{"record":{"id":"15c053fb703a8486","repo":"paperclipai/paperclip","slug":"path-must-start-with-and-be-relative-to-api-an","errorCode":null,"errorMessage":"path must start with / and be relative to /api, and must not contain '..'","messagePattern":"path must start with / and be relative to /api, and must not contain '\\.\\.'","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/mcp-server/src/tools.ts","lineNumber":626,"sourceCode":"        return client.requestJson(\"POST\", path, { body });\n      },\n    ),\n    makeTool(\n      \"paperclipAddApprovalComment\",\n      \"Add a comment to an approval\",\n      z.object({ approvalId: approvalIdSchema, body: z.string().min(1) }),\n      async ({ approvalId, body }) =>\n        client.requestJson(\"POST\", `/approvals/${encodeURIComponent(approvalId)}/comments`, {\n          body: { body },\n        }),\n    ),\n    makeTool(\n      \"paperclipApiRequest\",\n      \"Make a JSON request to an existing Paperclip /api endpoint for unsupported operations\",\n      apiRequestSchema,\n      async ({ method, path, jsonBody }) => {\n        if (!path.startsWith(\"/\") || path.includes(\"..\")) {\n          throw new Error(\"path must start with / and be relative to /api, and must not contain '..'\");\n        }\n        return client.requestJson(method, path, {\n          body: parseOptionalJson(jsonBody),\n        });\n      },\n    ),\n  ];\n}\n","sourceCodeStart":608,"sourceCodeEnd":635,"githubUrl":"https://github.com/paperclipai/paperclip/blob/a7e689b3c35347b529cb9f54c9b9a8575a3dcab6/packages/mcp-server/src/tools.ts#L608-L635","documentation":"Path validation inside the paperclipApiRequest escape-hatch tool: the caller-supplied API path failed one of the structural rules (must begin with '/', is joined onto /api, and must not contain '..'). This is a generic request-shape guard preventing path traversal outside the /api namespace before client.requestJson is invoked.","triggerScenarios":"Thrown at packages/mcp-server/src/tools.ts:626 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Pass a path starting with / that stays under /api and contains no '..' segments."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"a7e689b3c35347b529cb9f54c9b9a8575a3dcab6","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}