Skip to main content

BridgeContext

Struct BridgeContext 

Source
pub struct BridgeContext {
    pub env_name_charset_desc: String,
    pub max_arg_count: usize,
    pub max_arg_len: usize,
    pub max_env_count: usize,
    pub max_env_value_len: usize,
    pub max_url_len: usize,
    pub max_header_count: usize,
    pub max_header_value_len: usize,
    /* private fields */
}
Expand description

Context for rendering the runtime bridge template.

The forbidden-char/forbidden-env-name/charset-pattern fields are rendered directly from mcp_execution_core’s canonical lists so the generated bridge’s copies structurally cannot drift from the Rust source of truth — see BridgeContext::default, the only way to construct one, which populates them from mcp_execution_core::forbidden_chars/ forbidden_env_names/forbidden_env_prefix/env_name_charset_pattern rather than leaving them empty. This deliberately does not derive Default: an empty forbidden_chars would render a bridge whose validateCommandString accepts every shell metacharacter, and an empty env_name_charset_pattern would render new RegExp(''), which matches every string (fail-open on exactly the checks these exist to enforce) — so Default is hand-written to make “always populated” a property of the type rather than a convention callers must remember to uphold.

Those four fields are private with read-only accessors for the same reason: pub fields would let BridgeContext { forbidden_chars: vec![], .. } bypass the invariant entirely and still compile, silently reintroducing the fail-open state Default exists to prevent. Deserialize is intentionally not derived — nothing in this codebase deserializes a BridgeContext from external input, and doing so would need to re-validate non-emptiness rather than trust the wire data.

The remaining fields — the denial-of-service size/count ceilings (mcp_execution_core::MAX_ARG_COUNT and siblings) and env_name_charset_desc (the human-readable charset description used only in a rejection message’s text, not in the enforcement regex above) — are plain pub fields: unlike an emptied list or pattern, a wrong value here cannot fail open — at worst it makes the rendered bridge reject configs it should accept (a wrong MAX_*), or emit a confusing-but-still-rejecting error message (a wrong env_name_charset_desc), never silently accept something it shouldn’t — so the extra accessor/invariant machinery above would be pure ceremony here.

§Examples

use mcp_execution_codegen::progressive::BridgeContext;

let context = BridgeContext::default();
assert!(!context.forbidden_chars().is_empty());
assert!(context.forbidden_chars().contains(&";".to_string()));
assert!(!context.forbidden_env_prefix().is_empty());
assert!(!context.env_name_charset_pattern().is_empty());
assert!(!context.env_name_charset_desc.is_empty());
assert!(context.max_arg_count > 0);

Fields§

§env_name_charset_desc: String

Human-readable description of the charset above (mcp_execution_core::env_name_charset_desc, e.g. "[A-Za-z_][A-Za-z0-9_]*"), pre-escaped like env_name_charset_pattern and rendered into the bridge’s own rejection message so that text isn’t a second hand-copied literal alongside the pattern.

§max_arg_count: usize

Maximum number of positional arguments (mcp_execution_core::MAX_ARG_COUNT).

§max_arg_len: usize

Maximum byte length for a command, argument, env-var name, or header name (mcp_execution_core::MAX_ARG_LEN).

§max_env_count: usize

Maximum number of environment variables (mcp_execution_core::MAX_ENV_COUNT).

§max_env_value_len: usize

Maximum byte length for a single environment variable value (mcp_execution_core::MAX_ENV_VALUE_LEN).

§max_url_len: usize

Maximum byte length for the Http/Sse transport url (mcp_execution_core::MAX_URL_LEN).

§max_header_count: usize

Maximum number of HTTP headers (mcp_execution_core::MAX_HEADER_COUNT).

§max_header_value_len: usize

Maximum byte length for a single HTTP header value (mcp_execution_core::MAX_HEADER_VALUE_LEN).

Implementations§

Source§

impl BridgeContext

Source

pub fn forbidden_chars(&self) -> &[String]

Shell metacharacters forbidden in a command or argument string, each pre-escaped for safe embedding inside a single-quoted TypeScript string literal. Never empty.

§Examples
use mcp_execution_codegen::progressive::BridgeContext;

assert!(!BridgeContext::default().forbidden_chars().is_empty());
Source

pub fn forbidden_env_names(&self) -> &[String]

Forbidden environment variable names (exact match). Never empty.

§Examples
use mcp_execution_codegen::progressive::BridgeContext;

assert!(!BridgeContext::default().forbidden_env_names().is_empty());
Source

pub fn forbidden_env_prefix(&self) -> &str

Environment-variable-name prefix rejected regardless of exact match (e.g. DYLD_). Never empty.

§Examples
use mcp_execution_codegen::progressive::BridgeContext;

assert!(!BridgeContext::default().forbidden_env_prefix().is_empty());
Source

pub fn env_name_charset_pattern(&self) -> &str

POSIX/Windows environment-variable-name identifier charset, as an anchored JavaScript RegExp-compatible pattern source. Never empty.

§Examples
use mcp_execution_codegen::progressive::BridgeContext;

assert!(!BridgeContext::default().env_name_charset_pattern().is_empty());

Trait Implementations§

Source§

impl Clone for BridgeContext

Source§

fn clone(&self) -> BridgeContext

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for BridgeContext

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for BridgeContext

Source§

fn default() -> Self

Populates the forbidden-char/forbidden-env-name/charset-pattern fields directly from mcp_execution_core’s canonical lists/constants, so BridgeContext::default() can never render a bridge with an empty (fail-open) FORBIDDEN_CHARS or ENV_NAME_CHARSET_REGEX. Each forbidden_chars entry and env_name_charset_pattern itself are passed through sanitize_ts_string_literal (this crate’s TS-string-literal escaper) so they render as syntactically valid single-quoted TypeScript string literals regardless of what the Rust source contains — critique #471/#467 S2: without this, a future edit introducing a '/\ into the Rust pattern would either break the generated new RegExp('...') call or silently change what it matches.

Source§

impl Serialize for BridgeContext

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more