Expand description
bugwarden — MCP server for Bugzilla with operator-controlled security guards.
This library target exists so the MCP tool surface can be driven end to
end by integration tests (tests/): the binary (main.rs) is a thin
transport wrapper around server::BugWarden, and a binary-only crate
would leave the tool gates — the code that calls the guard — untestable
as a unit. The supported product remains the bugwarden binary; this
API carries no stability promise of its own.
Modules§
- audit
- Operator-facing audit event stream: record schema and JSONL file sink.
- config
- CLI configuration for bugwarden.
- http_
auth - Who the HTTP caller is, decided before rmcp sees the request (issue #32).
- http_
session - Session-id provenance for the streamable-HTTP transport.
- otel
- OTLP export of the audit stream and of the server’s own diagnostics (issue #31).
- panic_
hook - The process’s panic hook: one tracing event per panic, and never the payload (issue #270).
- server
- MCP tool surface for bugwarden.
- stdio
- What wraps rmcp’s stdio transport: a frame bound (
BoundedLines) and aserver/discoveranswer (DiscoverAnswering). - tracing_
fields - The diagnostic stream’s bound, applied at the SINK: every field of
every tracing line is cut at
PARAM_VALUE_MAX_CHARScharacters and rewritten wherever it carries a control character or a line break (#260, #266, #275). That set is the WHOLE C0 range\x00–\x1f, DEL, the C1 range\u{80}–\u{9f}, and U+2028 and U+2029 — every control character, and every line break Unicode makes mandatory. It is wider than the set tracing-subscriber escapes inmessage.