Initial schulcloud-mcp server
Read-only MCP server exposing a Schulcloud account to Claude: courses,
column boards, lessons, tasks, and file downloads with text extraction.
The API surface was verified against the live instance rather than
inferred from upstream source, which changed several design decisions:
- The `jwt` cookie works verbatim as `Authorization: Bearer` and lasts 30
days, so there is no cookie jar and no refresh-session timer.
- Course contents live at /api/v3/course-rooms/{courseId}/board; there is
no GET /api/v3/courses/{id}.
- Files are a separate service (/api/v3/file/*) with its own OpenAPI doc.
- Board file elements carry no file id; attachments are resolved by
listing files-storage with parentType=boardnodes and the element id.
Read-only by construction: every client method is a GET, including the
api_get escape hatch. The endpoint is internet-facing by necessity, so a
leaked token being unable to act as the user is the key safety property.
Deploys as a container behind the Pi's existing Caddy, guarded by a
constant-time bearer check. Stateless — no database.
Verified: 28 unit tests, plus a 30-check end-to-end run driving a real
MCP client over Streamable HTTP against the live account.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
38
src/context.ts
Normal file
38
src/context.ts
Normal file
@@ -0,0 +1,38 @@
|
||||
import type { Config } from './config.ts';
|
||||
import { SchulcloudClient } from './schulcloud/client.ts';
|
||||
import type { MeResponse } from './schulcloud/types.ts';
|
||||
|
||||
/**
|
||||
* Per-process state shared by every tool.
|
||||
*
|
||||
* The only thing worth holding onto is the identity from `/api/v3/me`: the
|
||||
* school id is a required path segment for every files-storage call, and it
|
||||
* cannot change for a given JWT. Everything else is fetched live.
|
||||
*/
|
||||
export class ServerContext {
|
||||
readonly client: SchulcloudClient;
|
||||
private identity: Promise<MeResponse> | undefined;
|
||||
|
||||
constructor(readonly config: Config) {
|
||||
this.client = new SchulcloudClient(config);
|
||||
}
|
||||
|
||||
/** Cached `/me`. Shared promise, so concurrent first calls make one request. */
|
||||
me(): Promise<MeResponse> {
|
||||
this.identity ??= this.client.me().catch((error: unknown) => {
|
||||
// Don't cache a failure — a replaced JWT should be able to recover.
|
||||
this.identity = undefined;
|
||||
throw error;
|
||||
});
|
||||
return this.identity;
|
||||
}
|
||||
|
||||
async schoolId(): Promise<string> {
|
||||
return (await this.me()).school.id;
|
||||
}
|
||||
|
||||
/** Drops the cached identity so the next call re-reads it. */
|
||||
reset(): void {
|
||||
this.identity = undefined;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user