mcp connection
Some checks failed
CI / fixture (push) Has been cancelled
CI / test (push) Has been cancelled

This commit is contained in:
2026-09-22 10:58:02 +05:30
parent 4e1f746b22
commit f2aa3b3ad8
53 changed files with 12515 additions and 37 deletions

View File

@@ -37,6 +37,7 @@ import (
"github.com/krow/krow-backend/go-api/internal/db"
"github.com/krow/krow-backend/go-api/internal/definition"
"github.com/krow/krow-backend/go-api/internal/knowledge"
"github.com/krow/krow-backend/go-api/internal/ratelimit"
"github.com/krow/krow-backend/go-api/internal/runtime"
"github.com/krow/krow-backend/go-api/internal/service"
"github.com/krow/krow-backend/go-api/internal/tools"
@@ -83,7 +84,18 @@ type Server struct {
users auth.UserStore
credentials *auth.Credentials
loginByEmail *attemptLimiter
loginByAddr *attemptLimiter
// limiter bounds the OAuth and MCP routes, shared across instances via
// Postgres. Nil when those routes are not registered — see mcplimit.go,
// where a nil limiter means the middleware is not installed at all rather
// than installed and permissive.
limiter *ratelimit.Limiter
loginByAddr *attemptLimiter
// trust resolves a request to the address its per-address limits are keyed
// by, reading a forwarded address only from a configured proxy. Wired once
// here so no handler can be given a different notion of who called.
trust proxyTrust
// now is injectable so tests can drive expiry without sleeping.
now func() time.Time
@@ -223,6 +235,7 @@ func New(cfg *config.Config, database *db.DB, log *slog.Logger, opts ...Option)
credentials: auth.NewCredentials(users),
loginByEmail: newAttemptLimiter(o.perEmail, o.loginWindow, o.now),
loginByAddr: newAttemptLimiter(o.perAddress, o.loginWindow, o.now),
trust: newProxyTrust(cfg.HTTP.TrustedProxies),
now: o.now,
}
@@ -277,11 +290,23 @@ func New(cfg *config.Config, database *db.DB, log *slog.Logger, opts ...Option)
}
s.definitions = s.definitions.WithCuratedAgents(curated)
// The shared limiter, built only when the routes that use it exist. The
// existing in-process login limiter is untouched: it guards a different
// thing (failed password attempts) with a different model (count failures,
// reset on success), and replacing it is not this change's business.
if cfg.OAuth.Enabled() {
s.limiter = ratelimit.New(database.Pool)
}
mux := http.NewServeMux()
mux.HandleFunc("GET /health", s.handleHealth)
s.endpoints = s.routeAuth(mux) + s.routeResources(mux) + s.routeMe(mux) +
s.routeDefinitions(mux) + s.routeWorkflows(mux) + s.routeOwliver(mux) +
s.routeRuns(mux) + s.routeVersion(mux) + s.routeTools(mux)
s.routeRuns(mux) + s.routeVersion(mux) + s.routeTools(mux) +
// The MCP surface and the OAuth server behind it. Both return 0 and
// register nothing when OAUTH_ISSUER and MCP_RESOURCE are unset, which
// is every deployment that has not asked for them.
s.routeOAuth(mux) + s.routeMCP(mux)
handler := jsonErrors(mux)
// Authentication sits where devOrgMiddleware used to, so every route below