isMutatingMethod reports whether an HTTP method can mutate server state. The verified-email gate only fires on these; reads pass through so an unverified user can still fetch context over MCP.
(method string)
| 532 | // state. The verified-email gate only fires on these; reads pass |
| 533 | // through so an unverified user can still fetch context over MCP. |
| 534 | func isMutatingMethod(method string) bool { |
| 535 | switch method { |
| 536 | case http.MethodPost, http.MethodPatch, http.MethodPut, http.MethodDelete: |
| 537 | return true |
| 538 | default: |
| 539 | return false |
| 540 | } |
| 541 | } |
| 542 | |
| 543 | func (d *HTTPHandlerDispatcher) buildAuthedRequest( |
| 544 | ctx context.Context, |