Skip to content

[19.0][FIX] ai_tool: date output schema and tool model metadata access - #119

Closed
nobuQuartile wants to merge 2 commits into
OCA:19.0from
qrtl:19.0-fix-ai_tool
Closed

nobuQuartile wants to merge 2 commits into
OCA:19.0from
qrtl:19.0-fix-ai_tool

Conversation

@nobuQuartile

@nobuQuartile nobuQuartile commented Oct 1, 2026 •

Copy link
Copy Markdown

Forward-port of #89 and #94 to 19.0.

Fixes

_ai_get_date output schema (#89): _ai_get_date declared {"type": "date"}, which is not a valid JSON Schema type. It now declares {"type": "string", "format": "date"}.

Tool model metadata for non-admin users (#94): _get_tool_definition and _execute_tool read model_id.model (ir.model), which a plain internal user cannot read, so building or running a tool raised AccessError. The model name is now resolved with sudo(). The tool itself still runs with the caller's rights.

The regression test uses group_ids instead of groups_id (renamed in 19.0).

Tests

Added test_tool_non_admin_user: a user who has only base.group_user can build the tool definition and execute a generic tool.

@qrtl

ZachDreamZ and others added 2 commits September 30, 2026 00:36
The JSON Schema spec does not define 'date' as a valid type.
Use 'string' with format 'date' instead, which is the correct
way to represent a date in JSON Schema.

(cherry picked from commit 3efa79a)
Building and dispatching a tool reads ir.model via model_id, which a
plain internal user (base.group_user) cannot access. Resolve the model
name with sudo() while keeping the actual tool execution under the
caller's own permissions, so non-admin MCP keys can list and call tools.

Add a regression test exercising a non-admin user through
_get_tool_definition and _execute_tool.

(cherry picked from commit 16beaa7)
@oca-cla-bot

oca-cla-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

The following commit authors need to sign the Contributor License Agreement:

CLA not signed

@nobuQuartile
nobuQuartile marked this pull request as draft October 1, 2026 23:59
dreispt added a commit to dreispt/ai that referenced this pull request Oct 7, 2026
Port ai_oca_mcp to 19.0, based on the 17.0 migration in OCA#85 and
the 18.0 migration in OCA#76.

- Replace _sql_constraints with models.Constraint.
- Declare the MCP endpoint readonly=False: auth="none" routes default
  to a read-only cursor in 19.0 and this endpoint always writes (log
  records, key expiry).
- res.users groups_id renamed to group_ids in tests.
- Replace per-method ormcache clear_cache() with
  env.registry.clear_cache() in tests.
- Restore the security/security.xml manifest entry lost while rebasing
  the 17.0 migration over the 16.0 fix commit.
- Non-admin key usage additionally requires the ai_tool fix in
  OCA#119 (ir.model is no longer readable by internal users),
  cherry-picked in the previous commits.

Assisted-by: Devin:SWE-2 High
dreispt added a commit to dreispt/ai that referenced this pull request Oct 7, 2026
Port ai_oca_mcp to 19.0, based on the 17.0 migration in OCA#85 and
the 18.0 migration in OCA#76.

- Replace _sql_constraints with models.Constraint.
- Declare the MCP endpoint readonly=False: auth="none" routes default
  to a read-only cursor in 19.0 and this endpoint always writes (log
  records, key expiry).
- res.users groups_id renamed to group_ids in tests.
- Replace per-method ormcache clear_cache() with
  env.registry.clear_cache() in tests.
- Restore the security/security.xml manifest entry lost while rebasing
  the 17.0 migration over the 16.0 fix commit.
- Non-admin key usage additionally requires the ai_tool fixes in the
  preceding commits: the ir.model metadata lookup cherry-picked from
  OCA#119, and an equivalent output-schema fix for _ai_get_date.

Assisted-by: Devin:SWE-2 High
@dreispt

dreispt commented Oct 7, 2026

Copy link
Copy Markdown
Member

Thanks! We've picked this up in #125, which supersedes this PR — your [FIX] commit is cherry-picked there preserving authorship.

For the record, two issues prevented merging this as-is:

@nobuQuartile

Copy link
Copy Markdown
Author

@dreispt
Thank you for your comment! Let's follow up on your PR!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants