Add independent MCP PDF report delivery

This commit is contained in:
2026-09-27 11:09:13 +02:00
parent 0c18c86a47
commit 6c36d78063
9 changed files with 555 additions and 20 deletions
+12
View File
@@ -180,6 +180,18 @@ The browser and PDF endpoints both submit a `CalculationRequest`. The PDF endpoi
`POST /api/reports/roll-calculation.pdf` is protected by the existing HTTP Basic Auth. Incomplete, conflicting, or invalid calculation requests return HTTP 400 rather than a document. Generated filenames include date and time without colon characters.
The MCP server exposes `generate_calculation_pdf` for an explicit user request
only. It accepts original direct-roll inputs, recalculates with `calculate_roll()`,
and passes the authoritative result through the same report adapter and renderer
as Flask. It cannot accept calculated values or a file path. With FastMCP
Streamable HTTP, the MCP host stores the PDF locally under a 256-bit opaque
capability token and serves it itself from `/reports/<token>.pdf`; Flask is not
in that delivery path. `ROLLCALC_MCP_ARTIFACT_PUBLIC_BASE_URL` configures the
browser-reachable MCP-host origin used in the returned `download_url`. Reports
expire after 24 hours during store access and are lost with MCP-host temporary
storage. Native MCP resources are intentionally omitted because installed MCPO
0.0.20 does not preserve resource links or embedded resources.
`pdf_report.py` uses no third-party package. It creates one A4 page with a compact header, result cards, two-column input area, warnings/notes, and footer. Repeated diagonal `INTERNAL USE ONLY` text is drawn into the actual page content stream with reduced opacity; it is a marking/deterrence mechanism and is not tamper-proof or DRM.
Direct-flow warnings are returned by the domain core and rendered by both consumers. `checkForklift()` remains only for the existing non-headless length/target UI modes. Build metadata and generation time are supplied server-side.