Skip to content

Add MCP tool to delete a notification - #8683

Merged
andypalmi merged 4 commits into
mainfrom
feat/mcp-delete-notification
Oct 2, 2026
Merged

andypalmi merged 4 commits into
mainfrom
feat/mcp-delete-notification

Conversation

@cstns

@cstns cstns commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Closes #7704

Adds platform_delete_notification, which deletes one of the caller's own notifications.

It's marked destructive, so it's served as a delete tool and read-only tokens can't reach it. The route only ever looks at the caller's own notifications, so someone else's id just gets a 404.

There's no bulk delete route (the "delete all" one is commented out), so the tool takes one id per call and the description says so. It also points the agent at marking it read if the user only wants to dismiss it.

@cstns cstns self-assigned this Sep 29, 2026
@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.78%. Comparing base (e73a9b4) to head (12c4a20).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #8683   +/-   ##
=======================================
  Coverage   77.77%   77.78%           
=======================================
  Files         474      474           
  Lines       25530    25535    +5     
  Branches     6798     6799    +1     
=======================================
+ Hits        19857    19862    +5     
  Misses       5673     5673           
Flag Coverage Δ
backend 77.78% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

cstns added 2 commits October 1, 2026 15:01
The id went straight into the inject URL, which resolves dot segments,
so a notificationId like ../../applications/<id> deleted an
application. The handler now refuses anything that is not a hashid
before making the request.
@andypalmi
andypalmi enabled auto-merge (squash) October 2, 2026 09:06
@andypalmi
andypalmi merged commit 3dbfe63 into main Oct 2, 2026
28 checks passed
@andypalmi
andypalmi deleted the feat/mcp-delete-notification branch October 2, 2026 09:27

This branch was successfully deployed

1 active deployment
staging — 12c4a206 Deployed Oct 2, 2026 by andypalmi via Remove application #12084
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5.9-c Delete and destructive tools (phase 2)

2 participants