fix(mcp): fix two failing unit tests for RBAC tool visibility
- Restore "Available tools:" section header in app.py instructions so test_get_default_instructions_declares_data_boundary can find it - Revert fail-open change in _tool_allowed_for_current_user: tool-search should stay fail-closed (hide protected tools) when no user is resolved; only RBACToolVisibilityMiddleware.on_list_tools is fail-open for the no-auth-configured case Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
A
Amin Ghadersohi committed
07b96d669ab3be4a05c080a200317aba229946e9
Parent: 83a5a59