Repository navigation
Agent Composer v1.3.0 – Structure Contracts and protected MCP access
SmartCloud Agent Composer 1.3.0
This release adds protected MCP access, human-controlled publication, semantic Structure Contracts, and deterministic content migrations.
Protected MCP access
- Added optional Cognito access-token validation with group roles, per-client ceilings, optional scopes, filtered discovery, and invocation enforcement.
- Added OAuth protected-resource discovery with PKCE S256, public-client authentication, authorization-code and refresh-token grants.
- Bound MCP access tokens and advertised scopes to the exact external MCP resource URI.
- Added principal-bound ownership and actor-aware audit context for accepted MCP requests and completed tool calls.
- Added token-free transport diagnostics without storing bearer values, request arguments, or tool results.
- Added a guided MCP Access administration screen with automatic Cognito provider discovery, manual overrides, and fail-closed status guidance.
Human publication
- Added Publisher-only, revision- and hash-bound publication requests.
- Added cross-principal, read-only handoff for human review.
- Added an inline MCP App with app-private human decision tools and a WordPress administration fallback.
- Kept publication and approval capabilities outside the agent-visible tool surface.
Structure Contracts and semantic editing
- Added independently versioned Structure Contracts with protected editor projections, managed baselines, typed override manifests, drift detection, and machine-readable violations.
- Added semantic document reads and field, media, section, and extension-slot operations using stable semantic IDs instead of serialized Gutenberg paths.
- Added native synced-pattern materialization with Pattern Overrides and validation of expanded structures.
- Added exact source and target baselines, deterministic migration operations, override-aware rebasing, zero-write previews, and plan-bound update proposals.
- Added bounded bulk migration planning and compatibility reports, with idempotent proposal creation for explicitly reviewed items.
- Added a governed extension-slot block for controlled layout customization.
Administration and compatibility
- Added clearer separation between human migration guidance and executable migration policy.
- Improved loading and pending states while preserving refreshed content in place.
- Distinguished registry patterns from synced structural
wp_blockrecords. - Fixed Site Contract list handling so explicit lists replace defaults without retaining removed numeric entries.
Upgrade notes
- Install MCP Adapter 0.6.1 or newer.
- Validate and explicitly activate a Structure Contract Config Set, then synchronize its local patterns.
- Restart the MCP runtime and refresh the client tool and resource catalogue.
- Existing content is not migrated automatically; review migration previews before creating update proposals.
- MCP protection remains Open after upgrading. Before enabling Protected Required, configure a Cognito Hosted UI domain and a public authorization-code plus PKCE client with the exact callback URI.
- Configure the exact external MCP resource URI, group mappings, and client ceilings, migrate external tunnels from STDIO to HTTP where required, and complete a test OAuth round trip.
- Enable scope enforcement only after Cognito uses the same MCP resource URI as its resource-server identifier and the required App Client scopes are assigned.