The editor asks every retriever-backed field whether its list is open,
and whether the field is required, on endpoints suffixed onto the
field's own URL. Only the unsecured retriever had them, so opening an
MCP agent's shared session picker asked /secure-retriever/.../open and
got a NoResourceFoundException stack in the log. The editor swallowed
the failure and fell back to a closed list, which is why nothing looked
wrong.
Both questions now exist on the secure side too, defaulting the same
way, so the answer comes from the retriever rather than from a 404.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>