import { GraphCatalogService } from "../../agents/graph/services/graph.catalog.service"; import { EntityServiceRegistry } from "../../common/registries/entity.service.registry"; import { BlockNoteService } from "../../core/blocknote/services/blocknote.service"; import { RbacPermissionService } from "../../foundations/rbac/services/rbac-permission.service"; import type { McpToolDefinition, McpToolResult, McpUserContext } from "../interfaces/mcp.tool.interface"; /** * MCP write executors (C4): create/update entities and add/remove to-many * relationship items for any JSON:API type registered in EntityServiceRegistry. * * Every write is gated by the catalog (type visible to the user's modules) and * RBAC (`create`/`update` permission on the entity's module), dispatched through * the framework's `AbstractService.*FromDTO` path (never hand-built JSON:API * beyond the `JsonApiDTOData` framework type). Audit is NOT performed here: * `AbstractService.create/put` audits internally when the concrete entity * service injects AuditService, so MCP writes audit exactly like HTTP writes. */ export declare class McpEntityWriteService { private readonly registry; private readonly catalog; private readonly rbac; /** * Optional in the TYPE signature only, so unit tests can construct the three * collaborators they exercise. Nest has no notion of `?` and still resolves * it from BlockNoteModule (imported by McpModule) — a missing provider fails * loudly at boot rather than silently storing markdown in a rich-text field. */ private readonly blockNote?; constructor(registry: EntityServiceRegistry, catalog: GraphCatalogService, rbac: RbacPermissionService, /** * Optional in the TYPE signature only, so unit tests can construct the three * collaborators they exercise. Nest has no notion of `?` and still resolves * it from BlockNoteModule (imported by McpModule) — a missing provider fails * loudly at boot rather than silently storing markdown in a rich-text field. */ blockNote?: BlockNoteService); /** * The four write McpToolDefinitions (all `readOnly: false`) with hand-written * JSON Schemas matching the C4 method params. Consumed by McpGenericToolsService. */ buildTools(_ctx: McpUserContext): McpToolDefinition[]; /** Create a new entity of the given type. RBAC action: `create`. */ createEntity(params: { type: string; attributes: Record; relationships?: Record; }>; }, ctx: McpUserContext): Promise; /** * Update an existing entity. RBAC action: `update`. * * PATCH semantics via `patchFromDTO` — only the provided attributes change. * Deliberately NOT `putFromDTO`: the framework's PUT maps every descriptor * relationship and treats the ones absent from the DTO as "delete all * edges". The HTTP path is safe because the frontend model always sends the * complete relationship set on PUT, but an MCP caller sends attributes only — * a PUT here would silently strip every mutable relationship off the record. */ updateEntity(params: { type: string; id: string; attributes: Record; }, ctx: McpUserContext): Promise; /** Add items to a to-many relationship. RBAC action: `update`. */ addRelationship(params: { type: string; id: string; relationship: string; relatedType: string; relatedIds: string[]; }, ctx: McpUserContext): Promise; /** Remove items from a to-many relationship. RBAC action: `update`. */ removeRelationship(params: { type: string; id: string; relationship: string; relatedType: string; relatedIds: string[]; }, ctx: McpUserContext): Promise; /** * Shared gate: catalog visibility (unknown_type), RBAC (forbidden), and * service registration (unknown_type). */ private gate; /** * Rejects attribute keys that are not in the entity's catalog field list. * Catalog fields are a CatalogField[] array — keys are the `name` property. */ private unknownAttributes; } //# sourceMappingURL=mcp.entity.write.service.d.ts.map