Repository object · task

Em 0013

Accepted task in the public catalog.

Source path
tasks/contracts/EM-0013.json
Media type
application/json
Object ID
em:task:sha256:7404f6cf4efbb1135764bf20d68ddbb5d2d8f08f7c60155d063654204a09eef0
Content digest
6d28e792e3a6751acae834b9af991fe0de5a98a5caf260f43f118d5e8b120268

Source content

{

"$schema": "https://epistemedia.com/schemas/task-contract-v1.json",

"id": "EM-0013",

"title": "Harden the public API and modern MCP transport",

"status": "ready",

"change_class": "ordinary-implementation",

"objective": "Bring the read-only public gateway into explicit MCP 2026-07-28 Streamable HTTP conformance, expose complete public-projection identity on API responses, and define bounded request, rate, and timeout controls before external deployment.",

"depends_on": [

"EM-0008"

],

"authority": {

"allowed_paths": [

"src/**",

"tests/**",

"docs/**",

"ops/**",

"runs/**",

"Dockerfile",

"compose.yaml",

"pyproject.toml",

"server.json"

],

"forbidden_paths": [

"constitution/**",

"schemas/**",

"policies/**",

"catalog/**",

"governance/events/**",

"tasks/contracts/EM-0001.json",

"tasks/contracts/EM-0002.json",

"tasks/contracts/EM-0003.json",

"tasks/contracts/EM-0004.json",

"tasks/contracts/EM-0005.json",

"tasks/contracts/EM-0006.json",

"tasks/contracts/EM-0007.json",

"tasks/contracts/EM-0008.json",

"tasks/contracts/EM-0009.json",

"tasks/contracts/EM-0010.json",

"tasks/contracts/EM-0011.json",

"tasks/contracts/EM-0012.json"

]

},

"required_evaluation": [

"MCP 2026-07-28 request-metadata and Streamable HTTP conformance tests",

"adversarial Origin, header-mismatch, malformed-message, and oversized-body tests",

"API and MCP public-projection identity parity tests",

"deployment resource-limit review"

],

"acceptance": [

"the MCP endpoint implements the stateless POST shape of Streamable HTTP 2026-07-28 and rejects unsupported HTTP methods",

"Origin is validated before request-body processing",

"required Accept, Content-Type, MCP-Protocol-Version, Mcp-Method, and Mcp-Name metadata is validated against the JSON-RPC body with protocol-defined structured errors",

"server/discover, version mismatch, unknown method, invalid request, and notification responses follow the 2026-07-28 result and error contracts",

"public API envelopes expose commit, catalog, frontier, policy, compiler, and deterministic content-digest identity",

"anonymous request body, query, response, rate, and timeout limits are explicit and covered proportionally before deployment",

"the gateway performs no arbitrary network fetch and exposes no tool that writes accepted knowledge or governance",

"local stdio MCP remains available through the CLI",

"make check passes without changing accepted source state"

],

"limitations": [

"This task does not activate a hosted API or MCP endpoint and must not describe local conformance as production availability.",

"Provider-edge rate and timeout enforcement still requires deployment-specific read-back.",

"This task does not change the protected Epistemic Mesh identifier namespace governed by EM-0009."

]

}

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0