Skip to content

feat(mcp): McpQueryService, read-only SQL core for MCP tools #1134

Description

@ZhuchkaTriplesix

Scope

A UI-free service in lib/core/mcp/ that the MCP tools call. It reuses the existing database services and does not duplicate execution logic.

  • listConnections(): id, name, type, environment, database of connections with MCP access enabled. No host, user, password, SSH data or connection strings.
  • listTables(conn, {schema}), describeTable(conn, table): columns, types, nullability, PK / FK, indexes (reuse postgres_metadata, TableSchemaMeta, MySQL / SQLite catalog queries).
  • sampleRows(conn, table, {n = 20}): quoted identifiers, never string-built SQL from model input.
  • runQuery(conn, sql), explainQuery(conn, sql).

Read-only guarantees

  • Exactly one statement; must be SELECT, WITH without data-modifying CTE, EXPLAIN (without ANALYZE on Postgres), SHOW, or PRAGMA from an allow-list on SQLite. Reuse isMutatingSqlStatement / DestructiveSqlDetector.
  • Read-only session at the database: Postgres PgSessionMode.readOnly, MySQL SET SESSION TRANSACTION READ ONLY on a dedicated pooled session, SQLite PRAGMA query_only=ON (or a read-only open).
  • Statement timeout (default 15 s) and row limit (default 1000, via sql_limit.dart); result says truncated: true.
  • Cells longer than 4 KB are cut with a marker; binary values as hex with a type tag.
  • SQL errors are returned as text (the model fixes the query), mapped by database_error_mapper.

Tests

  • Classifier table: allowed / refused statements, including comments, strings, WITH ... DELETE, multiple statements, EXPLAIN ANALYZE DELETE.
  • A refused statement never reaches the driver (fake delegate).
  • listConnections output never contains secrets (scan of JSON for password / host / connection string).

Part of #1133.

Activity

  1. added
    coreCore library logic and services
    backendBackend database driver execution and queries
    P2Medium priority / Parity & Refactoring
    on Oct 8, 2026
  2. ZhuchkaTriplesix commented on Oct 8, 2026

    @ZhuchkaTriplesix
    MemberAuthor

    Сделано в #1139 (смержен в dev).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium priority / Parity & RefactoringbackendBackend database driver execution and queriescoreCore library logic and services

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions