Skip to content

Agent Composer v1.3.0 – Structure Contracts and protected MCP access

Choose a tag to compare

@scsinfo scsinfo released this 20 Sep 14:34
· 11 commits to main since this release

SmartCloud Agent Composer 1.3.0

This release adds protected MCP access, human-controlled publication, semantic Structure Contracts, and deterministic content migrations.

Protected MCP access

  • Added optional Cognito access-token validation with group roles, per-client ceilings, optional scopes, filtered discovery, and invocation enforcement.
  • Added OAuth protected-resource discovery with PKCE S256, public-client authentication, authorization-code and refresh-token grants.
  • Bound MCP access tokens and advertised scopes to the exact external MCP resource URI.
  • Added principal-bound ownership and actor-aware audit context for accepted MCP requests and completed tool calls.
  • Added token-free transport diagnostics without storing bearer values, request arguments, or tool results.
  • Added a guided MCP Access administration screen with automatic Cognito provider discovery, manual overrides, and fail-closed status guidance.

Human publication

  • Added Publisher-only, revision- and hash-bound publication requests.
  • Added cross-principal, read-only handoff for human review.
  • Added an inline MCP App with app-private human decision tools and a WordPress administration fallback.
  • Kept publication and approval capabilities outside the agent-visible tool surface.

Structure Contracts and semantic editing

  • Added independently versioned Structure Contracts with protected editor projections, managed baselines, typed override manifests, drift detection, and machine-readable violations.
  • Added semantic document reads and field, media, section, and extension-slot operations using stable semantic IDs instead of serialized Gutenberg paths.
  • Added native synced-pattern materialization with Pattern Overrides and validation of expanded structures.
  • Added exact source and target baselines, deterministic migration operations, override-aware rebasing, zero-write previews, and plan-bound update proposals.
  • Added bounded bulk migration planning and compatibility reports, with idempotent proposal creation for explicitly reviewed items.
  • Added a governed extension-slot block for controlled layout customization.

Administration and compatibility

  • Added clearer separation between human migration guidance and executable migration policy.
  • Improved loading and pending states while preserving refreshed content in place.
  • Distinguished registry patterns from synced structural wp_block records.
  • Fixed Site Contract list handling so explicit lists replace defaults without retaining removed numeric entries.

Upgrade notes

  1. Install MCP Adapter 0.6.1 or newer.
  2. Validate and explicitly activate a Structure Contract Config Set, then synchronize its local patterns.
  3. Restart the MCP runtime and refresh the client tool and resource catalogue.
  4. Existing content is not migrated automatically; review migration previews before creating update proposals.
  5. MCP protection remains Open after upgrading. Before enabling Protected Required, configure a Cognito Hosted UI domain and a public authorization-code plus PKCE client with the exact callback URI.
  6. Configure the exact external MCP resource URI, group mappings, and client ceilings, migrate external tunnels from STDIO to HTTP where required, and complete a test OAuth round trip.
  7. Enable scope enforcement only after Cognito uses the same MCP resource URI as its resource-server identifier and the required App Client scopes are assigned.