Repository navigation
[19.0][FIX] ai_tool: date output schema and tool model metadata access - #119
Closed
nobuQuartile wants to merge 2 commits into
Closed
nobuQuartile wants to merge 2 commits into
nobuQuartile wants to merge 2 commits into
Conversation
The JSON Schema spec does not define 'date' as a valid type. Use 'string' with format 'date' instead, which is the correct way to represent a date in JSON Schema. (cherry picked from commit 3efa79a)
Building and dispatching a tool reads ir.model via model_id, which a plain internal user (base.group_user) cannot access. Resolve the model name with sudo() while keeping the actual tool execution under the caller's own permissions, so non-admin MCP keys can list and call tools. Add a regression test exercising a non-admin user through _get_tool_definition and _execute_tool. (cherry picked from commit 16beaa7)
|
The following commit authors need to sign the Contributor License Agreement: |
nobuQuartile
marked this pull request as draft
October 1, 2026 23:59
dreispt
added a commit
to dreispt/ai
that referenced
this pull request
Oct 7, 2026
Port ai_oca_mcp to 19.0, based on the 17.0 migration in OCA#85 and the 18.0 migration in OCA#76. - Replace _sql_constraints with models.Constraint. - Declare the MCP endpoint readonly=False: auth="none" routes default to a read-only cursor in 19.0 and this endpoint always writes (log records, key expiry). - res.users groups_id renamed to group_ids in tests. - Replace per-method ormcache clear_cache() with env.registry.clear_cache() in tests. - Restore the security/security.xml manifest entry lost while rebasing the 17.0 migration over the 16.0 fix commit. - Non-admin key usage additionally requires the ai_tool fix in OCA#119 (ir.model is no longer readable by internal users), cherry-picked in the previous commits. Assisted-by: Devin:SWE-2 High
dreispt
added a commit
to dreispt/ai
that referenced
this pull request
Oct 7, 2026
Port ai_oca_mcp to 19.0, based on the 17.0 migration in OCA#85 and the 18.0 migration in OCA#76. - Replace _sql_constraints with models.Constraint. - Declare the MCP endpoint readonly=False: auth="none" routes default to a read-only cursor in 19.0 and this endpoint always writes (log records, key expiry). - res.users groups_id renamed to group_ids in tests. - Replace per-method ormcache clear_cache() with env.registry.clear_cache() in tests. - Restore the security/security.xml manifest entry lost while rebasing the 17.0 migration over the 16.0 fix commit. - Non-admin key usage additionally requires the ai_tool fixes in the preceding commits: the ir.model metadata lookup cherry-picked from OCA#119, and an equivalent output-schema fix for _ai_get_date. Assisted-by: Devin:SWE-2 High
Member
|
Thanks! We've picked this up in #125, which supersedes this PR — your For the record, two issues prevented merging this as-is:
|
Author
|
@dreispt |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Forward-port of #89 and #94 to 19.0.
Fixes
_ai_get_date output schema (#89):
_ai_get_datedeclared{"type": "date"}, which is not a valid JSON Schema type. It now declares{"type": "string", "format": "date"}.Tool model metadata for non-admin users (#94):
_get_tool_definitionand_execute_toolreadmodel_id.model(ir.model), which a plain internal user cannot read, so building or running a tool raisedAccessError. The model name is now resolved withsudo(). The tool itself still runs with the caller's rights.The regression test uses
group_idsinstead ofgroups_id(renamed in 19.0).Tests
Added
test_tool_non_admin_user: a user who has onlybase.group_usercan build the tool definition and execute a generic tool.@qrtl