(
request: Request,
principal: Extract<AuthOutcome, { readonly _tag: "Authenticated" }>["principal"],
resource: McpResource,
)
| 202 | }; |
| 203 | |
| 204 | const propsForPrincipal = ( |
| 205 | request: Request, |
| 206 | principal: Extract<AuthOutcome, { readonly _tag: "Authenticated" }>["principal"], |
| 207 | resource: McpResource, |
| 208 | ): Effect.Effect<McpSessionProps> => |
| 209 | Effect.gen(function* () { |
| 210 | const propagation = yield* currentPropagationHeaders(request); |
| 211 | return { |
| 212 | session: { |
| 213 | organizationId: principal.organizationId, |
| 214 | // The org record the live membership check resolved microseconds ago, |
| 215 | // handed to the session DO so it never opens a connection of its own to |
| 216 | // re-read it. An unnamed org (no auth plane could resolve one) is |
| 217 | // omitted rather than sent empty, so the DO can tell "not carried" from |
| 218 | // "carried, and blank". |
| 219 | ...(principal.organizationName ? { organizationName: principal.organizationName } : {}), |
| 220 | ...(principal.organizationSlug ? { organizationSlug: principal.organizationSlug } : {}), |
| 221 | userId: principal.accountId, |
| 222 | elicitationMode: readElicitationMode(request), |
| 223 | artifactsEnabled: readArtifactsEnabled(request), |
| 224 | searchToolsEnabled: readSearchToolsEnabled(request), |
| 225 | resource, |
| 226 | webOrigin: new URL(request.url).origin, |
| 227 | }, |
| 228 | propagation, |
| 229 | }; |
| 230 | }); |
| 231 | |
| 232 | export const makeCloudMcpAgentHandler = () => { |
| 233 | const serveOptions = { |
no test coverage detected