mcp connection
This commit is contained in:
@@ -37,6 +37,7 @@ import (
|
||||
"github.com/krow/krow-backend/go-api/internal/db"
|
||||
"github.com/krow/krow-backend/go-api/internal/definition"
|
||||
"github.com/krow/krow-backend/go-api/internal/knowledge"
|
||||
"github.com/krow/krow-backend/go-api/internal/ratelimit"
|
||||
"github.com/krow/krow-backend/go-api/internal/runtime"
|
||||
"github.com/krow/krow-backend/go-api/internal/service"
|
||||
"github.com/krow/krow-backend/go-api/internal/tools"
|
||||
@@ -83,7 +84,18 @@ type Server struct {
|
||||
users auth.UserStore
|
||||
credentials *auth.Credentials
|
||||
loginByEmail *attemptLimiter
|
||||
loginByAddr *attemptLimiter
|
||||
|
||||
// limiter bounds the OAuth and MCP routes, shared across instances via
|
||||
// Postgres. Nil when those routes are not registered — see mcplimit.go,
|
||||
// where a nil limiter means the middleware is not installed at all rather
|
||||
// than installed and permissive.
|
||||
limiter *ratelimit.Limiter
|
||||
loginByAddr *attemptLimiter
|
||||
|
||||
// trust resolves a request to the address its per-address limits are keyed
|
||||
// by, reading a forwarded address only from a configured proxy. Wired once
|
||||
// here so no handler can be given a different notion of who called.
|
||||
trust proxyTrust
|
||||
|
||||
// now is injectable so tests can drive expiry without sleeping.
|
||||
now func() time.Time
|
||||
@@ -223,6 +235,7 @@ func New(cfg *config.Config, database *db.DB, log *slog.Logger, opts ...Option)
|
||||
credentials: auth.NewCredentials(users),
|
||||
loginByEmail: newAttemptLimiter(o.perEmail, o.loginWindow, o.now),
|
||||
loginByAddr: newAttemptLimiter(o.perAddress, o.loginWindow, o.now),
|
||||
trust: newProxyTrust(cfg.HTTP.TrustedProxies),
|
||||
now: o.now,
|
||||
}
|
||||
|
||||
@@ -277,11 +290,23 @@ func New(cfg *config.Config, database *db.DB, log *slog.Logger, opts ...Option)
|
||||
}
|
||||
s.definitions = s.definitions.WithCuratedAgents(curated)
|
||||
|
||||
// The shared limiter, built only when the routes that use it exist. The
|
||||
// existing in-process login limiter is untouched: it guards a different
|
||||
// thing (failed password attempts) with a different model (count failures,
|
||||
// reset on success), and replacing it is not this change's business.
|
||||
if cfg.OAuth.Enabled() {
|
||||
s.limiter = ratelimit.New(database.Pool)
|
||||
}
|
||||
|
||||
mux := http.NewServeMux()
|
||||
mux.HandleFunc("GET /health", s.handleHealth)
|
||||
s.endpoints = s.routeAuth(mux) + s.routeResources(mux) + s.routeMe(mux) +
|
||||
s.routeDefinitions(mux) + s.routeWorkflows(mux) + s.routeOwliver(mux) +
|
||||
s.routeRuns(mux) + s.routeVersion(mux) + s.routeTools(mux)
|
||||
s.routeRuns(mux) + s.routeVersion(mux) + s.routeTools(mux) +
|
||||
// The MCP surface and the OAuth server behind it. Both return 0 and
|
||||
// register nothing when OAUTH_ISSUER and MCP_RESOURCE are unset, which
|
||||
// is every deployment that has not asked for them.
|
||||
s.routeOAuth(mux) + s.routeMCP(mux)
|
||||
|
||||
handler := jsonErrors(mux)
|
||||
// Authentication sits where devOrgMiddleware used to, so every route below
|
||||
|
||||
Reference in New Issue
Block a user