Repository object · task
Em 0013
Accepted task in the public catalog.
- Source path
tasks/contracts/EM-0013.json- Media type
application/json- Object ID
em:task:sha256:7404f6cf4efbb1135764bf20d68ddbb5d2d8f08f7c60155d063654204a09eef0- Content digest
6d28e792e3a6751acae834b9af991fe0de5a98a5caf260f43f118d5e8b120268
Also filed under
Source content
{
"$schema": "https://epistemedia.com/schemas/task-contract-v1.json",
"id": "EM-0013",
"title": "Harden the public API and modern MCP transport",
"status": "ready",
"change_class": "ordinary-implementation",
"objective": "Bring the read-only public gateway into explicit MCP 2026-07-28 Streamable HTTP conformance, expose complete public-projection identity on API responses, and define bounded request, rate, and timeout controls before external deployment.",
"depends_on": [
"EM-0008"
],
"authority": {
"allowed_paths": [
"src/**",
"tests/**",
"docs/**",
"ops/**",
"runs/**",
"Dockerfile",
"compose.yaml",
"pyproject.toml",
"server.json"
],
"forbidden_paths": [
"constitution/**",
"schemas/**",
"policies/**",
"catalog/**",
"governance/events/**",
"tasks/contracts/EM-0001.json",
"tasks/contracts/EM-0002.json",
"tasks/contracts/EM-0003.json",
"tasks/contracts/EM-0004.json",
"tasks/contracts/EM-0005.json",
"tasks/contracts/EM-0006.json",
"tasks/contracts/EM-0007.json",
"tasks/contracts/EM-0008.json",
"tasks/contracts/EM-0009.json",
"tasks/contracts/EM-0010.json",
"tasks/contracts/EM-0011.json",
"tasks/contracts/EM-0012.json"
]
},
"required_evaluation": [
"MCP 2026-07-28 request-metadata and Streamable HTTP conformance tests",
"adversarial Origin, header-mismatch, malformed-message, and oversized-body tests",
"API and MCP public-projection identity parity tests",
"deployment resource-limit review"
],
"acceptance": [
"the MCP endpoint implements the stateless POST shape of Streamable HTTP 2026-07-28 and rejects unsupported HTTP methods",
"Origin is validated before request-body processing",
"required Accept, Content-Type, MCP-Protocol-Version, Mcp-Method, and Mcp-Name metadata is validated against the JSON-RPC body with protocol-defined structured errors",
"server/discover, version mismatch, unknown method, invalid request, and notification responses follow the 2026-07-28 result and error contracts",
"public API envelopes expose commit, catalog, frontier, policy, compiler, and deterministic content-digest identity",
"anonymous request body, query, response, rate, and timeout limits are explicit and covered proportionally before deployment",
"the gateway performs no arbitrary network fetch and exposes no tool that writes accepted knowledge or governance",
"local stdio MCP remains available through the CLI",
"make check passes without changing accepted source state"
],
"limitations": [
"This task does not activate a hosted API or MCP endpoint and must not describe local conformance as production availability.",
"Provider-edge rate and timeout enforcement still requires deployment-specific read-back.",
"This task does not change the protected Epistemic Mesh identifier namespace governed by EM-0009."
]
}
Build receipt
Reproduce this projection
- Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d- Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf- Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9- Epistemic policy
commons-balanced-v0.1- Disclosure policy
public-noninterference-v0.1- Compiler
epistemedia/0.2.0