// Google Cloud Platform (Vertex AI) compat
ctx_http.register_gcp_compat();
+ // return 403 for disabled features
+ server_http_context::handler_t res_403 = [](const server_http_req &) {
+ auto res = std::make_unique<server_http_res>();
+ res->status = 403;
+ res->data = safe_json_to_str({
+ {"error", {
+ {"message", "this feature is disabled"},
+ {"type", "feature_disabled"},
+ }}
+ });
+ return res;
+ };
+
// CORS proxy (EXPERIMENTAL, only used by the Web UI for MCP)
if (params.ui_mcp_proxy) {
SRV_WRN("%s", "-----------------\n");
SRV_WRN("%s", "-----------------\n");
ctx_http.get ("/cors-proxy", ex_wrapper(proxy_handler_get));
ctx_http.post("/cors-proxy", ex_wrapper(proxy_handler_post));
+ } else {
+ ctx_http.get ("/cors-proxy", ex_wrapper(res_403));
+ ctx_http.post("/cors-proxy", ex_wrapper(res_403));
}
+
// EXPERIMENTAL built-in tools
if (!params.server_tools.empty()) {
try {
SRV_WRN("%s", "-----------------\n");
ctx_http.get ("/tools", ex_wrapper(tools.handle_get));
ctx_http.post("/tools", ex_wrapper(tools.handle_post));
+ } else {
+ ctx_http.get ("/tools", ex_wrapper(res_403));
+ ctx_http.post("/tools", ex_wrapper(res_403));
}
//
} catch (err) {
const errorMessage = err instanceof Error ? err.message : String(err);
this._error = errorMessage;
- // 404 from /tools means the server was started without --tools
- if (errorMessage.includes('404') || errorMessage.toLowerCase().includes('not found')) {
+ // 403 from /tools means the server was started without --tools
+ // TODO: check status code instead of relying on message
+ if (errorMessage.includes('this feature is disabled')) {
this._toolsEndpointUnreachable = true;
+ console.info('[ToolsStore] Built-in tools are disabled on the server');
+ } else {
+ console.error('[ToolsStore] Failed to fetch built-in tools:', err);
}
- console.error('[ToolsStore] Failed to fetch built-in tools:', err);
} finally {
this._loading = false;
}