maimcp, registered in~/.mcp.jsonascommand: maimcp.list_tasks,create_task,get_messages,send_message,list_projects,register_worker, etc. — domain verbs, not SQL..mcp.json.mai.workers(worker_id → project access). Paliad's per-call auth is JWT-based (auth.uid()→ RLS).Naive paliad MCP would land somewhere between
sqlx.DBpool, themintTurnJWThelper, the typedservices.*layer. Registering them as MCP tools is mostly wire-up.paliad_whats_on_my_plate,paliad_list_my_projects,paliad_get_project_detail,paliad_search_my_deadlines,paliad_list_my_appointments,paliad_lookup_court,paliad_lookup_deadline_rule. 7–10 tools to cover the current recipe set.jwt_path(or raw JWT) parameter; the MCP reads + verifies the signature againstSUPABASE_JWT_SECRET, extracts claims, runs the query inside a tx that setsrequest.jwt.claims. Bad/missing JWT → typed error, no fallback to service-role.Design questions to settle before writing code
paliad_execute_sql(jwt_path, sql)or no? Pros: unblocks novel recipes during dogfood. Cons: reopens the discipline problem (claude could passBEGIN; SET LOCAL ROLE supabase_admin; ...). Likely answer: no for v1; pre-build every recipe; add new tools as new patterns emerge. Revisit if dogfood reveals the tool list is too narrow./tmp/paliadin/<turn>.jwtand the envelope carries|jwt=<path>. Option A: keep file, MCP reads it (filesystem coupling between paliad-shim and paliad-mcp on the same host). Option B: skip the file, paliad-shim hands the JWT directly via tool args (simpler but JWT shows up in MCP stdio logs)..mcp.json. DB connection to youpc supabase over Tailscale — same pattern as paliad itself.postgres(BYPASSRLS). The MCP should connect as a dedicated role with USAGE onpaliadonly + GRANT to switch intoauthenticatedviaSET ROLE. Migration on top of 078.cmd/paliad-mcp/main.goproduces a binary, ships in the same Docker image, gets symlinked to~/.local/bin/paliad-mcpon mRiver via the existing install scripts.Surface sketch (v1)
Tools, all take
jwt_path(orjwtraw, TBD per Q2):paliad_whats_on_my_plate→ overdue / today / this_week / appointments_today countspaliad_list_my_projects→ active projects, paginatedpaliad_get_project_detail(id | slug)→ project + deadlines + appointments + partiespaliad_search_my_deadlines(status?, due_after?, due_before?)paliad_list_my_appointments(from, to)paliad_lookup_court(q)— firm-wide ref, no auth needed but kept in same MCP for surface coherencepaliad_lookup_deadline_rule(q)— samepaliad_suggest_deadline(...)— agent-write, folds in/api/paliadin/suggest/deadlinepaliad_suggest_appointment(...)— sameEach tool's description is the recipe; SKILL.md collapses to "call the relevant
paliad_*tool withjwt_pathfrom the envelope; on missing/invalid JWT the tool returns a structured error you should surface verbatim."Out of scope
data.*(UPC case law in youpc.org). Different schema, different ownership.sqlxdirectly.Done when
cmd/paliad-mcp/main.gobuilds, ships in the paliad image, deploys to mRiver via the existing scripts pattern (scripts/install-paliad-mcpnext toscripts/install-paliadin-skill).paliadintest config swapsmcp__supabase__execute_sqlformcp__paliad__*in.mcp.jsonfor the claude pane.references/sql-recipes.md(or wall it off as raw-SQL escape hatch).paliad_mcpPostgres role withUSAGEon schemapaliadand GRANT toSET ROLE authenticated.mcp__paliad__*, RLS enforces, audit row reflects per-call tool name.Phasing relative to t-paliad-156
Do NOT block on t-156's dogfood. The SQL-wrapper-via-MCP cut shipped today is a working enforcement layer; this issue is the next tightening pass. Right order:
.mcp.jsonon mRiver. Roll back trivially by re-enablingsupabasein the same file.