Compare commits

39 Commits

Author SHA1 Message Date
bsodfather 63f8ee333f наблюдаемость: измерять бюджет каталога MCP
CI / Rust Checks (push) Successful in 12m5s
CI / UI Checks (push) Successful in 9s
CI / Deployment Manifests (push) Successful in 6s
CI / Frontend E2E (push) Failing after 30s
CI / Deploy (push) Has been skipped
2026-07-21 01:59:09 +03:00
bsodfather 0241d186ea Выровнять шкалу шагов мастера
CI / Rust Checks (push) Successful in 6m17s
CI / UI Checks (push) Successful in 8s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m21s
CI / Deploy (push) Successful in 2m42s
2026-07-12 13:26:13 +03:00
bsodfather 46892ee61c Усилить безопасность веб-интерфейса
CI / Rust Checks (push) Successful in 5m14s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Successful in 2m58s
CI / Deploy (push) Successful in 1m44s
2026-07-11 17:12:50 +03:00
bsodfather 8318e4b560 Усилить безопасность и надёжность выполнения операций
CI / Rust Checks (push) Successful in 5m7s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m9s
CI / Deploy (push) Successful in 1m41s
2026-07-11 14:08:07 +03:00
bsodfather 626f2845e2 Усилить проверку источника и ограничение запросов
CI / Rust Checks (push) Successful in 5m7s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m5s
CI / Deploy (push) Successful in 1m37s
2026-07-11 10:54:17 +03:00
bsodfather 502e339809 Адаптировать wizard под мобильный экран
CI / Rust Checks (push) Successful in 6m25s
CI / UI Checks (push) Successful in 8s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m29s
CI / Deploy (push) Successful in 2m44s
2026-07-10 01:05:12 +03:00
bsodfather dca97bd69b Включать мобильное меню раньше
CI / Rust Checks (push) Successful in 5m26s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Successful in 3m7s
CI / Deploy (push) Successful in 2m58s
2026-07-09 00:43:30 +03:00
Codex 061873058e ci: install rust toolchain from project config
CI / Rust Checks (push) Successful in 6m43s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m49s
CI / Deploy (push) Successful in 3m11s
2026-07-06 20:09:26 +00:00
bsodfather c98c7c8ce2 Merge pull request 'Обновил зависимости проекта' (#1) from chore/update-dependencies into main
CI / Rust Checks (push) Successful in 5m10s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m6s
CI / Deploy (push) Successful in 31s
Reviewed-on: #1
2026-07-06 19:49:54 +00:00
bsodfather fd8571ad10 Обновить зависимости проекта
CI / Rust Checks (pull_request) Failing after 3s
CI / UI Checks (pull_request) Has been skipped
CI / Frontend E2E (pull_request) Has been skipped
CI / Deployment Manifests (pull_request) Has been skipped
CI / Deploy (pull_request) Has been skipped
2026-07-06 22:47:24 +03:00
github-ops c7e5efa976 Polish Russian approval copy
CI / Rust Checks (push) Successful in 5m39s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m22s
CI / Deploy (push) Successful in 1m30s
2026-06-27 09:00:02 +00:00
github-ops 4da13c0811 Explain approval payload preview
CI / Rust Checks (push) Successful in 5m37s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m29s
CI / Deploy (push) Successful in 1m36s
2026-06-27 08:50:10 +00:00
github-ops 4cad7f1c46 Simplify approval payload settings
CI / Rust Checks (push) Successful in 5m38s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Successful in 3m27s
CI / Deploy (push) Successful in 1m30s
2026-06-27 08:33:16 +00:00
github-ops 700a684257 Add approval mode selection
CI / Rust Checks (push) Successful in 5m35s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Successful in 3m28s
CI / Deploy (push) Successful in 1m38s
2026-06-27 07:55:38 +00:00
github-ops 2b2ff92146 Remove approval confirmation copy
CI / Rust Checks (push) Successful in 5m32s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m24s
CI / Deploy (push) Successful in 1m33s
2026-06-27 07:12:04 +00:00
github-ops d34c8a73d6 Fix API keys header layout
CI / Rust Checks (push) Successful in 5m34s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m22s
CI / Deploy (push) Successful in 1m31s
2026-06-25 06:40:53 +00:00
github-ops 9ba2aa3f38 Clarify request mapping UI
CI / Rust Checks (push) Successful in 5m37s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m28s
CI / Deploy (push) Successful in 1m31s
2026-06-25 04:59:12 +00:00
github-ops 209b3e1485 Polish approval and import UI
CI / Rust Checks (push) Successful in 5m32s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 3m30s
CI / Deploy (push) Successful in 1m33s
2026-06-24 21:51:13 +00:00
github-ops 3b51cb89df Fix OpenAPI import modal background
CI / Rust Checks (push) Successful in 5m33s
CI / UI Checks (push) Successful in 4s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Successful in 3m29s
CI / Deploy (push) Successful in 1m28s
2026-06-24 21:12:46 +00:00
github-ops 861502aabc Use preinstalled Rust binaries in CI
CI / Rust Checks (push) Successful in 5m38s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Successful in 4m13s
CI / Deploy (push) Successful in 1m35s
2026-06-24 17:04:29 +00:00
github-ops 327bea6f33 Fail fast when runner Rust toolchain is missing
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 16:51:00 +00:00
github-ops 87d9ba2299 Prepare Rust toolchain explicitly in CI
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 16:26:21 +00:00
github-ops de1bcc5cae Restore Gitea runner label
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 15:44:24 +00:00
github-ops 2f6e1d5e51 Use rust stable runner for Gitea workflows
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 15:40:04 +00:00
github-ops 0d828257c0 Split MCP approval integration tests
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 15:36:28 +00:00
github-ops 8b8f2fc6c5 Expose approval requests in admin logs
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 13:51:54 +00:00
github-ops 7aad3b1228 Expire stale approval requests
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
CI / Rust Checks (push) Has been cancelled
2026-06-24 13:27:00 +00:00
github-ops 8ce00ede31 Make approval decisions idempotent
CI / Rust Checks (push) Has been cancelled
CI / UI Checks (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
2026-06-24 13:23:04 +00:00
github-ops 267061e226 Execute approved tool calls
CI / Rust Checks (push) Successful in 1h31m49s
CI / UI Checks (push) Successful in 5s
CI / Frontend E2E (push) Has been cancelled
CI / Deployment Manifests (push) Has been cancelled
CI / Deploy (push) Has been cancelled
2026-06-24 12:49:57 +00:00
github-ops 78d3052a61 Document human approval flow
CI / Rust Checks (push) Successful in 1h25m31s
CI / UI Checks (push) Successful in 6s
CI / Deployment Manifests (push) Successful in 2s
CI / Deploy (push) Has been cancelled
CI / Frontend E2E (push) Has been cancelled
2026-06-24 11:43:34 +00:00
github-ops 0d193b84dd Gate MCP tool calls on human approval 2026-06-24 11:42:16 +00:00
github-ops 8a1cc1746f Add approval request HTTP surface 2026-06-24 11:39:39 +00:00
github-ops d83ab541d9 Add operation approval policy editor 2026-06-24 10:45:09 +00:00
github-ops 5922aea68f Split MCP and approval agent keys 2026-06-24 10:31:52 +00:00
github-ops d739f17393 Polish OpenAPI import modal
CI / Rust Checks (push) Successful in 5m49s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Successful in 4m23s
CI / Deploy (push) Successful in 1m29s
2026-06-24 07:18:02 +00:00
github-ops dbb75871ae Remove manual deploy workflow
CI / Rust Checks (push) Successful in 6m11s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Failing after 13m37s
CI / Deploy (push) Has been skipped
2026-06-24 06:41:10 +00:00
github-ops 50ae60952a Gate deploy on successful CI
CI / Rust Checks (push) Successful in 6m7s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 3s
CI / Frontend E2E (push) Failing after 6m47s
CI / Deploy (push) Has been skipped
2026-06-24 06:33:16 +00:00
github-ops 5fb3d37329 Keep startup demo cleanup non-fatal
Deploy / deploy (push) Successful in 1m38s
CI / Rust Checks (push) Successful in 6m36s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Failing after 13m30s
2026-06-24 06:24:29 +00:00
github-ops 6d36b5e262 Fix community OpenAPI import docs scope
Deploy / deploy (push) Failing after 1m57s
CI / Rust Checks (push) Successful in 6m20s
CI / UI Checks (push) Successful in 5s
CI / Deployment Manifests (push) Successful in 2s
CI / Frontend E2E (push) Failing after 13m43s
2026-06-24 06:20:42 +00:00
130 changed files with 7090 additions and 1703 deletions
+8
View File
@@ -24,11 +24,19 @@ CRANK_RUNTIME_MAX_CONCURRENT_UNARY=64
CRANK_RUNTIME_MAX_CONCURRENT_WINDOW=16
CRANK_RUNTIME_MAX_CONCURRENT_SESSIONS=16
CRANK_RUNTIME_MAX_CONCURRENT_JOBS=16
# Публичные узлы разрешены по умолчанию. Для внутренних API перечислите
# допустимые имена или IP через запятую.
CRANK_OUTBOUND_ALLOWED_HOSTS=
CRANK_OUTBOUND_DENIED_HOSTS=
CRANK_OUTBOUND_MAX_RESPONSE_BYTES=4194304
CRANK_LOG_LEVEL=info
CRANK_MASTER_KEY=change-me-master-key
CRANK_SESSION_SECRET=change-me-session-secret
CRANK_PASSWORD_PEPPER=change-me-password-pepper
CRANK_SESSION_TTL_HOURS=24
# Trust X-Real-IP / X-Forwarded-For for client rate limiting. Enable only when
# admin-api runs behind the bundled nginx (or another trusted reverse proxy).
CRANK_TRUST_FORWARDED_HEADERS=true
CRANK_BOOTSTRAP_ADMIN_EMAIL=owner@crank.local
CRANK_BOOTSTRAP_ADMIN_PASSWORD=change-me-admin-password
CRANK_BOOTSTRAP_ADMIN_DISPLAY_NAME=Crank Owner
+284
View File
@@ -22,6 +22,29 @@ jobs:
- name: Checkout
uses: actions/checkout@v5
- name: Install Rust toolchain
run: |
set -eu
toolchain="$(sed -n 's/^channel = "\(.*\)"/\1/p' rust-toolchain.toml | head -n1)"
if [ -z "$toolchain" ]; then
echo "Unable to read Rust toolchain channel from rust-toolchain.toml" >&2
exit 1
fi
rustup toolchain install "$toolchain" --profile minimal --component clippy --component rustfmt
rustup default "$toolchain"
host="$(rustc -vV | sed -n 's/^host: //p')"
toolchain_dir="${RUSTUP_HOME:-$HOME/.rustup}/toolchains/${toolchain}-${host}"
toolchain_bin="$toolchain_dir/bin"
if [ ! -x "$toolchain_bin/rustc" ] || [ ! -x "$toolchain_bin/cargo" ]; then
echo "Rust $toolchain was not installed at $toolchain_dir." >&2
exit 1
fi
printf '%s\n' "$toolchain_bin" >> "$GITHUB_PATH"
"$toolchain_bin/rustc" --version
"$toolchain_bin/cargo" --version
"$toolchain_bin/rustfmt" --version
"$toolchain_bin/cargo-clippy" --version
- name: Verify runner toolchain
run: |
python3 --version
@@ -104,6 +127,29 @@ jobs:
- name: Checkout
uses: actions/checkout@v5
- name: Install Rust toolchain
run: |
set -eu
toolchain="$(sed -n 's/^channel = "\(.*\)"/\1/p' rust-toolchain.toml | head -n1)"
if [ -z "$toolchain" ]; then
echo "Unable to read Rust toolchain channel from rust-toolchain.toml" >&2
exit 1
fi
rustup toolchain install "$toolchain" --profile minimal --component clippy --component rustfmt
rustup default "$toolchain"
host="$(rustc -vV | sed -n 's/^host: //p')"
toolchain_dir="${RUSTUP_HOME:-$HOME/.rustup}/toolchains/${toolchain}-${host}"
toolchain_bin="$toolchain_dir/bin"
if [ ! -x "$toolchain_bin/rustc" ] || [ ! -x "$toolchain_bin/cargo" ]; then
echo "Rust $toolchain was not installed at $toolchain_dir." >&2
exit 1
fi
printf '%s\n' "$toolchain_bin" >> "$GITHUB_PATH"
"$toolchain_bin/rustc" --version
"$toolchain_bin/cargo" --version
"$toolchain_bin/rustfmt" --version
"$toolchain_bin/cargo-clippy" --version
- name: Verify runner toolchain
run: |
rustc --version
@@ -143,3 +189,241 @@ jobs:
- name: Validate Community deployment manifest
run: docker compose -f deploy/community/docker-compose.yml --env-file deploy/community/.env.example config -q
deploy:
name: Deploy
runs-on: ubuntu-latest
needs:
- rust
- ui
- frontend-e2e
- deployment
if: ${{ gitea.event_name == 'push' && gitea.ref == 'refs/heads/main' }}
env:
REGISTRY: git.itexp.me
IMAGE_TAG: ${{ gitea.sha }}
ADMIN_API_IMAGE: git.itexp.me/bsodfather/crank-community-admin-api
MCP_SERVER_IMAGE: git.itexp.me/bsodfather/crank-community-mcp-server
UI_IMAGE: git.itexp.me/bsodfather/crank-community-ui
OPENBAO_ENV_FILE: .openbao-env
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Verify runner toolchain
run: |
docker --version
command -v bao
bao version
- name: Load deployment secrets from OpenBao
env:
BAO_ADDR: ${{ secrets.BAO_ADDR }}
BAO_ROLE_ID: ${{ secrets.BAO_ROLE_ID }}
BAO_SECRET_ID: ${{ secrets.BAO_SECRET_ID }}
OPENBAO_APP: crank
run: scripts/load-openbao-env.sh
- name: Login to registry
run: |
. "$OPENBAO_ENV_FILE"
printf '%s' "$DEPLOY_REGISTRY_TOKEN" | \
docker login '${{ env.REGISTRY }}' -u "$DEPLOY_REGISTRY_USER" --password-stdin
- name: Build and push images
run: |
docker build -f apps/admin-api/Dockerfile \
-t '${{ env.ADMIN_API_IMAGE }}:${{ env.IMAGE_TAG }}' \
-t '${{ env.ADMIN_API_IMAGE }}:main' \
.
docker build -f apps/mcp-server/Dockerfile \
-t '${{ env.MCP_SERVER_IMAGE }}:${{ env.IMAGE_TAG }}' \
-t '${{ env.MCP_SERVER_IMAGE }}:main' \
.
docker build -f apps/ui/Dockerfile \
-t '${{ env.UI_IMAGE }}:${{ env.IMAGE_TAG }}' \
-t '${{ env.UI_IMAGE }}:main' \
.
docker push '${{ env.ADMIN_API_IMAGE }}:${{ env.IMAGE_TAG }}'
docker push '${{ env.ADMIN_API_IMAGE }}:main'
docker push '${{ env.MCP_SERVER_IMAGE }}:${{ env.IMAGE_TAG }}'
docker push '${{ env.MCP_SERVER_IMAGE }}:main'
docker push '${{ env.UI_IMAGE }}:${{ env.IMAGE_TAG }}'
docker push '${{ env.UI_IMAGE }}:main'
- name: Configure SSH key
run: |
. "$OPENBAO_ENV_FILE"
mkdir -p ~/.ssh
chmod 700 ~/.ssh
printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
- name: Configure known hosts
run: |
. "$OPENBAO_ENV_FILE"
if [ -n "${DEPLOY_KNOWN_HOSTS:-}" ]; then
printf '%s\n' "$DEPLOY_KNOWN_HOSTS" > ~/.ssh/known_hosts
else
ssh-keyscan -p "${DEPLOY_PORT:-22}" "$DEPLOY_HOST" > ~/.ssh/known_hosts
fi
chmod 644 ~/.ssh/known_hosts
- name: Sync deployment files to server
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" \
"mkdir -p '$DEPLOY_PATH'"
rsync -az -e "ssh -p $DEPLOY_PORT" deploy/community/docker-compose.yml \
"$DEPLOY_USER@$DEPLOY_HOST:$DEPLOY_PATH/docker-compose.yml"
- name: Write environment file
run: |
. "$OPENBAO_ENV_FILE"
tmp_env="$(mktemp)"
append_if_set() {
if [ -n "$2" ]; then
printf '%s=%s\n' "$1" "$2" >> "$tmp_env"
fi
}
: > "$tmp_env"
append_if_set POSTGRES_DB "$POSTGRES_DB"
append_if_set POSTGRES_USER "$POSTGRES_USER"
append_if_set POSTGRES_PASSWORD "$POSTGRES_PASSWORD"
append_if_set POSTGRES_HOST "$POSTGRES_HOST"
if [ -n "${POSTGRES_PORT:-}" ]; then
append_if_set POSTGRES_PORT "$POSTGRES_PORT"
elif [ -n "${PGBOUNCER_PORT:-}" ]; then
append_if_set POSTGRES_PORT "$PGBOUNCER_PORT"
fi
append_if_set CRANK_STORAGE_ROOT "$CRANK_STORAGE_ROOT"
append_if_set CRANK_PUBLISH_BIND "$CRANK_PUBLISH_BIND"
append_if_set CRANK_ADMIN_BIND "$CRANK_ADMIN_BIND"
append_if_set CRANK_MCP_BIND "$CRANK_MCP_BIND"
append_if_set CRANK_MCP_REFRESH_MS "$CRANK_MCP_REFRESH_MS"
append_if_set CRANK_OUTBOUND_ALLOWED_HOSTS "${CRANK_OUTBOUND_ALLOWED_HOSTS:-}"
append_if_set CRANK_OUTBOUND_DENIED_HOSTS "${CRANK_OUTBOUND_DENIED_HOSTS:-}"
append_if_set CRANK_OUTBOUND_MAX_RESPONSE_BYTES "${CRANK_OUTBOUND_MAX_RESPONSE_BYTES:-}"
append_if_set CRANK_LOG_LEVEL "$CRANK_LOG_LEVEL"
append_if_set CRANK_MASTER_KEY "$CRANK_MASTER_KEY"
append_if_set CRANK_BASE_URL "$CRANK_BASE_URL"
append_if_set CRANK_CACHE_BACKEND "$CRANK_CACHE_BACKEND"
append_if_set CRANK_CACHE_URL "$CRANK_CACHE_URL"
append_if_set CRANK_CACHE_DEFAULT_TTL_MS "$CRANK_CACHE_DEFAULT_TTL_MS"
append_if_set CRANK_SESSION_SECRET "$CRANK_SESSION_SECRET"
append_if_set CRANK_PASSWORD_PEPPER "$CRANK_PASSWORD_PEPPER"
append_if_set CRANK_SESSION_TTL_HOURS "$CRANK_SESSION_TTL_HOURS"
append_if_set CRANK_BOOTSTRAP_ADMIN_EMAIL "$CRANK_BOOTSTRAP_ADMIN_EMAIL"
append_if_set CRANK_BOOTSTRAP_ADMIN_PASSWORD "$CRANK_BOOTSTRAP_ADMIN_PASSWORD"
append_if_set CRANK_BOOTSTRAP_ADMIN_DISPLAY_NAME "$CRANK_BOOTSTRAP_ADMIN_DISPLAY_NAME"
append_if_set CRANK_DEMO_SEED "$CRANK_DEMO_SEED"
{
printf 'COMPOSE_PROJECT_NAME=community\n'
printf 'CRANK_ADMIN_API_IMAGE=%s:%s\n' '${{ env.ADMIN_API_IMAGE }}' '${{ env.IMAGE_TAG }}'
printf 'CRANK_MCP_SERVER_IMAGE=%s:%s\n' '${{ env.MCP_SERVER_IMAGE }}' '${{ env.IMAGE_TAG }}'
printf 'CRANK_UI_IMAGE=%s:%s\n' '${{ env.UI_IMAGE }}' '${{ env.IMAGE_TAG }}'
} >> "$tmp_env"
cat "$tmp_env" | ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" \
"mkdir -p '$DEPLOY_PATH' && cat > '$DEPLOY_PATH/.env'"
rm -f "$tmp_env"
- name: Validate required environment variables
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" "
set -e
cd '$DEPLOY_PATH'
required_vars='
POSTGRES_HOST
POSTGRES_PORT
POSTGRES_DB
POSTGRES_USER
POSTGRES_PASSWORD
CRANK_MASTER_KEY
CRANK_SESSION_SECRET
CRANK_PASSWORD_PEPPER
CRANK_BOOTSTRAP_ADMIN_EMAIL
CRANK_BOOTSTRAP_ADMIN_PASSWORD
CRANK_BASE_URL
'
for var in \$required_vars; do
value=\$(grep -E \"^\${var}=\" .env | tail -n1 | cut -d= -f2- || true)
if [ -z \"\$value\" ]; then
echo \"missing required env: \$var\" >&2
exit 1
fi
done
"
- name: Deploy with Docker Compose
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" "
set -e
cd '$DEPLOY_PATH'
compose_profiles=''
cache_backend=\$(grep -E '^CRANK_CACHE_BACKEND=' .env | tail -n1 | cut -d= -f2- || true)
if [ \"\$cache_backend\" = 'valkey' ] || [ \"\$cache_backend\" = 'redis' ]; then
compose_profiles='--profile cache'
fi
echo '$DEPLOY_REGISTRY_TOKEN' | docker login '${{ env.REGISTRY }}' -u '$DEPLOY_REGISTRY_USER' --password-stdin
docker compose \$compose_profiles config -q
docker compose \$compose_profiles pull
docker compose \$compose_profiles down --remove-orphans
for container in \
crank-ui-1 \
crank-admin-api-1 \
crank-mcp-server-1 \
crank-postgres-1 \
crank-valkey-1 \
crank-community-ui-1 \
crank-community-admin-api-1 \
crank-community-mcp-server-1 \
crank-community-postgres-1 \
crank-community-valkey-1; do
if docker ps -a --format '{{.Names}}' | grep -Fx \"\$container\" >/dev/null; then
docker rm -f \"\$container\"
fi
done
echo 'Docker containers before freeing required ports:'
docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Ports}}'
for port in 3000 3001 3002; do
container_ids=\$(docker ps -aq --filter \"publish=\$port\")
if [ -n \"\$container_ids\" ]; then
echo \"Removing containers publishing port \$port\"
docker inspect --format '{{.Name}} {{json .NetworkSettings.Ports}}' \$container_ids || true
docker rm -f \$container_ids
fi
done
if command -v ss >/dev/null 2>&1; then
ss -ltnp '( sport = :3000 or sport = :3001 or sport = :3002 )' || true
fi
docker compose \$compose_profiles up -d --remove-orphans
"
- name: Verify health endpoints
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" "
set -e
cd '$DEPLOY_PATH'
for attempt in \$(seq 1 30); do
if curl --fail --silent http://127.0.0.1:3000/ >/dev/null \
&& curl --fail --silent http://127.0.0.1:3001/health >/dev/null \
&& curl --fail --silent http://127.0.0.1:3002/health >/dev/null; then
exit 0
fi
sleep 2
done
echo 'deployment health verification failed' >&2
docker compose ps >&2
exit 1
"
- name: Run authenticated product smoke
run: |
. "$OPENBAO_ENV_FILE"
CRANK_STAGING_ADMIN_EMAIL="$CRANK_BOOTSTRAP_ADMIN_EMAIL" \
CRANK_STAGING_ADMIN_PASSWORD="$CRANK_BOOTSTRAP_ADMIN_PASSWORD" \
scripts/authenticated-product-smoke.sh "$CRANK_BASE_URL"
-237
View File
@@ -1,237 +0,0 @@
name: Deploy
on:
push:
branches:
- main
workflow_dispatch:
env:
REGISTRY: git.itexp.me
IMAGE_TAG: ${{ gitea.sha }}
ADMIN_API_IMAGE: git.itexp.me/bsodfather/crank-community-admin-api
MCP_SERVER_IMAGE: git.itexp.me/bsodfather/crank-community-mcp-server
UI_IMAGE: git.itexp.me/bsodfather/crank-community-ui
OPENBAO_ENV_FILE: .openbao-env
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Verify runner toolchain
run: |
docker --version
command -v bao
bao version
- name: Load deployment secrets from OpenBao
env:
BAO_ADDR: ${{ secrets.BAO_ADDR }}
BAO_ROLE_ID: ${{ secrets.BAO_ROLE_ID }}
BAO_SECRET_ID: ${{ secrets.BAO_SECRET_ID }}
OPENBAO_APP: crank
run: scripts/load-openbao-env.sh
- name: Login to registry
run: |
. "$OPENBAO_ENV_FILE"
printf '%s' "$DEPLOY_REGISTRY_TOKEN" | \
docker login '${{ env.REGISTRY }}' -u "$DEPLOY_REGISTRY_USER" --password-stdin
- name: Build and push images
run: |
docker build -f apps/admin-api/Dockerfile \
-t '${{ env.ADMIN_API_IMAGE }}:${{ env.IMAGE_TAG }}' \
-t '${{ env.ADMIN_API_IMAGE }}:main' \
.
docker build -f apps/mcp-server/Dockerfile \
-t '${{ env.MCP_SERVER_IMAGE }}:${{ env.IMAGE_TAG }}' \
-t '${{ env.MCP_SERVER_IMAGE }}:main' \
.
docker build -f apps/ui/Dockerfile \
-t '${{ env.UI_IMAGE }}:${{ env.IMAGE_TAG }}' \
-t '${{ env.UI_IMAGE }}:main' \
.
docker push '${{ env.ADMIN_API_IMAGE }}:${{ env.IMAGE_TAG }}'
docker push '${{ env.ADMIN_API_IMAGE }}:main'
docker push '${{ env.MCP_SERVER_IMAGE }}:${{ env.IMAGE_TAG }}'
docker push '${{ env.MCP_SERVER_IMAGE }}:main'
docker push '${{ env.UI_IMAGE }}:${{ env.IMAGE_TAG }}'
docker push '${{ env.UI_IMAGE }}:main'
- name: Configure SSH key
run: |
. "$OPENBAO_ENV_FILE"
mkdir -p ~/.ssh
chmod 700 ~/.ssh
printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
- name: Configure known hosts
run: |
. "$OPENBAO_ENV_FILE"
if [ -n "${DEPLOY_KNOWN_HOSTS:-}" ]; then
printf '%s\n' "$DEPLOY_KNOWN_HOSTS" > ~/.ssh/known_hosts
else
ssh-keyscan -p "${DEPLOY_PORT:-22}" "$DEPLOY_HOST" > ~/.ssh/known_hosts
fi
chmod 644 ~/.ssh/known_hosts
- name: Sync deployment files to server
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" \
"mkdir -p '$DEPLOY_PATH'"
rsync -az -e "ssh -p $DEPLOY_PORT" deploy/community/docker-compose.yml \
"$DEPLOY_USER@$DEPLOY_HOST:$DEPLOY_PATH/docker-compose.yml"
- name: Write environment file
run: |
. "$OPENBAO_ENV_FILE"
tmp_env="$(mktemp)"
append_if_set() {
if [ -n "$2" ]; then
printf '%s=%s\n' "$1" "$2" >> "$tmp_env"
fi
}
: > "$tmp_env"
append_if_set POSTGRES_DB "$POSTGRES_DB"
append_if_set POSTGRES_USER "$POSTGRES_USER"
append_if_set POSTGRES_PASSWORD "$POSTGRES_PASSWORD"
append_if_set POSTGRES_HOST "$POSTGRES_HOST"
if [ -n "${POSTGRES_PORT:-}" ]; then
append_if_set POSTGRES_PORT "$POSTGRES_PORT"
elif [ -n "${PGBOUNCER_PORT:-}" ]; then
append_if_set POSTGRES_PORT "$PGBOUNCER_PORT"
fi
append_if_set CRANK_STORAGE_ROOT "$CRANK_STORAGE_ROOT"
append_if_set CRANK_PUBLISH_BIND "$CRANK_PUBLISH_BIND"
append_if_set CRANK_ADMIN_BIND "$CRANK_ADMIN_BIND"
append_if_set CRANK_MCP_BIND "$CRANK_MCP_BIND"
append_if_set CRANK_MCP_REFRESH_MS "$CRANK_MCP_REFRESH_MS"
append_if_set CRANK_LOG_LEVEL "$CRANK_LOG_LEVEL"
append_if_set CRANK_MASTER_KEY "$CRANK_MASTER_KEY"
append_if_set CRANK_BASE_URL "$CRANK_BASE_URL"
append_if_set CRANK_CACHE_BACKEND "$CRANK_CACHE_BACKEND"
append_if_set CRANK_CACHE_URL "$CRANK_CACHE_URL"
append_if_set CRANK_CACHE_DEFAULT_TTL_MS "$CRANK_CACHE_DEFAULT_TTL_MS"
append_if_set CRANK_SESSION_SECRET "$CRANK_SESSION_SECRET"
append_if_set CRANK_PASSWORD_PEPPER "$CRANK_PASSWORD_PEPPER"
append_if_set CRANK_SESSION_TTL_HOURS "$CRANK_SESSION_TTL_HOURS"
append_if_set CRANK_BOOTSTRAP_ADMIN_EMAIL "$CRANK_BOOTSTRAP_ADMIN_EMAIL"
append_if_set CRANK_BOOTSTRAP_ADMIN_PASSWORD "$CRANK_BOOTSTRAP_ADMIN_PASSWORD"
append_if_set CRANK_BOOTSTRAP_ADMIN_DISPLAY_NAME "$CRANK_BOOTSTRAP_ADMIN_DISPLAY_NAME"
append_if_set CRANK_DEMO_SEED "$CRANK_DEMO_SEED"
{
printf 'COMPOSE_PROJECT_NAME=community\n'
printf 'CRANK_ADMIN_API_IMAGE=%s:%s\n' '${{ env.ADMIN_API_IMAGE }}' '${{ env.IMAGE_TAG }}'
printf 'CRANK_MCP_SERVER_IMAGE=%s:%s\n' '${{ env.MCP_SERVER_IMAGE }}' '${{ env.IMAGE_TAG }}'
printf 'CRANK_UI_IMAGE=%s:%s\n' '${{ env.UI_IMAGE }}' '${{ env.IMAGE_TAG }}'
} >> "$tmp_env"
cat "$tmp_env" | ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" \
"mkdir -p '$DEPLOY_PATH' && cat > '$DEPLOY_PATH/.env'"
rm -f "$tmp_env"
- name: Validate required environment variables
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" "
set -e
cd '$DEPLOY_PATH'
required_vars='
POSTGRES_HOST
POSTGRES_PORT
POSTGRES_DB
POSTGRES_USER
POSTGRES_PASSWORD
CRANK_MASTER_KEY
CRANK_SESSION_SECRET
CRANK_PASSWORD_PEPPER
CRANK_BOOTSTRAP_ADMIN_EMAIL
CRANK_BOOTSTRAP_ADMIN_PASSWORD
CRANK_BASE_URL
'
for var in \$required_vars; do
value=\$(grep -E \"^\${var}=\" .env | tail -n1 | cut -d= -f2- || true)
if [ -z \"\$value\" ]; then
echo \"missing required env: \$var\" >&2
exit 1
fi
done
"
- name: Deploy with Docker Compose
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" "
set -e
cd '$DEPLOY_PATH'
compose_profiles=''
cache_backend=\$(grep -E '^CRANK_CACHE_BACKEND=' .env | tail -n1 | cut -d= -f2- || true)
if [ \"\$cache_backend\" = 'valkey' ] || [ \"\$cache_backend\" = 'redis' ]; then
compose_profiles='--profile cache'
fi
echo '$DEPLOY_REGISTRY_TOKEN' | docker login '${{ env.REGISTRY }}' -u '$DEPLOY_REGISTRY_USER' --password-stdin
docker compose \$compose_profiles config -q
docker compose \$compose_profiles pull
docker compose \$compose_profiles down --remove-orphans
for container in \
crank-ui-1 \
crank-admin-api-1 \
crank-mcp-server-1 \
crank-postgres-1 \
crank-valkey-1 \
crank-community-ui-1 \
crank-community-admin-api-1 \
crank-community-mcp-server-1 \
crank-community-postgres-1 \
crank-community-valkey-1; do
if docker ps -a --format '{{.Names}}' | grep -Fx \"\$container\" >/dev/null; then
docker rm -f \"\$container\"
fi
done
echo 'Docker containers before freeing required ports:'
docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Ports}}'
for port in 3000 3001 3002; do
container_ids=\$(docker ps -aq --filter \"publish=\$port\")
if [ -n \"\$container_ids\" ]; then
echo \"Removing containers publishing port \$port\"
docker inspect --format '{{.Name}} {{json .NetworkSettings.Ports}}' \$container_ids || true
docker rm -f \$container_ids
fi
done
if command -v ss >/dev/null 2>&1; then
ss -ltnp '( sport = :3000 or sport = :3001 or sport = :3002 )' || true
fi
docker compose \$compose_profiles up -d --remove-orphans
"
- name: Verify health endpoints
run: |
. "$OPENBAO_ENV_FILE"
ssh -p "$DEPLOY_PORT" "$DEPLOY_USER@$DEPLOY_HOST" "
set -e
cd '$DEPLOY_PATH'
for attempt in \$(seq 1 30); do
if curl --fail --silent http://127.0.0.1:3000/ >/dev/null \
&& curl --fail --silent http://127.0.0.1:3001/health >/dev/null \
&& curl --fail --silent http://127.0.0.1:3002/health >/dev/null; then
exit 0
fi
sleep 2
done
echo 'deployment health verification failed' >&2
docker compose ps >&2
exit 1
"
- name: Run authenticated product smoke
run: |
. "$OPENBAO_ENV_FILE"
CRANK_STAGING_ADMIN_EMAIL="$CRANK_BOOTSTRAP_ADMIN_EMAIL" \
CRANK_STAGING_ADMIN_PASSWORD="$CRANK_BOOTSTRAP_ADMIN_PASSWORD" \
scripts/authenticated-product-smoke.sh "$CRANK_BASE_URL"
+17
View File
@@ -22,6 +22,23 @@ jobs:
- name: Checkout
uses: actions/checkout@v5
- name: Use preinstalled Rust toolchain
run: |
set -eu
toolchain_dir="${RUSTUP_HOME:-$HOME/.rustup}/toolchains/1.96.1-x86_64-unknown-linux-gnu"
toolchain_bin="$toolchain_dir/bin"
if [ ! -x "$toolchain_bin/rustc" ] || [ ! -x "$toolchain_bin/cargo" ]; then
echo "Rust 1.96.1 is not preinstalled at $toolchain_dir." >&2
echo "Install it in the Gitea runner image/host before running CI:" >&2
echo "rustup toolchain install 1.96.1 --profile minimal --component clippy --component rustfmt" >&2
exit 1
fi
printf '%s\n' "$toolchain_bin" >> "$GITHUB_PATH"
"$toolchain_bin/rustc" --version
"$toolchain_bin/cargo" --version
"$toolchain_bin/rustfmt" --version
"$toolchain_bin/cargo-clippy" --version
- name: Verify runner toolchain
run: |
rustc --version
Generated
+564 -869
View File
File diff suppressed because it is too large Load Diff
+7 -7
View File
@@ -18,28 +18,28 @@ resolver = "3"
[workspace.package]
edition = "2024"
license = "AGPL-3.0-only"
rust-version = "1.85"
rust-version = "1.96"
version = "0.3.1"
[workspace.dependencies]
aes-gcm = "0.10"
argon2 = "0.5"
axum = "0.8"
axum-extra = { version = "0.10", features = ["cookie"] }
axum-extra = { version = "0.12", features = ["cookie"] }
base64 = "0.22"
hkdf = "0.12"
rand = "0.8"
rand = "0.10"
reqwest = { version = "0.12", default-features = false, features = ["cookies", "json", "rustls-tls"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
serde_yaml = "0.9"
sha2 = "0.10"
sqlx = { version = "0.8", default-features = false, features = ["runtime-tokio-rustls", "postgres", "macros", "json", "time"] }
sqlx = { version = "0.9", default-features = false, features = ["runtime-tokio", "tls-rustls", "postgres", "macros", "json", "time", "uuid"] }
thiserror = "2"
time = { version = "0.3", features = ["formatting", "parsing", "serde"] }
time = { version = "0.3.53", features = ["formatting", "parsing", "serde"] }
tokio = { version = "1", features = ["macros", "rt-multi-thread"] }
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "fmt"] }
uuid = { version = "1", features = ["serde", "v7"] }
testcontainers = { version = "0.25.0", features = ["blocking"] }
testcontainers-modules = { version = "0.13.0", features = ["postgres", "blocking"] }
testcontainers = { version = "0.27", features = ["blocking"] }
testcontainers-modules = { version = "0.15", features = ["postgres", "blocking"] }
+2 -2
View File
@@ -1,4 +1,4 @@
FROM rust:1.85-bookworm AS deps
FROM rust:1.96.1-bookworm AS deps
WORKDIR /app
@@ -36,7 +36,7 @@ RUN --mount=type=cache,target=/usr/local/cargo/registry \
--mount=type=cache,target=/app/target \
SQLX_OFFLINE=true cargo build --release -p admin-api
FROM rust:1.85-bookworm AS builder
FROM rust:1.96.1-bookworm AS builder
WORKDIR /app
+6 -1
View File
@@ -19,7 +19,10 @@ use crate::{
auth_profiles::{create_auth_profile, get_auth_profile, list_auth_profiles},
capabilities::get_capabilities,
imports::{create_openapi_import, preview_openapi_import},
observability::{get_agent_usage, get_log, get_operation_usage, get_usage, list_logs},
observability::{
get_agent_usage, get_approval, get_log, get_operation_usage, get_usage, list_approvals,
list_logs,
},
operations::{
analyze_operation_quality, archive_operation, create_operation, create_version,
delete_operation, export_operation, generate_draft, get_operation,
@@ -123,6 +126,8 @@ pub fn build_app(state: AppState) -> Router {
.route("/export", get(export_workspace))
.route("/logs", get(list_logs))
.route("/logs/{log_id}", get(get_log))
.route("/approvals", get(list_approvals))
.route("/approvals/{approval_id}", get(get_approval))
.route("/usage", get(get_usage))
.route("/usage/operations/{operation_id}", get(get_operation_usage))
.route("/usage/agents/{agent_id}", get(get_agent_usage));
+20 -4
View File
@@ -1,8 +1,8 @@
use crank_core::{
AgentId, AgentStatus, AuthConfig, AuthKind, ExecutionMode, ExportMode, GeneratedDraft,
InvocationLevel, InvocationSource, InvocationStatus, OperationSecurityLevel, OperationStatus,
PlatformApiKeyScope, Protocol, SecretKind, Target, UsagePeriod, WizardState, WorkspaceId,
WorkspaceStatus,
AgentId, AgentStatus, ApprovalRequestStatus, AuthConfig, AuthKind, ExecutionMode, ExportMode,
GeneratedDraft, InvocationLevel, InvocationSource, InvocationStatus, OperationSecurityLevel,
OperationStatus, PlatformApiKeyKind, PlatformApiKeyScope, Protocol, SecretKind, Target,
UsagePeriod, WizardState, WorkspaceId, WorkspaceStatus,
};
use crank_mapping::MappingSet;
use crank_registry::{
@@ -211,7 +211,17 @@ pub struct AgentMutationResult {
#[derive(Clone, Debug, Deserialize)]
pub struct PlatformApiKeyPayload {
pub name: String,
#[serde(default = "default_platform_api_key_kind")]
pub key_kind: PlatformApiKeyKind,
pub scopes: Vec<PlatformApiKeyScope>,
#[serde(default)]
pub expires_at: Option<String>,
#[serde(default)]
pub allowed_origins: Vec<String>,
}
fn default_platform_api_key_kind() -> PlatformApiKeyKind {
PlatformApiKeyKind::McpClient
}
#[derive(Clone, Debug, Serialize)]
@@ -240,6 +250,12 @@ pub struct LogsQuery {
pub limit: Option<u32>,
}
#[derive(Clone, Debug, Deserialize)]
pub struct ApprovalsQuery {
pub status: Option<ApprovalRequestStatus>,
pub limit: Option<u32>,
}
#[derive(Clone, Debug, Deserialize)]
pub struct UsageRequestQuery {
pub period: Option<UsagePeriod>,
+1
View File
@@ -175,6 +175,7 @@ mod tests {
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
},
+7 -3
View File
@@ -10,7 +10,7 @@ use crank_community_auth::PasswordIdentityProvider;
use crank_registry::{PostgresPoolConfig, PostgresRegistry};
use crank_runtime::{
RequestRateLimitConfig, RequestRateLimiter, RuntimeCacheConfig, RuntimeCacheStores,
RuntimeLimits, SecretCrypto, community_default,
RuntimeLimits, SecretCrypto,
};
use sqlx::postgres::PgConnectOptions;
use tokio::net::TcpListener;
@@ -56,7 +56,8 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
let cache_stores = RuntimeCacheStores::from_config(&cache_config).await?;
let api_rate_limit = admin_api_rate_limit_config_from_env()?;
let secret_crypto = SecretCrypto::new(&env::var("CRANK_MASTER_KEY")?)?;
let runtime = community_default()
let outbound_http_policy = crank_runtime::OutboundHttpPolicy::from_env()?;
let runtime = crank_runtime::community_with_outbound_policy(outbound_http_policy.clone())
.with_limits(runtime_limits)
.with_response_cache(cache_stores.response.clone())
.with_coordination_store(cache_stores.coordination.clone())
@@ -70,6 +71,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
secret_crypto,
runtime,
)
.with_outbound_http_policy(outbound_http_policy)
.with_identity_provider(std::sync::Arc::new(identity_provider))
.build();
service.bootstrap_admin_user().await?;
@@ -83,9 +85,11 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
} else {
RequestRateLimiter::new(api_rate_limit)
},
trust_forwarded_headers: env_flag("CRANK_TRUST_FORWARDED_HEADERS"),
};
let app = build_app(state);
let listener = TcpListener::bind(socket_addr).await?;
let make_service = app.into_make_service_with_connect_info::<SocketAddr>();
info!(
runtime_max_concurrent_unary = runtime_limits.max_concurrent_unary,
@@ -101,7 +105,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
);
info!("admin-api listening on {}", socket_addr);
axum::serve(listener, app).await?;
axum::serve(listener, make_service).await?;
Ok(())
}
+123 -37
View File
@@ -1,19 +1,30 @@
use std::net::{IpAddr, SocketAddr};
use axum::{
extract::{Request, State},
http::header::{COOKIE, HeaderMap},
extract::{ConnectInfo, Request, State},
http::HeaderMap,
middleware::Next,
response::Response,
};
use crank_runtime::RateLimitRejection;
use crate::{auth::SESSION_COOKIE_NAME, error::ApiError, state::AppState};
use crate::{error::ApiError, state::AppState};
pub async fn apply_api_rate_limit(
State(state): State<AppState>,
request: Request,
next: Next,
) -> Result<Response, ApiError> {
let key = rate_limit_key(request.headers(), request.uri().path());
let peer_ip = request
.extensions()
.get::<ConnectInfo<SocketAddr>>()
.map(|ConnectInfo(address)| address.ip());
let key = rate_limit_key(
request.headers(),
request.uri().path(),
peer_ip,
state.trust_forwarded_headers,
);
if let Err(rejection) = state.api_rate_limiter.check(&key).await {
return Err(ApiError::rate_limited_with_context(
"request rate limit exceeded",
@@ -30,56 +41,64 @@ fn rejection_context(rejection: RateLimitRejection) -> serde_json::Value {
})
}
fn rate_limit_key(headers: &HeaderMap, path: &str) -> String {
if let Some(session_id) = session_id_from_headers(headers) {
return format!("session:{session_id}");
fn rate_limit_key(
headers: &HeaderMap,
path: &str,
peer_ip: Option<IpAddr>,
trust_forwarded_headers: bool,
) -> String {
if trust_forwarded_headers && let Some(client_ip) = forwarded_client_ip(headers) {
return format!("ip:{client_ip}");
}
if let Some(forwarded_for) = header_value(headers, "x-forwarded-for") {
let ip = forwarded_for
.split(',')
.next()
.map(str::trim)
.filter(|value| !value.is_empty())
.unwrap_or("unknown");
return format!("ip:{ip}");
}
if let Some(real_ip) = header_value(headers, "x-real-ip") {
return format!("ip:{real_ip}");
if let Some(peer_ip) = peer_ip {
return format!("ip:{peer_ip}");
}
format!("anonymous:{path}")
}
fn session_id_from_headers(headers: &HeaderMap) -> Option<String> {
let cookies = headers.get(COOKIE)?.to_str().ok()?;
for part in cookies.split(';') {
let (name, value) = part.trim().split_once('=')?;
if name != SESSION_COOKIE_NAME {
continue;
}
let (session_id, _) = value.split_once('.')?;
if !session_id.is_empty() {
return Some(session_id.to_owned());
}
/// Resolves the client IP from proxy headers, assuming a single trusted proxy.
///
/// `X-Real-IP` is preferred because a trusted proxy (e.g. nginx) sets it to the
/// real peer address. For `X-Forwarded-For` the proxy *appends* the observed
/// peer, so the last entry is the trustworthy hop; taking the first entry (as
/// naive implementations do) would let a client spoof its address by sending a
/// pre-populated header.
fn forwarded_client_ip(headers: &HeaderMap) -> Option<IpAddr> {
if let Some(real_ip) = header_value(headers, "x-real-ip").and_then(parse_ip) {
return Some(real_ip);
}
None
header_value(headers, "x-forwarded-for")?
.split(',')
.map(str::trim)
.rfind(|value| !value.is_empty())
.and_then(parse_ip)
}
fn header_value<'a>(headers: &'a HeaderMap, name: &'static str) -> Option<&'a str> {
headers.get(name)?.to_str().ok().map(str::trim)
}
fn parse_ip(value: &str) -> Option<IpAddr> {
value.parse().ok()
}
#[cfg(test)]
mod tests {
use std::net::{IpAddr, Ipv4Addr};
use axum::http::{HeaderMap, HeaderValue, header::COOKIE};
use super::rate_limit_key;
fn peer() -> Option<IpAddr> {
Some(IpAddr::V4(Ipv4Addr::new(203, 0, 113, 7)))
}
#[test]
fn keys_by_session_cookie_first() {
fn unverified_session_cookie_cannot_change_client_key() {
let mut headers = HeaderMap::new();
headers.insert(
COOKIE,
@@ -88,19 +107,86 @@ mod tests {
headers.insert("x-forwarded-for", HeaderValue::from_static("10.0.0.5"));
assert_eq!(
rate_limit_key(&headers, "/api/auth/login"),
"session:sess_123"
rate_limit_key(&headers, "/api/auth/login", peer(), true),
"ip:10.0.0.5"
);
}
#[test]
fn falls_back_to_forwarded_ip() {
fn ignores_forwarded_headers_when_untrusted() {
let mut headers = HeaderMap::new();
headers.insert("x-forwarded-for", HeaderValue::from_static("10.0.0.5"));
headers.insert("x-real-ip", HeaderValue::from_static("10.0.0.9"));
assert_eq!(
rate_limit_key(&headers, "/api/auth/login", peer(), false),
"ip:203.0.113.7"
);
}
#[test]
fn prefers_real_ip_when_trusted() {
let mut headers = HeaderMap::new();
headers.insert(
"x-forwarded-for",
HeaderValue::from_static("10.0.0.5, 10.0.0.6"),
HeaderValue::from_static("1.2.3.4, 10.0.0.6"),
);
headers.insert("x-real-ip", HeaderValue::from_static("10.0.0.9"));
assert_eq!(
rate_limit_key(&headers, "/api/auth/login", peer(), true),
"ip:10.0.0.9"
);
}
#[test]
fn uses_last_forwarded_hop_when_trusted() {
// A client can prepend spoofed entries; the trusted proxy appends the
// real peer, so the last entry is authoritative.
let mut headers = HeaderMap::new();
headers.insert(
"x-forwarded-for",
HeaderValue::from_static("1.2.3.4, 10.0.0.6"),
);
assert_eq!(rate_limit_key(&headers, "/api/auth/login"), "ip:10.0.0.5");
assert_eq!(
rate_limit_key(&headers, "/api/auth/login", peer(), true),
"ip:10.0.0.6"
);
}
#[test]
fn falls_back_to_peer_ip_without_headers() {
let headers = HeaderMap::new();
assert_eq!(
rate_limit_key(&headers, "/api/auth/login", peer(), true),
"ip:203.0.113.7"
);
}
#[test]
fn ignores_invalid_forwarded_ip_values() {
let mut headers = HeaderMap::new();
headers.insert("x-real-ip", HeaderValue::from_static("not-an-ip"));
headers.insert(
"x-forwarded-for",
HeaderValue::from_static("198.51.100.8, also-not-an-ip"),
);
assert_eq!(
rate_limit_key(&headers, "/api/auth/login", peer(), true),
"ip:203.0.113.7"
);
}
#[test]
fn falls_back_to_path_without_peer() {
let headers = HeaderMap::new();
assert_eq!(
rate_limit_key(&headers, "/api/auth/login", None, false),
"anonymous:/api/auth/login"
);
}
}
+33 -1
View File
@@ -7,7 +7,7 @@ use serde_json::{Value, json};
use crate::{
error::ApiError,
routes::access::WorkspacePath,
service::{LogsQuery, UsageRequestQuery},
service::{ApprovalsQuery, LogsQuery, UsageRequestQuery},
state::AppState,
};
@@ -17,6 +17,12 @@ pub struct WorkspaceLogPath {
pub log_id: String,
}
#[derive(serde::Deserialize)]
pub struct WorkspaceApprovalPath {
pub workspace_id: String,
pub approval_id: String,
}
#[derive(serde::Deserialize)]
pub struct WorkspaceOperationUsagePath {
pub workspace_id: String,
@@ -55,6 +61,32 @@ pub async fn get_log(
Ok(Json(json!(item)))
}
pub async fn list_approvals(
Path(path): Path<WorkspacePath>,
Query(query): Query<ApprovalsQuery>,
State(state): State<AppState>,
) -> Result<Json<Value>, ApiError> {
let items = state
.service
.list_approvals(&path.workspace_id.as_str().into(), query)
.await?;
Ok(Json(json!({ "items": items })))
}
pub async fn get_approval(
Path(path): Path<WorkspaceApprovalPath>,
State(state): State<AppState>,
) -> Result<Json<Value>, ApiError> {
let item = state
.service
.get_approval(
&path.workspace_id.as_str().into(),
&path.approval_id.as_str().into(),
)
.await?;
Ok(Json(json!(item)))
}
pub async fn get_usage(
Path(path): Path<WorkspacePath>,
Query(query): Query<UsageRequestQuery>,
+29 -2
View File
@@ -15,7 +15,9 @@ use crank_registry::{
AgentSummary, CreateInvocationLogRequest, OperationAgentRef, OperationSummary,
OperationUsageSummary, PostgresRegistry, RegistryOperation, UsageBucket,
};
use crank_runtime::{PreparedRequest, ResolvedAuth, RuntimeError, RuntimeExecutor, SecretCrypto};
use crank_runtime::{
OutboundHttpPolicy, PreparedRequest, ResolvedAuth, RuntimeError, RuntimeExecutor, SecretCrypto,
};
use crank_schema::{Schema, SchemaKind};
use serde_json::{Value, json};
use sha2::{Digest, Sha256};
@@ -38,7 +40,8 @@ mod workspaces;
use crate::{auth::AuthSettings, error::ApiError, storage::LocalArtifactStorage};
use operation_validation::{
validate_idempotency_policy, validate_protocol_target, validate_response_cache_policy,
validate_approval_policy, validate_execution_timeout, validate_idempotency_policy,
validate_protocol_target, validate_response_cache_policy,
};
#[derive(Clone)]
@@ -52,6 +55,7 @@ pub struct AdminService {
policy_engine: Arc<dyn PolicyEngine>,
audit_sink: Arc<dyn AuditSink>,
capability_profile: Arc<dyn CapabilityProfile>,
outbound_http_policy: OutboundHttpPolicy,
}
pub struct AdminServiceBuilder {
@@ -64,6 +68,7 @@ pub struct AdminServiceBuilder {
policy_engine: Option<Arc<dyn PolicyEngine>>,
audit_sink: Option<Arc<dyn AuditSink>>,
capability_profile: Option<Arc<dyn CapabilityProfile>>,
outbound_http_policy: OutboundHttpPolicy,
}
pub use crate::dto::*;
@@ -138,6 +143,7 @@ impl AdminServiceBuilder {
policy_engine: None,
audit_sink: None,
capability_profile: None,
outbound_http_policy: OutboundHttpPolicy::default(),
}
}
@@ -146,6 +152,11 @@ impl AdminServiceBuilder {
self
}
pub fn with_outbound_http_policy(mut self, policy: OutboundHttpPolicy) -> Self {
self.outbound_http_policy = policy;
self
}
#[allow(dead_code)]
pub fn with_policy_engine(mut self, policy_engine: Arc<dyn PolicyEngine>) -> Self {
self.policy_engine = Some(policy_engine);
@@ -182,6 +193,7 @@ impl AdminServiceBuilder {
capability_profile: self
.capability_profile
.unwrap_or_else(|| Arc::new(CommunityCapabilityProfile)),
outbound_http_policy: self.outbound_http_policy,
}
}
}
@@ -296,8 +308,11 @@ impl AdminService {
fn validate_operation_payload(&self, payload: &OperationPayload) -> Result<(), ApiError> {
self.validate_operation_capabilities(payload.protocol, payload.security_level)?;
validate_protocol_target(payload.protocol, &payload.target)?;
self.validate_outbound_target(&payload.target)?;
validate_execution_timeout(&payload.execution_config)?;
validate_response_cache_policy(&payload.target, &payload.execution_config)?;
validate_idempotency_policy(&payload.target, &payload.execution_config)?;
validate_approval_policy(&payload.execution_config)?;
payload.input_mapping.validate_paths()?;
payload.output_mapping.validate_paths()?;
Ok(())
@@ -306,13 +321,25 @@ impl AdminService {
fn validate_registry_operation(&self, operation: &RegistryOperation) -> Result<(), ApiError> {
self.validate_operation_capabilities(operation.protocol, operation.security_level)?;
validate_protocol_target(operation.protocol, &operation.target)?;
self.validate_outbound_target(&operation.target)?;
validate_execution_timeout(&operation.execution_config)?;
validate_response_cache_policy(&operation.target, &operation.execution_config)?;
validate_idempotency_policy(&operation.target, &operation.execution_config)?;
validate_approval_policy(&operation.execution_config)?;
operation.input_mapping.validate_paths()?;
operation.output_mapping.validate_paths()?;
Ok(())
}
fn validate_outbound_target(&self, target: &crank_core::Target) -> Result<(), ApiError> {
match target {
crank_core::Target::Rest(rest) => self
.outbound_http_policy
.validate_base_url(&rest.base_url)
.map_err(|error| ApiError::validation(error.to_string())),
}
}
fn validate_operation_capabilities(
&self,
protocol: Protocol,
+56 -3
View File
@@ -1,7 +1,10 @@
use crank_core::{AgentId, PlatformApiKey, PlatformApiKeyId, PlatformApiKeyStatus, WorkspaceId};
use crank_core::{
AgentId, PlatformApiKey, PlatformApiKeyId, PlatformApiKeyKind, PlatformApiKeyScope,
PlatformApiKeyStatus, WorkspaceId,
};
use crank_registry::{CreatePlatformApiKeyRequest, PlatformApiKeyRecord};
use serde_json::json;
use time::OffsetDateTime;
use time::{OffsetDateTime, format_description::well_known::Rfc3339};
use tracing::instrument;
use crate::{
@@ -53,7 +56,19 @@ impl AdminService {
)
})?;
let secret = generate_access_secret("crk");
validate_platform_api_key_payload(&payload)?;
let expires_at = match payload.expires_at.as_deref() {
Some(value) => Some(
OffsetDateTime::parse(value, &Rfc3339)
.map_err(|_| ApiError::validation("expires_at must be RFC3339 timestamp"))?,
),
None => None,
};
let secret = generate_access_secret(match payload.key_kind {
PlatformApiKeyKind::McpClient => "crk",
PlatformApiKeyKind::Approval => "crk_appr",
});
let api_key = PlatformApiKeyRecord {
api_key: PlatformApiKey {
id: PlatformApiKeyId::new(new_prefixed_id("pk")),
@@ -61,10 +76,13 @@ impl AdminService {
agent_id: Some(agent_id.clone()),
name: payload.name,
prefix: secret.chars().take(16).collect(),
key_kind: payload.key_kind,
scopes: payload.scopes,
status: PlatformApiKeyStatus::Active,
created_at: OffsetDateTime::now_utc(),
last_used_at: None,
expires_at,
allowed_origins: payload.allowed_origins,
},
};
@@ -109,3 +127,38 @@ impl AdminService {
Ok(())
}
}
fn validate_platform_api_key_payload(payload: &PlatformApiKeyPayload) -> Result<(), ApiError> {
if payload.name.trim().is_empty() {
return Err(ApiError::validation("key name is required"));
}
if payload.scopes.is_empty() {
return Err(ApiError::validation("at least one key scope is required"));
}
let valid = payload.scopes.iter().all(|scope| match payload.key_kind {
PlatformApiKeyKind::McpClient => matches!(
scope,
PlatformApiKeyScope::Read | PlatformApiKeyScope::Write | PlatformApiKeyScope::Deploy
),
PlatformApiKeyKind::Approval => matches!(
scope,
PlatformApiKeyScope::Approve
| PlatformApiKeyScope::Deny
| PlatformApiKeyScope::ReadPending
),
});
if !valid {
return Err(ApiError::validation(
"key scopes do not match selected key kind",
));
}
if payload.key_kind == PlatformApiKeyKind::Approval && payload.allowed_origins.len() > 20 {
return Err(ApiError::validation(
"approval key can contain at most 20 allowed origins",
));
}
Ok(())
}
+33 -13
View File
@@ -2,12 +2,12 @@ use std::collections::BTreeMap;
use crank_core::{
AgentId, InvocationLevel, InvocationSource, InvocationStatus, MembershipRole, OperationId,
OperationSecurityLevel, PlatformApiKeyScope, PlatformApiKeyStatus, Protocol, Target,
WizardState, WorkspaceId,
OperationSecurityLevel, PlatformApiKeyKind, PlatformApiKeyScope, PlatformApiKeyStatus,
Protocol, Target, WizardState, WorkspaceId,
};
use crank_mapping::{JsonPathRoot, infer_mapping_from_samples};
use crank_mapping::{MappingRule, MappingSet};
use crank_registry::{ListInvocationLogsQuery, OperationSummary, SampleKind};
use crank_registry::{ListInvocationLogsQuery, OperationSummary, RegistryError, SampleKind};
use crank_schema::Schema;
use serde_json::{Value, json};
@@ -99,11 +99,8 @@ impl AdminService {
.name
.starts_with("weather_current_open_meteo_smoke_")
{
self.delete_operation(
workspace_id,
&OperationId::new(operation.id.as_str().to_owned()),
)
.await?;
self.delete_legacy_demo_operation_if_safe(workspace_id, &operation.id)
.await?;
}
}
@@ -113,17 +110,36 @@ impl AdminService {
"weather_current_open_meteo",
] {
if let Some(operation) = self.find_operation_by_name(workspace_id, name).await? {
self.delete_operation(
workspace_id,
&OperationId::new(operation.id.as_str().to_owned()),
)
.await?;
self.delete_legacy_demo_operation_if_safe(workspace_id, &operation.id)
.await?;
}
}
Ok(())
}
async fn delete_legacy_demo_operation_if_safe(
&self,
workspace_id: &WorkspaceId,
operation_id: &OperationId,
) -> Result<(), ApiError> {
match self
.registry
.delete_operation(workspace_id, operation_id)
.await
{
Ok(()) => Ok(()),
Err(RegistryError::OperationHasPublishedAgentBindings { .. }) => {
tracing::warn!(
operation_id = %operation_id.as_str(),
"legacy demo operation is still bound to a published agent; leaving it in place"
);
Ok(())
}
Err(error) => Err(ApiError::from(error)),
}
}
async fn ensure_demo_platform_api_key(
&self,
workspace_id: &WorkspaceId,
@@ -146,7 +162,10 @@ impl AdminService {
agent_id,
PlatformApiKeyPayload {
name: name.to_owned(),
key_kind: PlatformApiKeyKind::McpClient,
scopes,
expires_at: None,
allowed_origins: Vec::new(),
},
)
.await?
@@ -368,6 +387,7 @@ fn demo_rest_operation_payload() -> OperationPayload {
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
},
+1
View File
@@ -191,6 +191,7 @@ impl AdminService {
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
},
+83 -3
View File
@@ -1,11 +1,21 @@
use crank_core::{AgentId, InvocationLogId, OperationId, UsagePeriod, WorkspaceId};
use crank_registry::{InvocationLogRecord, ListInvocationLogsQuery, UsageQuery, UsageRollupRecord};
use crank_core::{
AgentId, ApprovalRequestId, ApprovalRequestStatus, InvocationLogId, OperationId, UsagePeriod,
WorkspaceId,
};
use crank_registry::{
ApprovalRequestRecord, ExpireApprovalRequest, InvocationLogRecord, ListApprovalRequestsQuery,
ListInvocationLogsQuery, UsageQuery, UsageRollupRecord,
};
use serde_json::json;
use time::OffsetDateTime;
use tracing::instrument;
use crate::{
error::ApiError,
service::{AdminService, LogsQuery, UsageOverviewResponse, UsageRequestQuery, usage_window},
service::{
AdminService, ApprovalsQuery, LogsQuery, UsageOverviewResponse, UsageRequestQuery,
usage_window,
},
};
impl AdminService {
@@ -52,6 +62,76 @@ impl AdminService {
})
}
#[instrument(skip(self))]
pub async fn list_approvals(
&self,
workspace_id: &WorkspaceId,
query: ApprovalsQuery,
) -> Result<Vec<ApprovalRequestRecord>, ApiError> {
self.ensure_workspace_exists(workspace_id).await?;
let records = self
.registry
.list_approval_requests(ListApprovalRequestsQuery {
workspace_id,
status: query.status,
limit: query.limit.unwrap_or(50).clamp(1, 200),
})
.await?;
let mut normalized = Vec::with_capacity(records.len());
for record in records {
let record = self.normalize_approval_record(record).await?;
if query.status.is_none() || record.approval.status == query.status.unwrap() {
normalized.push(record);
}
}
Ok(normalized)
}
#[instrument(skip(self))]
pub async fn get_approval(
&self,
workspace_id: &WorkspaceId,
approval_id: &ApprovalRequestId,
) -> Result<ApprovalRequestRecord, ApiError> {
self.ensure_workspace_exists(workspace_id).await?;
let record = self
.registry
.get_approval_request(workspace_id, approval_id)
.await?
.ok_or_else(|| {
ApiError::not_found_with_context(
format!("approval request {} was not found", approval_id.as_str()),
json!({ "approval_id": approval_id.as_str() }),
)
})?;
self.normalize_approval_record(record).await
}
async fn normalize_approval_record(
&self,
record: ApprovalRequestRecord,
) -> Result<ApprovalRequestRecord, ApiError> {
if record.approval.status != ApprovalRequestStatus::Pending
|| record.approval.expires_at > OffsetDateTime::now_utc()
{
return Ok(record);
}
Ok(self
.registry
.expire_approval_request(ExpireApprovalRequest {
workspace_id: &record.approval.workspace_id,
agent_id: &record.approval.agent_id,
approval_id: &record.approval.id,
expired_at: OffsetDateTime::now_utc(),
})
.await?
.unwrap_or(record))
}
#[instrument(skip(self))]
pub async fn get_usage_overview(
&self,
@@ -3,6 +3,8 @@ use serde_json::json;
use crate::error::ApiError;
const MAX_OPERATION_TIMEOUT_MS: u64 = 300_000;
pub(super) fn validate_protocol_target(
protocol: Protocol,
target: &Target,
@@ -16,6 +18,18 @@ pub(super) fn validate_protocol_target(
Err(ApiError::validation("protocol and target kind must match"))
}
pub(super) fn validate_execution_timeout(
execution_config: &crank_core::ExecutionConfig,
) -> Result<(), ApiError> {
if !(1..=MAX_OPERATION_TIMEOUT_MS).contains(&execution_config.timeout_ms) {
return Err(ApiError::validation_with_context(
format!("operation timeout must be between 1 and {MAX_OPERATION_TIMEOUT_MS} ms"),
json!({ "field": "execution_config.timeout_ms" }),
));
}
Ok(())
}
pub(super) fn validate_response_cache_policy(
target: &Target,
execution_config: &crank_core::ExecutionConfig,
@@ -105,16 +119,54 @@ pub(super) fn validate_idempotency_policy(
Ok(())
}
pub(super) fn validate_approval_policy(
execution_config: &crank_core::ExecutionConfig,
) -> Result<(), ApiError> {
let Some(policy) = execution_config.approval_policy.as_ref() else {
return Ok(());
};
if !policy.required {
return Ok(());
}
if policy.ttl_seconds == 0 || policy.ttl_seconds > 300 {
return Err(ApiError::validation_with_context(
"approval ttl must be between 1 and 300 seconds".to_owned(),
json!({
"field": "execution_config.approval_policy.ttl_seconds",
}),
));
}
if let Some(message) = policy.elicitation_message.as_ref()
&& message.chars().count() > 240
{
return Err(ApiError::validation_with_context(
"approval elicitation message must be at most 240 characters".to_owned(),
json!({
"field": "execution_config.approval_policy.elicitation_message",
}),
));
}
Ok(())
}
#[cfg(test)]
mod tests {
use std::collections::BTreeMap;
use crank_core::{
ExecutionConfig, HttpMethod, IdempotencyMode, IdempotencyPolicy, ResponseCachePolicy,
RestTarget, Target,
ExecutionConfig, HttpMethod, IdempotencyMode, IdempotencyPolicy, OperationApprovalMode,
OperationApprovalPayloadPreviewMode, OperationApprovalPolicy, OperationApprovalRiskLevel,
ResponseCachePolicy, RestTarget, Target,
};
use super::{validate_idempotency_policy, validate_response_cache_policy};
use super::{
validate_approval_policy, validate_execution_timeout, validate_idempotency_policy,
validate_response_cache_policy,
};
fn cacheable_execution_config() -> ExecutionConfig {
ExecutionConfig {
@@ -123,6 +175,7 @@ mod tests {
response_cache: Some(ResponseCachePolicy { ttl_ms: 5_000 }),
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
}
@@ -140,6 +193,7 @@ mod tests {
header_name: Some("Idempotency-Key".to_owned()),
}),
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
}
@@ -159,6 +213,19 @@ mod tests {
assert!(result.is_ok());
}
#[test]
fn rejects_zero_and_excessive_execution_timeouts() {
let mut config = cacheable_execution_config();
config.timeout_ms = 0;
assert!(validate_execution_timeout(&config).is_err());
config.timeout_ms = 300_001;
assert!(validate_execution_timeout(&config).is_err());
config.timeout_ms = 300_000;
assert!(validate_execution_timeout(&config).is_ok());
}
#[test]
fn rejects_response_cache_for_non_get_rest_operation() {
let target = Target::Rest(RestTarget {
@@ -238,4 +305,42 @@ mod tests {
"required idempotency needs input_field or header_name"
);
}
#[test]
fn accepts_valid_approval_policy() {
let mut config = cacheable_execution_config();
config.approval_policy = Some(OperationApprovalPolicy {
required: true,
mode: OperationApprovalMode::Custom,
risk_level: OperationApprovalRiskLevel::Dangerous,
ttl_seconds: 300,
show_payload_preview: true,
payload_preview_mode: OperationApprovalPayloadPreviewMode::MaskedJson,
elicitation_message: None,
});
validate_approval_policy(&config).unwrap();
}
#[test]
fn rejects_invalid_approval_policy() {
let mut config = cacheable_execution_config();
config.approval_policy = Some(OperationApprovalPolicy {
required: true,
mode: OperationApprovalMode::Custom,
risk_level: OperationApprovalRiskLevel::Dangerous,
ttl_seconds: 0,
show_payload_preview: true,
payload_preview_mode: OperationApprovalPayloadPreviewMode::MaskedJson,
elicitation_message: None,
});
let error = validate_approval_policy(&config).unwrap_err();
assert!(matches!(error, crate::error::ApiError::Validation { .. }));
assert_eq!(
error.to_string(),
"approval ttl must be between 1 and 300 seconds"
);
}
}
+6
View File
@@ -5,4 +5,10 @@ use crank_runtime::RequestRateLimiter;
pub struct AppState {
pub service: AdminService,
pub api_rate_limiter: RequestRateLimiter,
/// Whether to trust `X-Real-IP` / `X-Forwarded-For` for client identification.
///
/// Only enable when the service sits behind a trusted reverse proxy that
/// overwrites these headers (e.g. the bundled nginx). When disabled the
/// real TCP peer address is used, which a client cannot spoof.
pub trust_forwarded_headers: bool,
}
@@ -109,15 +109,19 @@ async fn rejects_rapid_login_requests_with_429() {
api_rate_limiter: crank_runtime::RequestRateLimiter::new(
crank_runtime::RequestRateLimitConfig::new(1, 1).unwrap(),
),
trust_forwarded_headers: false,
});
let (shutdown_tx, shutdown_rx) = tokio::sync::oneshot::channel();
let handle = tokio::spawn(async move {
axum::serve(listener, app)
.with_graceful_shutdown(async move {
let _ = shutdown_rx.await;
})
.await
.unwrap();
axum::serve(
listener,
app.into_make_service_with_connect_info::<std::net::SocketAddr>(),
)
.with_graceful_shutdown(async move {
let _ = shutdown_rx.await;
})
.await
.unwrap();
});
let client = reqwest::Client::new();
+6 -1
View File
@@ -104,6 +104,7 @@ pub(super) fn build_test_app(
api_rate_limiter: crank_runtime::RequestRateLimiter::new(
crank_runtime::RequestRateLimitConfig::new(10_000, 10_000).unwrap(),
),
trust_forwarded_headers: false,
})
}
@@ -113,13 +114,16 @@ pub(super) fn test_service(
auth_settings: AuthSettings,
secret_crypto: SecretCrypto,
) -> AdminService {
let outbound_policy = crank_runtime::OutboundHttpPolicy::allowing_hosts(["127.0.0.1"]);
let runtime = crank_runtime::community_with_outbound_policy(outbound_policy.clone()).build();
AdminServiceBuilder::new(
registry,
storage_root,
auth_settings,
secret_crypto,
crank_runtime::RuntimeExecutor::new(),
runtime,
)
.with_outbound_http_policy(outbound_policy)
.build()
}
@@ -297,6 +301,7 @@ pub(super) fn test_operation_payload(base_url: &str, name: &str) -> OperationPay
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
},
@@ -12,8 +12,8 @@ use std::{
use async_trait::async_trait;
use axum::{Json, Router, routing::post};
use crank_core::{
ExecutionConfig, HttpMethod, MembershipRole, OperationSecurityLevel, Protocol,
ResponseCachePolicy, RestTarget, SecretKind, Target, ToolDescription, WorkspaceId,
AgentId, ExecutionConfig, HttpMethod, MembershipRole, OperationId, OperationSecurityLevel,
Protocol, ResponseCachePolicy, RestTarget, SecretKind, Target, ToolDescription, WorkspaceId,
};
use crank_core::{IdentityError, IdentityProvider, IdentityProviderKind, LoginOutcome};
use crank_mapping::{MappingRule, MappingSet};
@@ -27,7 +27,9 @@ use tokio::net::TcpListener;
use admin_api::{
app::build_app,
auth::{AuthSettings, BootstrapAdminConfig, hash_password},
service::{AdminService, AdminServiceBuilder, OperationPayload},
service::{
AdminService, AdminServiceBuilder, AgentBindingPayload, AgentPayload, OperationPayload,
},
state::AppState,
};
@@ -151,6 +153,7 @@ async fn manages_agent_platform_api_keys() {
.post(format!("{base_url}/agents/{agent_id}/platform-api-keys"))
.json(&json!({
"name": "sales-routing-primary",
"key_kind": "mcp_client",
"scopes": ["read", "write"]
}))
.send()
@@ -162,6 +165,31 @@ async fn manages_agent_platform_api_keys() {
.as_str()
.unwrap()
.to_owned();
let created_approval_key = assert_success_json(
client
.post(format!("{base_url}/agents/{agent_id}/platform-api-keys"))
.json(&json!({
"name": "sales-routing-approver",
"key_kind": "approval",
"scopes": ["approve", "deny"],
"allowed_origins": ["https://client.example.test"]
}))
.send()
.await
.unwrap(),
)
.await;
let invalid_mixed_scope_status = client
.post(format!("{base_url}/agents/{agent_id}/platform-api-keys"))
.json(&json!({
"name": "invalid-mixed-scope",
"key_kind": "approval",
"scopes": ["read", "approve"]
}))
.send()
.await
.unwrap()
.status();
let listed_keys = assert_success_json(
client
@@ -190,14 +218,27 @@ async fn manages_agent_platform_api_keys() {
.status();
assert_eq!(created_key["api_key"]["api_key"]["agent_id"], agent_id);
assert_eq!(created_key["api_key"]["api_key"]["key_kind"], "mcp_client");
assert_eq!(
created_approval_key["api_key"]["api_key"]["key_kind"],
"approval"
);
assert!(
created_approval_key["secret"]
.as_str()
.unwrap()
.starts_with("crk_appr_")
);
assert_eq!(
created_approval_key["api_key"]["api_key"]["allowed_origins"],
json!(["https://client.example.test"])
);
assert_eq!(invalid_mixed_scope_status, reqwest::StatusCode::BAD_REQUEST);
assert_eq!(
listed_keys["items"][0]["api_key"]["agent_id"],
json!(agent_id)
);
assert_eq!(
listed_keys["items"][0]["api_key"]["name"],
"sales-routing-primary"
);
assert_eq!(listed_keys["items"].as_array().unwrap().len(), 2);
assert!(created_key["secret"].as_str().unwrap().starts_with("crk_"));
assert_eq!(revoke_status, reqwest::StatusCode::NO_CONTENT);
assert_eq!(delete_status, reqwest::StatusCode::NO_CONTENT);
@@ -398,6 +439,61 @@ async fn seeds_demo_assets_for_live_ui() {
service.bootstrap_admin_user().await.unwrap();
service.seed_demo_assets().await.unwrap();
let smoke_operation = service
.create_operation(
&WorkspaceId::new(DEFAULT_WORKSPACE_ID),
test_operation_payload("https://example.test", "internal_health_smoke_bound"),
)
.await
.unwrap();
let smoke_operation_id = OperationId::new(smoke_operation.operation_id);
service
.publish_operation(
&WorkspaceId::new(DEFAULT_WORKSPACE_ID),
&smoke_operation_id,
smoke_operation.version,
)
.await
.unwrap();
let smoke_agent = service
.create_agent(
&WorkspaceId::new(DEFAULT_WORKSPACE_ID),
AgentPayload {
slug: "legacy-smoke-agent".to_owned(),
display_name: "Legacy Smoke Agent".to_owned(),
description: "Keeps a legacy smoke operation published".to_owned(),
instructions: json!({}),
tool_selection_policy: json!({}),
},
)
.await
.unwrap();
let smoke_agent_id = AgentId::new(smoke_agent.agent_id);
service
.save_agent_bindings(
&WorkspaceId::new(DEFAULT_WORKSPACE_ID),
&smoke_agent_id,
vec![AgentBindingPayload {
operation_id: smoke_operation_id.as_str().to_owned(),
operation_version: smoke_operation.version,
tool_name: "legacy_health_smoke".to_owned(),
tool_title: "Legacy health smoke".to_owned(),
tool_description_override: None,
enabled: true,
}],
)
.await
.unwrap();
service
.publish_agent(
&WorkspaceId::new(DEFAULT_WORKSPACE_ID),
&smoke_agent_id,
smoke_agent.version,
)
.await
.unwrap();
service.seed_demo_assets().await.unwrap();
let owner = registry
@@ -431,15 +527,18 @@ async fn seeds_demo_assets_for_live_ui() {
.iter()
.any(|operation| operation.name == "crm_create_lead")
);
assert!(!operations.iter().any(
|operation| operation.name.starts_with("internal_health_smoke_")
&& operation.name != "internal_health_smoke_bound"
));
assert!(
!operations
operations
.iter()
.any(|operation| operation.name.starts_with("internal_health_smoke_"))
.any(|operation| operation.name == "internal_health_smoke_bound")
);
let agents = service.list_agents(&default_workspace_id).await.unwrap();
assert_eq!(agents.len(), 1);
assert_eq!(agents[0].slug, "currency-rates");
assert!(agents.iter().any(|agent| agent.slug == "currency-rates"));
assert!(agents.iter().any(|agent| agent.key_count > 0));
+2 -2
View File
@@ -1,4 +1,4 @@
FROM rust:1.85-bookworm AS deps
FROM rust:1.96.1-bookworm AS deps
WORKDIR /app
@@ -36,7 +36,7 @@ RUN --mount=type=cache,target=/usr/local/cargo/registry \
--mount=type=cache,target=/app/target \
SQLX_OFFLINE=true cargo build --release -p mcp-server
FROM rust:1.85-bookworm AS builder
FROM rust:1.96.1-bookworm AS builder
WORKDIR /app
+5 -4
View File
@@ -1,12 +1,13 @@
use std::{env, net::SocketAddr, time::Duration};
use crank_community_mcp::{
auth::CommunityMachineCredentialVerifier, build_app, session::PostgresTransportSessionStore,
auth::CommunityMachineCredentialVerifier, build_app_with_background_workers,
session::PostgresTransportSessionStore,
};
use crank_registry::{PostgresPoolConfig, PostgresRegistry};
use crank_runtime::{
RequestRateLimitConfig, RequestRateLimiter, RuntimeCacheConfig, RuntimeCacheStores,
RuntimeLimits, SecretCrypto, community_default,
RuntimeLimits, SecretCrypto,
};
use sqlx::postgres::PgConnectOptions;
use tokio::net::TcpListener;
@@ -46,12 +47,12 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
)
.await?;
let secret_crypto = SecretCrypto::new(&env::var("CRANK_MASTER_KEY")?)?;
let runtime = community_default()
let runtime = crank_runtime::community_from_env()?
.with_limits(runtime_limits)
.with_response_cache(cache_stores.response.clone())
.with_coordination_store(cache_stores.coordination.clone())
.build();
let app = build_app(
let app = build_app_with_background_workers(
registry,
refresh_interval,
base_url,
@@ -1,5 +1,7 @@
#![allow(dead_code, unused_imports)]
mod approval_access;
use super::common::*;
use std::{
@@ -17,14 +19,18 @@ use axum::{
};
use base64::{Engine as _, engine::general_purpose::URL_SAFE_NO_PAD};
use crank_core::{
Agent, AgentId, AgentOperationBinding, AgentStatus, AgentVersion, ExecutionConfig, HttpMethod,
Operation, OperationId, OperationStatus, PlatformApiKey, PlatformApiKeyId, PlatformApiKeyScope,
PlatformApiKeyStatus, Protocol, RestTarget, Target, ToolDescription, WorkspaceId,
Agent, AgentId, AgentOperationBinding, AgentStatus, AgentVersion, ApprovalRequest,
ApprovalRequestId, ApprovalRequestStatus, ExecutionConfig, HttpMethod, InvocationSource,
Operation, OperationApprovalMode, OperationApprovalPayloadPreviewMode, OperationApprovalPolicy,
OperationApprovalRiskLevel, OperationId, OperationStatus, PlatformApiKey, PlatformApiKeyId,
PlatformApiKeyScope, PlatformApiKeyStatus, Protocol, RestTarget, Target, ToolDescription,
WorkspaceId,
};
use crank_mapping::{MappingRule, MappingSet};
use crank_registry::{
CreateAgentRequest, CreatePlatformApiKeyRequest, ListInvocationLogsQuery, PostgresRegistry,
PublishAgentRequest, PublishRequest, SaveAgentBindingsRequest,
CreateAgentRequest, CreateApprovalRequest, CreatePlatformApiKeyRequest,
ListInvocationLogsQuery, PostgresRegistry, PublishAgentRequest, PublishRequest,
SaveAgentBindingsRequest,
};
use crank_runtime::{
InMemoryCoordinationStateStore, RequestRateLimitConfig, RequestRateLimiter, RuntimeExecutor,
@@ -136,7 +142,10 @@ fn build_test_app_with_store(
refresh_interval,
public_base_url,
SecretCrypto::new("test-master-key").unwrap(),
RuntimeExecutor::new(),
crank_runtime::community_with_outbound_policy(
crank_runtime::OutboundHttpPolicy::allowing_hosts(["127.0.0.1"]),
)
.build(),
RequestRateLimiter::new(rate_limit_config),
std::sync::Arc::new(InMemoryCoordinationStateStore::default()),
sessions,
@@ -476,6 +485,38 @@ async fn rejects_initialize_without_platform_api_key() {
assert_eq!(response.status(), reqwest::StatusCode::UNAUTHORIZED);
}
#[tokio::test]
async fn rejects_initialize_with_approval_platform_api_key() {
let registry = test_registry().await;
publish_agent_with_bindings(&registry, "sales-approval-key", vec![]).await;
let api_key =
create_approval_platform_api_key(&registry, "sales-approval-key", "approval-only").await;
let base_url = spawn_mcp_server(build_test_app(
registry,
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let response = client
.post(agent_mcp_url(&base_url, "sales-approval-key"))
.header(header::ACCEPT, "application/json, text/event-stream")
.header(header::AUTHORIZATION, format!("Bearer {api_key}"))
.json(&json!({
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-11-25"
}
}))
.send()
.await
.unwrap();
assert_eq!(response.status(), reqwest::StatusCode::UNAUTHORIZED);
}
#[tokio::test]
async fn rejects_tool_call_with_read_only_platform_api_key() {
let registry = test_registry().await;
@@ -0,0 +1,617 @@
use super::*;
#[tokio::test]
async fn approval_key_lists_and_decides_pending_requests() {
let registry = test_registry().await;
let upstream_base_url = spawn_upstream_server().await;
let operation = test_operation(&upstream_base_url, "crm_human_approval");
registry
.create_operation(&test_workspace_id(), &operation, Some("alice"))
.await
.unwrap();
publish_agent_with_bindings(
&registry,
"sales-human-approval",
vec![binding_for_operation(&operation)],
)
.await;
let approval = ApprovalRequest {
id: ApprovalRequestId::new("approval_mcp_01"),
workspace_id: test_workspace_id(),
agent_id: test_agent_id("sales-human-approval"),
operation_id: operation.id.clone(),
operation_version: 1,
status: ApprovalRequestStatus::Pending,
risk_level: OperationApprovalRiskLevel::Dangerous,
request_payload: json!({"email": "ada@example.com"}),
response_payload: None,
created_at: OffsetDateTime::now_utc(),
expires_at: OffsetDateTime::now_utc() + time::Duration::minutes(5),
decided_at: None,
decided_by_key_id: None,
decision_note: None,
};
registry
.create_approval_request(CreateApprovalRequest {
approval: &approval,
})
.await
.unwrap();
let approval_key =
create_approval_platform_api_key(&registry, "sales-human-approval", "approval-http").await;
let mcp_key = create_platform_api_key(
&registry,
"sales-human-approval",
"mcp-human-approval",
&[PlatformApiKeyScope::Read, PlatformApiKeyScope::Write],
)
.await;
let base_url = spawn_mcp_server(build_test_app(
registry.clone(),
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let approvals_url = format!(
"{}/approvals",
agent_mcp_url(&base_url, "sales-human-approval")
);
let rejected = client
.get(&approvals_url)
.header(header::AUTHORIZATION, format!("Bearer {mcp_key}"))
.send()
.await
.unwrap();
assert_eq!(rejected.status(), reqwest::StatusCode::UNAUTHORIZED);
let pending = client
.get(&approvals_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.send()
.await
.unwrap();
assert_eq!(pending.status(), reqwest::StatusCode::OK);
let pending_body = pending.json::<Value>().await.unwrap();
assert_eq!(pending_body["items"].as_array().unwrap().len(), 1);
assert_eq!(
pending_body["items"][0]["approval"]["request_payload"],
json!({"email": "ada@example.com"})
);
let approve_url = format!(
"{}/approvals/{}/approve",
agent_mcp_url(&base_url, "sales-human-approval"),
approval.id
);
let approved = client
.post(&approve_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.json(&json!({ "approve": "yes", "note": "confirmed by test" }))
.send()
.await
.unwrap();
assert_eq!(approved.status(), reqwest::StatusCode::OK);
let approved_body = approved.json::<Value>().await.unwrap();
assert_eq!(
approved_body["approval"]["status"],
Value::String("completed".to_owned())
);
assert_eq!(
approved_body["approval"]["response_payload"],
json!({ "id": "lead_123" })
);
let status_url = format!(
"{}/approvals/{}",
agent_mcp_url(&base_url, "sales-human-approval"),
approval.id
);
let current = client
.get(&status_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.send()
.await
.unwrap();
assert_eq!(current.status(), reqwest::StatusCode::OK);
let current_body = current.json::<Value>().await.unwrap();
assert_eq!(
current_body["approval"]["status"],
Value::String("completed".to_owned())
);
assert_eq!(
current_body["approval"]["response_payload"],
json!({ "id": "lead_123" })
);
let repeated_approve = client
.post(&approve_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.json(&json!({ "approve": "yes", "note": "duplicate confirmation" }))
.send()
.await
.unwrap();
assert_eq!(repeated_approve.status(), reqwest::StatusCode::OK);
let repeated_body = repeated_approve.json::<Value>().await.unwrap();
assert_eq!(
repeated_body["approval"]["status"],
Value::String("completed".to_owned())
);
assert_eq!(
repeated_body["approval"]["response_payload"],
json!({ "id": "lead_123" })
);
let pending_after = client
.get(&approvals_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.send()
.await
.unwrap()
.json::<Value>()
.await
.unwrap();
assert!(pending_after["items"].as_array().unwrap().is_empty());
let logs = registry
.list_invocation_logs(ListInvocationLogsQuery {
workspace_id: &test_workspace_id(),
level: None,
search_text: None,
source: Some(InvocationSource::AgentToolCall),
operation_id: Some(&operation.id),
agent_id: Some(&test_agent_id("sales-human-approval")),
created_after: None,
limit: 10,
})
.await
.unwrap();
assert_eq!(logs.len(), 1);
}
#[tokio::test]
async fn approval_key_denies_without_executing_upstream() {
let registry = test_registry().await;
let upstream_base_url = spawn_upstream_server().await;
let operation = test_operation(&upstream_base_url, "crm_human_deny");
registry
.create_operation(&test_workspace_id(), &operation, Some("alice"))
.await
.unwrap();
publish_agent_with_bindings(
&registry,
"sales-human-deny",
vec![binding_for_operation(&operation)],
)
.await;
let approval = ApprovalRequest {
id: ApprovalRequestId::new("approval_mcp_deny_01"),
workspace_id: test_workspace_id(),
agent_id: test_agent_id("sales-human-deny"),
operation_id: operation.id.clone(),
operation_version: 1,
status: ApprovalRequestStatus::Pending,
risk_level: OperationApprovalRiskLevel::Dangerous,
request_payload: json!({"email": "deny@example.com"}),
response_payload: None,
created_at: OffsetDateTime::now_utc(),
expires_at: OffsetDateTime::now_utc() + time::Duration::minutes(5),
decided_at: None,
decided_by_key_id: None,
decision_note: None,
};
registry
.create_approval_request(CreateApprovalRequest {
approval: &approval,
})
.await
.unwrap();
let approval_key =
create_approval_platform_api_key(&registry, "sales-human-deny", "approval-deny-http").await;
let base_url = spawn_mcp_server(build_test_app(
registry.clone(),
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let deny_url = format!(
"{}/approvals/{}/deny",
agent_mcp_url(&base_url, "sales-human-deny"),
approval.id
);
let denied = client
.post(&deny_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.json(&json!({ "approve": "no", "note": "rejected by test" }))
.send()
.await
.unwrap();
assert_eq!(denied.status(), reqwest::StatusCode::OK);
let denied_body = denied.json::<Value>().await.unwrap();
assert_eq!(
denied_body["approval"]["status"],
Value::String("denied".to_owned())
);
let repeated_deny = client
.post(&deny_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.json(&json!({ "approve": "no", "note": "duplicate rejection" }))
.send()
.await
.unwrap();
assert_eq!(repeated_deny.status(), reqwest::StatusCode::OK);
let repeated_body = repeated_deny.json::<Value>().await.unwrap();
assert_eq!(
repeated_body["approval"]["status"],
Value::String("denied".to_owned())
);
let logs = registry
.list_invocation_logs(ListInvocationLogsQuery {
workspace_id: &test_workspace_id(),
level: None,
search_text: None,
source: Some(InvocationSource::AgentToolCall),
operation_id: Some(&operation.id),
agent_id: Some(&test_agent_id("sales-human-deny")),
created_after: None,
limit: 10,
})
.await
.unwrap();
assert!(logs.is_empty());
}
#[tokio::test]
async fn approval_key_expires_without_executing_upstream() {
let registry = test_registry().await;
let upstream_base_url = spawn_upstream_server().await;
let operation = test_operation(&upstream_base_url, "crm_human_expired");
registry
.create_operation(&test_workspace_id(), &operation, Some("alice"))
.await
.unwrap();
publish_agent_with_bindings(
&registry,
"sales-human-expired",
vec![binding_for_operation(&operation)],
)
.await;
let approval = ApprovalRequest {
id: ApprovalRequestId::new("approval_mcp_expired_01"),
workspace_id: test_workspace_id(),
agent_id: test_agent_id("sales-human-expired"),
operation_id: operation.id.clone(),
operation_version: 1,
status: ApprovalRequestStatus::Pending,
risk_level: OperationApprovalRiskLevel::Dangerous,
request_payload: json!({"email": "expired@example.com"}),
response_payload: None,
created_at: OffsetDateTime::now_utc() - time::Duration::minutes(10),
expires_at: OffsetDateTime::now_utc() - time::Duration::minutes(5),
decided_at: None,
decided_by_key_id: None,
decision_note: None,
};
registry
.create_approval_request(CreateApprovalRequest {
approval: &approval,
})
.await
.unwrap();
let approval_key =
create_approval_platform_api_key(&registry, "sales-human-expired", "approval-expired-http")
.await;
let base_url = spawn_mcp_server(build_test_app(
registry.clone(),
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let approve_url = format!(
"{}/approvals/{}/approve",
agent_mcp_url(&base_url, "sales-human-expired"),
approval.id
);
let expired = client
.post(&approve_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.json(&json!({ "approve": "yes", "note": "too late" }))
.send()
.await
.unwrap();
assert_eq!(expired.status(), reqwest::StatusCode::OK);
let expired_body = expired.json::<Value>().await.unwrap();
assert_eq!(
expired_body["approval"]["status"],
Value::String("expired".to_owned())
);
let logs = registry
.list_invocation_logs(ListInvocationLogsQuery {
workspace_id: &test_workspace_id(),
level: None,
search_text: None,
source: Some(InvocationSource::AgentToolCall),
operation_id: Some(&operation.id),
agent_id: Some(&test_agent_id("sales-human-expired")),
created_after: None,
limit: 10,
})
.await
.unwrap();
assert!(logs.is_empty());
}
#[tokio::test]
async fn tool_call_with_approval_policy_creates_pending_request() {
let registry = test_registry().await;
let upstream_base_url = spawn_upstream_server().await;
let mut operation = test_operation(&upstream_base_url, "crm_requires_human_approval");
operation.execution_config.approval_policy = Some(OperationApprovalPolicy {
required: true,
mode: OperationApprovalMode::Custom,
risk_level: OperationApprovalRiskLevel::Dangerous,
ttl_seconds: 300,
show_payload_preview: true,
payload_preview_mode: OperationApprovalPayloadPreviewMode::MaskedJson,
elicitation_message: None,
});
registry
.create_operation(&test_workspace_id(), &operation, Some("alice"))
.await
.unwrap();
registry
.publish_operation(PublishRequest {
workspace_id: &test_workspace_id(),
operation_id: &operation.id,
version: 1,
published_at: &OffsetDateTime::parse("2026-03-26T10:00:00Z", &Rfc3339).unwrap(),
published_by: Some("alice"),
})
.await
.unwrap();
publish_agent_for_operation(&registry, &operation, "sales-gated").await;
let api_key = create_platform_api_key(
&registry,
"sales-gated",
"mcp-gated",
&[PlatformApiKeyScope::Read, PlatformApiKeyScope::Write],
)
.await;
let approval_key =
create_approval_platform_api_key(&registry, "sales-gated", "approval-gated").await;
let base_url = spawn_mcp_server(build_test_app(
registry,
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let mcp_url = agent_mcp_url(&base_url, "sales-gated");
let initialized_session = initialize_session(&client, &mcp_url, &api_key).await;
let tool_result = post_jsonrpc(
&client,
&mcp_url,
&api_key,
Some(&initialized_session),
json!({
"jsonrpc": "2.0",
"id": 9,
"method": "tools/call",
"params": {
"name": "crm_requires_human_approval",
"arguments": {
"email": "ada@example.com"
}
}
}),
)
.await;
assert_eq!(
tool_result["result"]["structuredContent"]["status"],
"approval_required"
);
assert_eq!(tool_result["result"]["isError"], false);
let approval_id = tool_result["result"]["structuredContent"]["approval_id"]
.as_str()
.unwrap();
assert!(approval_id.starts_with("approval_"));
let approvals_url = format!("{}/approvals", agent_mcp_url(&base_url, "sales-gated"));
let pending = client
.get(&approvals_url)
.header(header::AUTHORIZATION, format!("Bearer {approval_key}"))
.send()
.await
.unwrap()
.json::<Value>()
.await
.unwrap();
assert_eq!(pending["items"].as_array().unwrap().len(), 1);
assert_eq!(pending["items"][0]["approval"]["id"], approval_id);
assert_eq!(
pending["items"][0]["approval"]["request_payload"]["email"],
"ada@example.com"
);
}
#[tokio::test]
async fn elicitation_approval_requires_client_capability() {
let registry = test_registry().await;
let upstream_base_url = spawn_upstream_server().await;
let mut operation = test_operation(&upstream_base_url, "crm_requires_elicitation");
operation.execution_config.approval_policy = Some(OperationApprovalPolicy {
required: true,
mode: OperationApprovalMode::Elicitation,
risk_level: OperationApprovalRiskLevel::Normal,
ttl_seconds: 300,
show_payload_preview: true,
payload_preview_mode: OperationApprovalPayloadPreviewMode::MaskedJson,
elicitation_message: Some("Подтвердите создание лида.".to_owned()),
});
registry
.create_operation(&test_workspace_id(), &operation, Some("alice"))
.await
.unwrap();
registry
.publish_operation(PublishRequest {
workspace_id: &test_workspace_id(),
operation_id: &operation.id,
version: 1,
published_at: &OffsetDateTime::now_utc(),
published_by: Some("alice"),
})
.await
.unwrap();
publish_agent_with_bindings(
&registry,
"sales-elicitation-no-capability",
vec![binding_for_operation(&operation)],
)
.await;
let api_key = create_platform_api_key(
&registry,
"sales-elicitation-no-capability",
"mcp-elicitation-no-capability",
&[PlatformApiKeyScope::Read, PlatformApiKeyScope::Write],
)
.await;
let base_url = spawn_mcp_server(build_test_app(
registry.clone(),
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let mcp_url = agent_mcp_url(&base_url, "sales-elicitation-no-capability");
let initialized_session = initialize_session(&client, &mcp_url, &api_key).await;
let tool_result = post_jsonrpc(
&client,
&mcp_url,
&api_key,
Some(&initialized_session),
json!({
"jsonrpc": "2.0",
"id": 7,
"method": "tools/call",
"params": {
"name": "crm_requires_elicitation",
"arguments": {
"email": "ada@example.com"
}
}
}),
)
.await;
assert_eq!(tool_result["result"]["isError"], true);
assert_eq!(
tool_result["result"]["structuredContent"]["error"]["code"],
"approval_elicitation_not_supported"
);
}
#[tokio::test]
async fn elicitation_approval_uses_session_capability_without_approval_key() {
let registry = test_registry().await;
let upstream_base_url = spawn_upstream_server().await;
let mut operation = test_operation(&upstream_base_url, "crm_requires_elicitation_supported");
operation.execution_config.approval_policy = Some(OperationApprovalPolicy {
required: true,
mode: OperationApprovalMode::Elicitation,
risk_level: OperationApprovalRiskLevel::Normal,
ttl_seconds: 300,
show_payload_preview: true,
payload_preview_mode: OperationApprovalPayloadPreviewMode::MaskedJson,
elicitation_message: Some("Подтвердите создание лида.".to_owned()),
});
registry
.create_operation(&test_workspace_id(), &operation, Some("alice"))
.await
.unwrap();
registry
.publish_operation(PublishRequest {
workspace_id: &test_workspace_id(),
operation_id: &operation.id,
version: 1,
published_at: &OffsetDateTime::now_utc(),
published_by: Some("alice"),
})
.await
.unwrap();
publish_agent_with_bindings(
&registry,
"sales-elicitation-supported",
vec![binding_for_operation(&operation)],
)
.await;
let api_key = create_platform_api_key(
&registry,
"sales-elicitation-supported",
"mcp-elicitation-supported",
&[PlatformApiKeyScope::Read, PlatformApiKeyScope::Write],
)
.await;
let base_url = spawn_mcp_server(build_test_app(
registry.clone(),
Duration::from_millis(0),
Some("https://crank.example.com".to_owned()),
))
.await;
let client = reqwest::Client::new();
let mcp_url = agent_mcp_url(&base_url, "sales-elicitation-supported");
let initialized_session = initialize_session_with_capabilities(
&client,
&mcp_url,
&api_key,
json!({ "elicitation": {} }),
)
.await;
let tool_result = post_jsonrpc(
&client,
&mcp_url,
&api_key,
Some(&initialized_session),
json!({
"jsonrpc": "2.0",
"id": 8,
"method": "tools/call",
"params": {
"name": "crm_requires_elicitation_supported",
"arguments": {
"email": "ada@example.com"
}
}
}),
)
.await;
assert_eq!(tool_result["result"]["isError"], false);
assert_eq!(
tool_result["result"]["structuredContent"]["status"],
"elicitation_required"
);
assert_eq!(
tool_result["result"]["structuredContent"]["message"],
"Подтвердите создание лида."
);
assert_eq!(
tool_result["result"]["structuredContent"]["payload_preview"]["email"],
"ada@example.com"
);
}
+62 -5
View File
@@ -16,8 +16,9 @@ use axum::{
use base64::{Engine as _, engine::general_purpose::URL_SAFE_NO_PAD};
use crank_core::{
Agent, AgentId, AgentOperationBinding, AgentStatus, AgentVersion, ExecutionConfig, HttpMethod,
Operation, OperationId, OperationStatus, PlatformApiKey, PlatformApiKeyId, PlatformApiKeyScope,
PlatformApiKeyStatus, Protocol, RestTarget, Target, ToolDescription, WorkspaceId,
Operation, OperationId, OperationStatus, PlatformApiKey, PlatformApiKeyId, PlatformApiKeyKind,
PlatformApiKeyScope, PlatformApiKeyStatus, Protocol, RestTarget, Target, ToolDescription,
WorkspaceId,
};
use crank_mapping::{MappingRule, MappingSet};
use crank_registry::{
@@ -134,7 +135,10 @@ fn build_test_app_with_store(
refresh_interval,
public_base_url,
SecretCrypto::new("test-master-key").unwrap(),
RuntimeExecutor::new(),
crank_runtime::community_with_outbound_policy(
crank_runtime::OutboundHttpPolicy::allowing_hosts(["127.0.0.1"]),
)
.build(),
RequestRateLimiter::new(rate_limit_config),
std::sync::Arc::new(InMemoryCoordinationStateStore::default()),
sessions,
@@ -146,6 +150,15 @@ pub(super) async fn initialize_session(
client: &reqwest::Client,
mcp_url: &str,
api_key: &str,
) -> String {
initialize_session_with_capabilities(client, mcp_url, api_key, json!({})).await
}
pub(super) async fn initialize_session_with_capabilities(
client: &reqwest::Client,
mcp_url: &str,
api_key: &str,
capabilities: Value,
) -> String {
let initialize_response = client
.post(mcp_url)
@@ -156,7 +169,8 @@ pub(super) async fn initialize_session(
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-11-25"
"protocolVersion": "2025-11-25",
"capabilities": capabilities
}
}))
.send()
@@ -236,17 +250,59 @@ pub(super) async fn create_platform_api_key(
name: &str,
scopes: &[PlatformApiKeyScope],
) -> String {
let secret = format!("crk_{}_{}", name, uuid::Uuid::now_v7().simple());
create_platform_api_key_with_kind(
registry,
agent_slug,
name,
PlatformApiKeyKind::McpClient,
scopes,
"crk",
)
.await
}
pub(super) async fn create_approval_platform_api_key(
registry: &PostgresRegistry,
agent_slug: &str,
name: &str,
) -> String {
create_platform_api_key_with_kind(
registry,
agent_slug,
name,
PlatformApiKeyKind::Approval,
&[
PlatformApiKeyScope::ReadPending,
PlatformApiKeyScope::Approve,
PlatformApiKeyScope::Deny,
],
"crk_appr",
)
.await
}
async fn create_platform_api_key_with_kind(
registry: &PostgresRegistry,
agent_slug: &str,
name: &str,
key_kind: PlatformApiKeyKind,
scopes: &[PlatformApiKeyScope],
prefix: &str,
) -> String {
let secret = format!("{prefix}_{}_{}", name, uuid::Uuid::now_v7().simple());
let api_key = PlatformApiKey {
id: PlatformApiKeyId::new(format!("pk_{name}")),
workspace_id: test_workspace_id(),
agent_id: Some(test_agent_id(agent_slug)),
key_kind,
name: name.to_owned(),
prefix: secret.chars().take(16).collect(),
scopes: scopes.to_vec(),
status: PlatformApiKeyStatus::Active,
created_at: OffsetDateTime::parse("2026-03-26T10:00:00Z", &Rfc3339).unwrap(),
last_used_at: None,
expires_at: None,
allowed_origins: Vec::new(),
};
registry
@@ -444,6 +500,7 @@ pub(super) fn test_operation(base_url: &str, name: &str) -> Operation<Schema, Ma
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
},
@@ -136,7 +136,10 @@ fn build_test_app_with_store(
refresh_interval,
public_base_url,
SecretCrypto::new("test-master-key").unwrap(),
RuntimeExecutor::new(),
crank_runtime::community_with_outbound_policy(
crank_runtime::OutboundHttpPolicy::allowing_hosts(["127.0.0.1"]),
)
.build(),
RequestRateLimiter::new(rate_limit_config),
std::sync::Arc::new(InMemoryCoordinationStateStore::default()),
sessions,
@@ -689,6 +692,7 @@ async fn get_returns_not_found_for_expired_transport_session() {
"2025-11-25",
test_workspace_slug(),
"sales-expired-session",
false,
OffsetDateTime::parse("2026-05-01T10:00:00Z", &Rfc3339).unwrap(),
Some(OffsetDateTime::parse("2026-05-01T10:00:01Z", &Rfc3339).unwrap()),
)
+97
View File
@@ -0,0 +1,97 @@
/* Local font assets are copied from pinned @fontsource packages during the UI build. */
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 400;
src: url('../fonts/inter-cyrillic-400-normal.woff2') format('woff2');
unicode-range: U+0301,U+0400-045F,U+0490-0491,U+04B0-04B1,U+2116;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 400;
src: url('../fonts/inter-latin-400-normal.woff2') format('woff2');
unicode-range: U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 500;
src: url('../fonts/inter-cyrillic-500-normal.woff2') format('woff2');
unicode-range: U+0301,U+0400-045F,U+0490-0491,U+04B0-04B1,U+2116;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 500;
src: url('../fonts/inter-latin-500-normal.woff2') format('woff2');
unicode-range: U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 600;
src: url('../fonts/inter-cyrillic-600-normal.woff2') format('woff2');
unicode-range: U+0301,U+0400-045F,U+0490-0491,U+04B0-04B1,U+2116;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 600;
src: url('../fonts/inter-latin-600-normal.woff2') format('woff2');
unicode-range: U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 700;
src: url('../fonts/inter-cyrillic-700-normal.woff2') format('woff2');
unicode-range: U+0301,U+0400-045F,U+0490-0491,U+04B0-04B1,U+2116;
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-display: swap;
font-weight: 700;
src: url('../fonts/inter-latin-700-normal.woff2') format('woff2');
unicode-range: U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD;
}
@font-face {
font-family: 'JetBrains Mono';
font-style: normal;
font-display: swap;
font-weight: 400;
src: url('../fonts/jetbrains-mono-cyrillic-400-normal.woff2') format('woff2');
unicode-range: U+0301,U+0400-045F,U+0490-0491,U+04B0-04B1,U+2116;
}
@font-face {
font-family: 'JetBrains Mono';
font-style: normal;
font-display: swap;
font-weight: 400;
src: url('../fonts/jetbrains-mono-latin-400-normal.woff2') format('woff2');
unicode-range: U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD;
}
@font-face {
font-family: 'JetBrains Mono';
font-style: normal;
font-display: swap;
font-weight: 500;
src: url('../fonts/jetbrains-mono-cyrillic-500-normal.woff2') format('woff2');
unicode-range: U+0301,U+0400-045F,U+0490-0491,U+04B0-04B1,U+2116;
}
@font-face {
font-family: 'JetBrains Mono';
font-style: normal;
font-display: swap;
font-weight: 500;
src: url('../fonts/jetbrains-mono-latin-500-normal.woff2') format('woff2');
unicode-range: U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD;
}
+1 -1
View File
@@ -246,7 +246,7 @@ body.page-leaving .ws-setup-body {
.mobile-nav-link.active { color: var(--text-primary); background: var(--bg-overlay); }
/* ── Responsive breakpoints ── */
@media (max-width: 720px) {
@media (max-width: 980px) {
.navbar { padding: 0 16px; }
.nav-links { display: none; }
.nav-hamburger { display: flex; }
+185
View File
@@ -134,3 +134,188 @@
}
.refresh-btn:hover { color: var(--text-secondary); background: var(--bg-muted); }
.approval-panel {
margin-bottom: 18px;
}
.approval-panel-header {
display: flex;
align-items: center;
justify-content: space-between;
gap: 16px;
padding: 16px 20px;
border-bottom: 1px solid var(--border-subtle);
}
.approval-panel-title {
font-size: 15px;
font-weight: 650;
color: var(--text-primary);
}
.approval-panel-subtitle {
margin-top: 4px;
font-size: 12.5px;
line-height: 1.45;
color: var(--text-muted);
}
.approval-refresh-btn {
margin-left: 0;
}
.approval-list {
display: grid;
gap: 12px;
padding: 16px 20px 20px;
}
.approval-empty {
padding: 20px;
border: 1px dashed var(--border);
border-radius: 10px;
background: var(--bg-canvas);
color: var(--text-muted);
font-size: 13px;
}
.approval-empty-error {
border-color: rgba(248, 81, 73, 0.35);
color: var(--red);
}
.approval-item {
border: 1px solid var(--border);
border-radius: 12px;
background: var(--bg-canvas);
padding: 14px;
}
.approval-pending {
border-color: rgba(210, 153, 34, 0.45);
background: linear-gradient(180deg, rgba(210, 153, 34, 0.08), var(--bg-canvas) 46%);
}
.approval-completed {
border-color: rgba(63, 185, 80, 0.28);
}
.approval-failed,
.approval-denied,
.approval-expired {
border-color: rgba(248, 81, 73, 0.26);
}
.approval-item-header {
display: flex;
align-items: flex-start;
justify-content: space-between;
gap: 12px;
}
.approval-item-title {
font-size: 14px;
font-weight: 650;
color: var(--text-primary);
}
.approval-item-meta,
.approval-timing,
.approval-note {
margin-top: 5px;
font-size: 11.5px;
color: var(--text-muted);
}
.approval-item-body {
margin: 10px 0 0;
font-size: 13px;
line-height: 1.55;
color: var(--text-secondary);
}
.approval-status {
flex-shrink: 0;
border: 1px solid var(--border);
border-radius: 999px;
padding: 3px 9px;
font-size: 11px;
font-weight: 700;
text-transform: uppercase;
letter-spacing: 0.35px;
color: var(--text-muted);
background: var(--bg-overlay);
}
.approval-status-pending {
color: var(--amber);
border-color: rgba(210, 153, 34, 0.45);
background: rgba(210, 153, 34, 0.1);
}
.approval-status-completed {
color: var(--green);
border-color: rgba(63, 185, 80, 0.35);
background: rgba(63, 185, 80, 0.1);
}
.approval-status-denied,
.approval-status-expired,
.approval-status-failed {
color: var(--red);
border-color: rgba(248, 81, 73, 0.35);
background: rgba(248, 81, 73, 0.09);
}
.approval-payload-grid {
display: grid;
gap: 10px;
grid-template-columns: repeat(auto-fit, minmax(220px, 1fr));
margin-top: 12px;
}
.approval-payload-label {
margin-bottom: 5px;
font-size: 10.5px;
font-weight: 700;
letter-spacing: 0.45px;
text-transform: uppercase;
color: var(--text-muted);
}
.approval-payload-code {
margin: 0;
max-height: 180px;
overflow: auto;
border: 1px solid var(--border-subtle);
border-radius: 8px;
background: #161b22;
padding: 10px;
color: #c9d1d9;
font-family: 'JetBrains Mono', monospace;
font-size: 11.5px;
line-height: 1.55;
white-space: pre-wrap;
word-break: break-word;
}
@media (max-width: 720px) {
.approval-panel-header {
align-items: stretch;
flex-direction: column;
}
.approval-refresh-btn {
justify-content: center;
}
.approval-item-header {
align-items: stretch;
flex-direction: column;
}
.approval-status {
align-self: flex-start;
}
}
+69 -20
View File
@@ -12,28 +12,36 @@
.openapi-import-modal {
position: fixed;
inset: 0;
z-index: 1200;
z-index: 2400;
display: flex;
align-items: flex-start;
justify-content: center;
padding: 28px 16px;
overflow: auto;
isolation: isolate;
}
.openapi-import-backdrop {
position: absolute;
position: fixed;
inset: 0;
background: rgba(15, 23, 42, 0.52);
backdrop-filter: blur(5px);
z-index: 0;
background: rgba(1, 4, 9, 0.82);
backdrop-filter: blur(8px);
}
.openapi-import-dialog {
position: relative;
z-index: 1;
width: min(1040px, calc(100vw - 32px));
max-height: min(860px, calc(100vh - 32px));
margin: 16px auto;
max-height: calc(100vh - 56px);
margin: 0 auto;
display: flex;
flex-direction: column;
overflow: hidden;
border: 1px solid var(--border);
border-radius: 22px;
background: var(--surface);
box-shadow: 0 24px 80px rgba(15, 23, 42, 0.28);
background: var(--bg-canvas);
box-shadow: 0 24px 80px rgba(0, 0, 0, 0.6);
}
.openapi-import-header {
@@ -42,6 +50,7 @@
gap: 18px;
padding: 22px 24px;
border-bottom: 1px solid var(--border);
background: var(--bg-canvas);
}
.openapi-import-header h2 {
@@ -58,11 +67,16 @@
.openapi-import-body {
overflow: auto;
padding: 20px 24px 24px;
background: var(--bg-canvas);
}
.openapi-import-upload {
display: grid;
gap: 12px;
padding: 16px;
border: 1px solid var(--border-subtle);
border-radius: 16px;
background: var(--bg-surface);
}
.openapi-file-label {
@@ -74,18 +88,53 @@
}
#openapi-import-document {
min-height: 180px;
min-height: 132px;
max-height: 34vh;
resize: vertical;
padding: 14px;
border: 1px solid var(--border);
border-radius: 14px;
background: var(--surface-muted);
background: #0d1117;
color: var(--text-primary);
font-family: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
font-size: 12px;
line-height: 1.55;
}
#openapi-import-file {
position: absolute;
width: 1px;
height: 1px;
overflow: hidden;
clip: rect(0 0 0 0);
clip-path: inset(50%);
white-space: nowrap;
}
.openapi-file-control {
display: flex;
align-items: center;
gap: 10px;
min-width: 0;
}
.openapi-file-button {
display: inline-flex;
align-items: center;
justify-content: center;
min-height: 32px;
cursor: pointer;
}
.openapi-file-name {
overflow: hidden;
color: var(--text-muted);
font-size: 13px;
font-weight: 500;
text-overflow: ellipsis;
white-space: nowrap;
}
.openapi-import-actions,
.openapi-import-footer {
display: flex;
@@ -115,7 +164,7 @@
.openapi-import-group {
border: 1px solid var(--border);
border-radius: 16px;
background: var(--surface-muted);
background: var(--bg-overlay);
}
.openapi-import-source {
@@ -144,7 +193,7 @@
padding: 10px 12px;
border: 1px solid var(--border);
border-radius: 12px;
background: var(--surface);
background: var(--bg-surface);
color: var(--text-primary);
}
@@ -156,7 +205,7 @@
padding: 14px 16px;
border: 1px solid var(--border);
border-radius: 16px;
background: var(--surface-muted);
background: var(--bg-overlay);
}
.openapi-import-filter {
@@ -174,7 +223,7 @@
#openapi-import-method-filter {
width: 100%;
max-width: none;
background: var(--surface);
background: var(--bg-surface);
}
.openapi-import-bulk-actions {
@@ -242,7 +291,7 @@
.openapi-import-method {
padding: 4px 8px;
border-radius: 999px;
background: var(--accent-muted);
background: var(--accent-glow);
color: var(--accent);
font-size: 11px;
font-weight: 800;
@@ -282,7 +331,7 @@
padding: 10px 12px;
border: 1px solid var(--border);
border-radius: 12px;
background: var(--surface);
background: var(--bg-surface);
}
.openapi-import-mapping-group {
@@ -304,7 +353,7 @@
padding: 3px 7px;
border: 1px solid var(--border);
border-radius: 999px;
background: var(--surface-muted);
background: var(--bg-overlay);
color: var(--text-primary);
font-size: 11px;
}
@@ -322,7 +371,7 @@
padding: 14px 16px;
border: 1px solid var(--border);
border-radius: 16px;
background: var(--surface-muted);
background: var(--bg-overlay);
color: var(--text-secondary);
font-size: 13px;
}
@@ -347,7 +396,7 @@
overflow: hidden;
border: 1px solid var(--border);
border-radius: 14px;
background: var(--surface);
background: var(--bg-surface);
}
.openapi-import-result-row {
@@ -369,7 +418,7 @@
font-weight: 900;
text-transform: uppercase;
letter-spacing: 0.04em;
background: var(--surface-muted);
background: var(--bg-overlay);
}
.openapi-import-result-name {
+210 -2
View File
@@ -202,6 +202,7 @@
display: grid;
grid-template-columns:
minmax(130px, 1fr)
24px
minmax(105px, 0.65fr)
minmax(130px, 1fr)
minmax(120px, 0.8fr)
@@ -216,14 +217,62 @@
}
.response-mapping-row {
grid-template-columns: minmax(160px, 1fr) minmax(140px, 1fr) 34px;
grid-template-columns: minmax(160px, 1fr) 24px minmax(140px, 1fr) 34px;
}
.mapping-field {
display: grid;
gap: 5px;
min-width: 0;
}
.mapping-field-label {
color: var(--text-muted);
font-size: 10.5px;
font-weight: 800;
letter-spacing: 0.04em;
line-height: 1;
text-transform: uppercase;
}
.mapping-arrow {
display: inline-flex;
align-items: center;
justify-content: center;
align-self: end;
width: 24px;
height: 34px;
color: var(--accent);
font-size: 18px;
font-weight: 900;
line-height: 1;
}
.mapping-default-value {
border-style: dashed;
}
.mapping-row-remove {
width: 32px;
height: 32px;
display: inline-flex;
align-items: center;
justify-content: center;
border: 1px solid var(--red-border);
border-radius: 8px;
background: var(--red-bg);
color: var(--red);
font-size: 18px;
line-height: 1;
font-weight: 800;
transition: background 0.15s, border-color 0.15s, color 0.15s, transform 0.15s;
}
.mapping-row-remove:hover {
border-color: rgba(248, 81, 73, 0.45);
background: rgba(248, 81, 73, 0.16);
color: #ff7b72;
transform: translateY(-1px);
}
.mapping-builder-actions {
@@ -315,6 +364,12 @@
grid-template-columns: 1fr;
}
.mapping-arrow {
width: 100%;
height: 18px;
transform: rotate(90deg);
}
.mapping-row-remove {
width: 100%;
}
@@ -412,7 +467,11 @@
cursor: pointer;
position: relative;
z-index: 1;
transition: background 0.15s;
text-align: left;
transition:
background 0.15s,
border-color 0.15s,
box-shadow 0.15s;
border: 1px solid transparent;
}
@@ -1058,6 +1117,31 @@
.toggle-label { font-size: 13px; font-weight: 500; color: var(--text-primary); }
.toggle-desc { font-size: 11.5px; color: var(--text-muted); margin-top: 1px; }
.approval-toggle-row {
position: relative;
}
.approval-toggle-input {
position: absolute;
opacity: 0;
pointer-events: none;
}
.approval-config-fields {
display: grid;
gap: 16px;
padding: 16px;
border: 1px solid var(--border-subtle);
border-radius: 10px;
background: rgba(13, 17, 23, 0.42);
}
.approval-preview-pill {
align-self: end;
min-height: 38px;
justify-content: center;
}
/*
BOTTOM ACTION BAR frosted dark glass
*/
@@ -1250,6 +1334,18 @@
box-shadow: none !important;
}
.form-group > .code-textarea {
border: 1px solid var(--border) !important;
border-radius: 8px !important;
background: #0d1117 !important;
box-shadow: inset 0 0 0 1px rgba(255, 255, 255, 0.015);
}
.form-group > .code-textarea:focus {
border-color: var(--accent) !important;
box-shadow: 0 0 0 3px var(--accent-ring), inset 0 0 0 1px rgba(255, 255, 255, 0.02) !important;
}
/* ── Section divider ── */
.section-divider {
display: flex;
@@ -1732,6 +1828,118 @@
cursor: wait;
}
@media (max-width: 900px) {
.progress-strip {
padding: 0 16px;
gap: 12px;
}
.wizard-body {
display: grid;
padding: 24px 16px 120px;
}
.step-sidebar {
position: static;
width: auto;
flex-basis: auto;
}
.step-sidebar-card {
border-radius: 10px;
}
.step-sidebar-header {
padding: 14px 16px 12px;
}
.steps-list {
display: grid;
grid-template-columns: repeat(5, minmax(0, 1fr));
gap: 8px;
}
.steps-list::before {
left: calc((100% - 32px) / 10);
right: calc((100% - 32px) / 10);
top: 27px;
bottom: auto;
width: auto;
height: 1px;
}
.step-item {
display: grid;
justify-items: center;
align-content: start;
gap: 8px;
min-height: 96px;
padding: 10px 6px 9px;
text-align: center;
}
.sidebar-help {
display: none;
}
.step-content {
width: 100%;
padding-top: 0;
}
.step-number {
margin-bottom: 3px;
font-size: 9.5px;
}
.step-name {
display: -webkit-box;
min-height: 28px;
overflow: hidden;
white-space: normal;
-webkit-line-clamp: 2;
-webkit-box-orient: vertical;
font-size: 11px;
line-height: 1.25;
}
.step-status-text {
margin-top: 3px;
font-size: 10px;
line-height: 1.2;
}
.action-bar-inner {
padding: 0 16px;
}
}
@media (max-width: 560px) {
.progress-label,
.progress-pct,
.btn-save-draft,
.step-counter {
display: none;
}
.step-item {
min-height: 88px;
padding: 9px 4px 8px;
}
.step-number {
font-size: 9px;
}
.step-name {
font-size: 10px;
}
.step-status-text {
font-size: 9.5px;
}
}
/*
HTTP method picker (Step 4 REST)
*/
+5
View File
@@ -37,7 +37,11 @@
color: var(--text-muted);
text-decoration: none;
padding: 6px 10px;
border: 0;
background: none;
border-radius: 6px;
font-family: inherit;
cursor: pointer;
transition: color 0.15s, background 0.15s;
}
.ws-setup-back:hover { color: var(--text-secondary); background: rgba(255,255,255,0.04); }
@@ -107,6 +111,7 @@
.ws-color-swatch {
width: 20px;
height: 20px;
padding: 0;
border-radius: 5px;
cursor: pointer;
border: 2px solid transparent;
+4 -4
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Agents</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
@@ -49,12 +49,12 @@
<div class="user-dropdown-name">Crank</div>
<div class="user-dropdown-role" id="user-ws-role"></div>
</div>
<button class="user-dropdown-item" onclick="window.location.href='/settings'">
<a class="user-dropdown-item" href="/settings">
<svg width="13" height="13"><use href="icons/general/settings.svg#icon"/></svg>
<span data-i18n="nav.settings">Settings</span>
</button>
</a>
<div class="dropdown-divider"></div>
<button class="user-dropdown-item danger" onclick="window.CrankAuth.logout()">
<button class="user-dropdown-item danger" @click="window.CrankAuth.logout()">
<svg width="13" height="13"><use href="icons/general/logout.svg#icon"/></svg>
<span data-i18n="nav.logout">Log out</span>
</button>
+87 -26
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Agent Keys</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
@@ -23,9 +23,75 @@
.scope-checkbox-name { font-size: 13px; font-weight: 500; color: var(--text-primary); }
.scope-checkbox-desc { font-size: 11.5px; color: var(--text-muted); }
.keys-card-list { display: none; }
.key-kind-tabs {
display: inline-flex;
gap: 4px;
padding: 4px;
border: 1px solid var(--border);
border-radius: var(--radius-lg);
background: var(--bg-overlay);
}
.key-kind-tab {
border: 0;
border-radius: var(--radius);
background: transparent;
color: var(--text-secondary);
padding: 7px 12px;
font-size: 13px;
font-weight: 600;
}
.key-kind-tab.active {
background: var(--accent);
color: #fff;
}
.key-kind-header-control {
display: grid;
grid-template-columns: auto auto;
align-items: center;
gap: 10px;
justify-content: space-between;
width: 100%;
}
.key-kind-header-hint {
grid-column: 1 / -1;
max-width: 520px;
margin: 0;
text-align: left;
}
.api-keys-page-header {
display: grid;
grid-template-columns: 1fr;
gap: 14px;
}
.api-keys-page-header .page-header-text {
max-width: 680px;
}
.api-keys-page-header .page-header-actions {
width: 100%;
}
.approval-warning-callout {
display: flex;
gap: 10px;
padding: 12px 14px;
border: 1px solid var(--amber-border);
border-radius: var(--radius-lg);
background: var(--amber-bg);
color: var(--text-primary);
font-size: 13px;
line-height: 1.55;
}
.approval-warning-callout svg {
color: var(--amber);
flex: 0 0 auto;
margin-top: 2px;
}
@media (max-width: 720px) {
#keys-table-wrap { display: none; }
.keys-card-list { display: grid; }
.key-kind-header-control { grid-template-columns: 1fr; justify-content: stretch; width: 100%; }
.key-kind-tabs { width: 100%; }
.key-kind-tab { flex: 1; }
.key-kind-header-hint { text-align: left; }
}
</style>
<script src="%CRANK_BUNDLE_PROTECTED_CORE%"></script>
@@ -94,16 +160,23 @@
<!-- ═══════════════════ PAGE ═══════════════════ -->
<div class="page">
<div class="page-header">
<div class="page-header api-keys-page-header">
<div class="page-header-text">
<h1 class="page-title" data-i18n="apikeys.title">Agent Keys</h1>
<p class="page-subtitle" data-i18n="apikeys.subtitle">These keys connect an MCP client to the MCP server and are issued for a specific agent.</p>
</div>
<div class="page-header-actions">
<button class="btn-primary" id="btn-create-key" type="button">
<svg width="13" height="13" viewBox="0 0 16 16" fill="currentColor"><path d="M7.75 2a.75.75 0 01.75.75V7h4.25a.75.75 0 010 1.5H8.5v4.25a.75.75 0 01-1.5 0V8.5H2.75a.75.75 0 010-1.5H7V2.75A.75.75 0 017.75 2z"/></svg>
<span data-i18n="apikeys.new">Create key</span>
</button>
<div class="key-kind-header-control">
<div class="key-kind-tabs" role="tablist" aria-label="Key type">
<button class="key-kind-tab active" id="key-kind-mcp-client" type="button" data-key-kind="mcp_client" data-i18n="apikeys.kind.mcp">MCP clients</button>
<button class="key-kind-tab" id="key-kind-approval" type="button" data-key-kind="approval" data-i18n="apikeys.kind.approval">Approvals</button>
</div>
<button class="btn-primary" id="btn-create-key" type="button">
<svg width="13" height="13" viewBox="0 0 16 16" fill="currentColor"><path d="M7.75 2a.75.75 0 01.75.75V7h4.25a.75.75 0 010 1.5H8.5v4.25a.75.75 0 01-1.5 0V8.5H2.75a.75.75 0 010-1.5H7V2.75A.75.75 0 017.75 2z"/></svg>
<span id="btn-create-key-label" data-i18n="apikeys.new">Create key</span>
</button>
<div class="field-hint key-kind-header-hint" id="key-kind-hint"></div>
</div>
</div>
</div>
@@ -170,25 +243,7 @@
<div class="section-card-header">
<div class="section-card-title" data-i18n="apikeys.scope_ref">Access reference</div>
</div>
<div class="section-card-body" style="display:grid;grid-template-columns:repeat(3,1fr);gap:12px;">
<div>
<div style="font-size:12.5px;font-weight:600;color:var(--text-primary);margin-bottom:4px;display:flex;align-items:center;gap:6px;">
<span class="badge badge-scope">read</span>
</div>
<div style="font-size:12px;color:var(--text-muted);line-height:1.55;" data-i18n="apikeys.scope.read">Initialize MCP sessions, ping the server, and list tools for a workspace agent.</div>
</div>
<div>
<div style="font-size:12.5px;font-weight:600;color:var(--text-primary);margin-bottom:4px;">
<span class="badge badge-scope">write</span>
</div>
<div style="font-size:12px;color:var(--text-muted);line-height:1.55;" data-i18n="apikeys.scope.write">Execute `tools/call` requests against published agent toolsets.</div>
</div>
<div>
<div style="font-size:12.5px;font-weight:600;color:var(--text-primary);margin-bottom:4px;">
<span class="badge badge-scope">deploy</span>
</div>
<div style="font-size:12px;color:var(--text-muted);line-height:1.55;" data-i18n="apikeys.scope.deploy">Reserved for deploy-scoped automation. Today it also permits MCP read/write flows.</div>
</div>
<div class="section-card-body" id="scope-reference-grid" style="display:grid;grid-template-columns:repeat(3,1fr);gap:12px;">
</div>
</div>
@@ -198,7 +253,7 @@
<div class="modal-overlay" id="modal-create">
<div class="modal">
<div class="modal-header">
<span class="modal-title" data-i18n="apikeys.modal.title">Create agent key</span>
<span class="modal-title" id="modal-create-title" data-i18n="apikeys.modal.title">Create agent key</span>
<button class="modal-close" id="modal-close-btn" type="button">
<svg width="12" height="12" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round">
<line x1="1" y1="1" x2="11" y2="11"/><line x1="11" y1="1" x2="1" y2="11"/>
@@ -211,6 +266,12 @@
<input class="field-input" id="new-key-name" type="text" data-i18n-ph="apikeys.modal.name_placeholder" placeholder="e.g. Production, CI pipeline" autocomplete="off">
<div class="field-hint" data-i18n="apikeys.modal.name_hint">A descriptive label to identify the key. Only visible to admins.</div>
</div>
<div class="approval-warning-callout" id="approval-key-warning" hidden>
<svg width="15" height="15" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round">
<polygon points="8,1.5 15.5,14.5 0.5,14.5" fill="none"/><path d="M8 6v4M8 11.5v.5"/>
</svg>
<div data-i18n="apikeys.approval.warning">Do not pass this key to an LLM or MCP client. It is only for an external interface where a human confirms an action.</div>
</div>
<div class="field-group" style="margin-bottom:0;">
<label class="field-label" data-i18n="apikeys.modal.scopes">Access</label>
<div style="display:flex;flex-direction:column;gap:8px;margin-top:2px;" id="scope-checkboxes">
+2 -2
View File
@@ -1,11 +1,11 @@
<div class="field-group" style="margin-top:8px;">
<label class="field-label">Interface language</label>
<div class="lang-switcher" style="display:flex;gap:6px;margin-top:6px;">
<button class="lang-btn" data-lang="en" onclick="setLang('en')">
<button class="lang-btn" data-lang="en">
<span class="lang-flag">🇬🇧</span>
<span data-i18n="settings.lang.en">English</span>
</button>
<button class="lang-btn" data-lang="ru" onclick="setLang('ru')">
<button class="lang-btn" data-lang="ru">
<span class="lang-flag">🇷🇺</span>
<span data-i18n="settings.lang.ru">Русский</span>
</button>
+1 -1
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Sign in</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/login.css">
<script src="%CRANK_BUNDLE_LOGIN%"></script>
+15 -1
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Logs</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
@@ -78,6 +78,20 @@
</div>
</div>
<div class="section-card approval-panel">
<div class="approval-panel-header">
<div>
<div class="approval-panel-title" data-i18n="approvals.title">Human confirmations</div>
<div class="approval-panel-subtitle" data-i18n="approvals.subtitle">Requests waiting for an external user decision and recent results.</div>
</div>
<button class="refresh-btn approval-refresh-btn" id="approval-refresh-btn" type="button">
<svg width="12" height="12" viewBox="0 0 16 16" fill="currentColor"><path d="M1.705 8.005a.75.75 0 01.834.656 5.5 5.5 0 009.592 2.97l-1.204-1.204a.25.25 0 01.177-.427h3.646a.25.25 0 01.25.25v3.646a.25.25 0 01-.427.177l-1.38-1.38A7.001 7.001 0 011.05 8.84a.75.75 0 01.656-.834zM8 2.5a5.487 5.487 0 00-4.131 1.869l1.204 1.204A.25.25 0 014.896 6H1.25A.25.25 0 011 5.75V2.104a.25.25 0 01.427-.177l1.38 1.38A7.001 7.001 0 0114.95 7.16a.75.75 0 01-1.49.178A5.501 5.501 0 008 2.5z"/></svg>
<span data-i18n="approvals.refresh">Refresh</span>
</button>
</div>
<div class="approval-list" id="approval-list"></div>
</div>
<div class="section-card">
<div class="log-toolbar">
<div class="live-dot"></div>
+1 -1
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Secrets</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
+3 -3
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Settings</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
@@ -172,11 +172,11 @@
<label class="field-label" data-i18n="settings.lang.title">Language</label>
<div class="field-hint" data-i18n="settings.lang.subtitle">Interface display language</div>
<div class="lang-switcher">
<button class="lang-btn" data-lang="en" type="button" onclick="setLang('en')">
<button class="lang-btn" data-lang="en" type="button">
<span class="lang-flag">🇬🇧</span>
<span data-i18n="settings.lang.en">English</span>
</button>
<button class="lang-btn" data-lang="ru" type="button" onclick="setLang('ru')">
<button class="lang-btn" data-lang="ru" type="button">
<span class="lang-flag">🇷🇺</span>
<span data-i18n="settings.lang.ru">Русский</span>
</button>
+1 -1
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Usage</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
+1 -1
View File
@@ -4,7 +4,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — New Operation</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="../../css/fonts.css">
<link rel="stylesheet" href="../../css/variables.css">
<link rel="stylesheet" href="../../css/layout.css">
<link rel="stylesheet" href="../../css/wizard.css">
+9 -9
View File
@@ -30,7 +30,7 @@
<!-- Searchable combobox -->
<div class="upstream-combobox" id="upstream-combobox">
<div class="upstream-combobox-trigger" id="upstream-combobox-trigger" onclick="toggleUpstreamDropdown(event)">
<div class="upstream-combobox-trigger" id="upstream-combobox-trigger" data-wizard-action="toggle-upstream">
<div class="upstream-combobox-value" id="upstream-combobox-value">
<span class="upstream-combobox-placeholder" data-i18n="wizard.step2.upstream_placeholder">Выберите API-хост…</span>
</div>
@@ -45,7 +45,7 @@
<svg width="13" height="13" viewBox="0 0 16 16" fill="none" stroke="var(--text-muted)" stroke-width="1.8" stroke-linecap="round">
<circle cx="7" cy="7" r="5"/><path d="M12 12l2.5 2.5"/>
</svg>
<input class="upstream-search-input" id="upstream-search" type="text" data-i18n-ph="wizard.step2.search_placeholder" placeholder="Поиск по имени или URL…" oninput="filterUpstreams(this.value)" autocomplete="off" spellcheck="false">
<input class="upstream-search-input" id="upstream-search" type="text" data-i18n-ph="wizard.step2.search_placeholder" placeholder="Поиск по имени или URL…" autocomplete="off" spellcheck="false">
</div>
<div class="upstream-dropdown-list" id="upstream-dropdown-list">
<!-- populated by JS -->
@@ -58,11 +58,11 @@
<div class="upstream-preview-name" id="upstream-preview-name"></div>
<div class="upstream-preview-url" id="upstream-preview-url"></div>
<span class="upstream-auth-badge" id="upstream-preview-badge"></span>
<button class="upstream-preview-change" onclick="beginEditSelectedUpstream(event)" data-i18n="wizard.step2.change">Изменить</button>
<button class="upstream-preview-change" data-wizard-action="edit-upstream" data-i18n="wizard.step2.change">Изменить</button>
</div>
<!-- Register new upstream trigger row -->
<div class="upstream-new-trigger" id="upstream-new-trigger" onclick="startNewUpstream()">
<div class="upstream-new-trigger" id="upstream-new-trigger" data-wizard-action="new-upstream">
<div class="upstream-new-trigger-radio" id="upstream-new-trigger-radio">
<div class="upstream-new-trigger-dot"></div>
</div>
@@ -89,7 +89,7 @@
</div>
<div class="form-group">
<label class="form-label" data-i18n="wizard.step2.auth_selector">Авторизация API-хоста</label>
<select class="form-select" id="new-upstream-auth-mode" data-testid="wizard-auth-mode-select" onchange="updateUpstreamAuthUi()">
<select class="form-select" id="new-upstream-auth-mode" data-testid="wizard-auth-mode-select">
<option value="none" data-i18n="wizard.step2.auth_mode.none">Без авторизации</option>
<option value="existing" data-i18n="wizard.step2.auth_mode.existing">Использовать существующий профиль авторизации</option>
<option value="create" data-i18n="wizard.step2.auth_mode.create">Создать профиль авторизации сейчас</option>
@@ -118,7 +118,7 @@
<div class="form-row" style="grid-template-columns: 1fr 1fr;">
<div class="form-group">
<label class="form-label"><span data-i18n="wizard.step2.profile_kind">Тип авторизации</span> <span class="form-label-required" data-i18n="workspace_setup.required">обязательно</span></label>
<select class="form-select" id="new-auth-profile-kind" data-testid="wizard-auth-profile-kind-select" onchange="updateAuthProfileCreateUi()">
<select class="form-select" id="new-auth-profile-kind" data-testid="wizard-auth-profile-kind-select">
<option value="bearer" data-i18n="wizard.step2.auth_kind.bearer">Bearer-токен</option>
<option value="basic" data-i18n="wizard.step2.auth_kind.basic">Логин и пароль</option>
<option value="api_key_header" data-i18n="wizard.step2.auth_kind.api_key_header">API-ключ в заголовке</option>
@@ -149,7 +149,7 @@
<select class="form-select" id="new-auth-profile-secret-id" data-testid="wizard-auth-secret-select"></select>
</div>
<div style="display:flex; gap:8px; align-items:center; flex-wrap:wrap;">
<button class="btn-ghost-sm" data-testid="wizard-open-quick-secret" onclick="openQuickSecretModal(event)" data-i18n="wizard.step2.quick_secret">Быстро создать секрет</button>
<button class="btn-ghost-sm" data-testid="wizard-open-quick-secret" data-wizard-action="quick-secret" data-i18n="wizard.step2.quick_secret">Быстро создать секрет</button>
<a class="btn-ghost-sm" href="/secrets" target="_blank" rel="noopener" data-i18n="wizard.step2.manage_secrets">Открыть страницу секретов</a>
</div>
</div>
@@ -168,8 +168,8 @@
<div class="form-hint" data-i18n="wizard.step2.static_headers_hint">Необязательные заголовки без секретных значений. Токены, пароли и ключи храните через профиль авторизации.</div>
</div>
<div style="display:flex; gap:8px; margin-top:4px;">
<button class="btn-primary-sm" onclick="saveNewUpstream(event)" data-i18n="wizard.step2.save_upstream">Сохранить API-хост</button>
<button class="btn-ghost-sm" onclick="cancelNewUpstream(event)" data-i18n="btn.cancel">Отмена</button>
<button class="btn-primary-sm" data-wizard-action="save-upstream" data-i18n="wizard.step2.save_upstream">Сохранить API-хост</button>
<button class="btn-ghost-sm" data-wizard-action="cancel-upstream" data-i18n="btn.cancel">Отмена</button>
</div>
</div>
</div>
+93 -5
View File
@@ -25,23 +25,23 @@
</div>
<div class="config-card-body">
<div class="method-grid">
<button class="method-card" data-method="GET" onclick="selectMethod(this)">
<button class="method-card" data-method="GET">
<span class="method-name">GET</span>
<span class="method-desc" data-i18n="wizard.step3.rest.read">Чтение</span>
</button>
<button class="method-card active" data-method="POST" onclick="selectMethod(this)">
<button class="method-card active" data-method="POST">
<span class="method-name">POST</span>
<span class="method-desc" data-i18n="wizard.step3.rest.create">Создание</span>
</button>
<button class="method-card" data-method="PUT" onclick="selectMethod(this)">
<button class="method-card" data-method="PUT">
<span class="method-name">PUT</span>
<span class="method-desc" data-i18n="wizard.step3.rest.replace">Замена</span>
</button>
<button class="method-card" data-method="PATCH" onclick="selectMethod(this)">
<button class="method-card" data-method="PATCH">
<span class="method-name">PATCH</span>
<span class="method-desc" data-i18n="wizard.step3.rest.update">Обновление</span>
</button>
<button class="method-card" data-method="DELETE" onclick="selectMethod(this)">
<button class="method-card" data-method="DELETE">
<span class="method-name">DELETE</span>
<span class="method-desc" data-i18n="wizard.step3.rest.remove">Удаление</span>
</button>
@@ -90,4 +90,92 @@
</div>
</div>
<div class="config-card approval-gate-card" style="margin-bottom: 20px;">
<div class="config-card-header">
<div class="config-card-header-icon">
<svg width="13" height="13" viewBox="0 0 16 16" fill="none" stroke="var(--text-secondary)" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round">
<path d="M8 2l5 2v4c0 3-2 5-5 6-3-1-5-3-5-6V4l5-2z"/>
<path d="M6 8l1.4 1.4L10.5 6"/>
</svg>
</div>
<div>
<div class="config-card-title" data-i18n="wizard.approval.title">Подтверждение человеком</div>
<div class="config-card-subtitle" data-i18n="wizard.approval.subtitle">Включайте для действий, которые нельзя выполнять без явного решения пользователя.</div>
</div>
</div>
<div class="config-card-body" style="gap: 16px;">
<label class="toggle-row approval-toggle-row" for="approval-required">
<span id="approval-required-toggle" class="toggle" aria-hidden="true"></span>
<span class="toggle-text">
<span class="toggle-label" data-i18n="wizard.approval.required_label">Требовать подтверждение перед выполнением</span>
<span class="toggle-desc" data-i18n="wizard.approval.required_desc">MCP клиент получит ожидающий запрос, а действие выполнится только после подтверждения через отдельный эндпоинт подтверждения.</span>
</span>
<input id="approval-required" type="checkbox" class="approval-toggle-input">
</label>
<div id="approval-config-fields" class="approval-config-fields" hidden>
<div class="form-group">
<label class="form-label" for="approval-mode" data-i18n="wizard.approval.mode">Механизм подтверждения</label>
<select id="approval-mode" class="form-select">
<option value="custom" data-i18n="wizard.approval.mode.custom">Custom MCP Approval</option>
<option value="elicitation" data-i18n="wizard.approval.mode.elicitation">MCP Elicitation</option>
</select>
</div>
<div class="info-callout" id="approval-custom-info">
<svg class="info-callout-icon" width="15" height="15" viewBox="0 0 16 16" fill="none" stroke="var(--accent)" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round">
<circle cx="8" cy="8" r="6.5"></circle>
<path d="M8 11V8M8 5.5V5"></path>
</svg>
<div class="info-callout-body">
<div class="info-callout-title" data-i18n="wizard.approval.custom_title">Custom MCP Approval</div>
<div class="info-callout-text" data-i18n="wizard.approval.custom_body">Crank вернёт MCP-клиенту ответ о необходимости подтверждения, идентификатор заявки и адреса для подтверждения или отказа. Ваш MCP-клиент должен распознать такой ответ, показать пользователю окно подтверждения и отправить решение на адрес подтверждения. Для этого адреса нужен отдельный ключ подтверждения агента.</div>
</div>
</div>
<div class="info-callout" id="approval-elicitation-info" hidden>
<svg class="info-callout-icon" width="15" height="15" viewBox="0 0 16 16" fill="none" stroke="var(--accent)" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round">
<circle cx="8" cy="8" r="6.5"></circle>
<path d="M8 11V8M8 5.5V5"></path>
</svg>
<div class="info-callout-body">
<div class="info-callout-title" data-i18n="wizard.approval.elicitation_title">MCP Elicitation</div>
<div class="info-callout-text" data-i18n="wizard.approval.elicitation_body">Crank запросит подтверждение стандартным способом MCP Elicitation. MCP-клиент должен поддерживать эту возможность. Отдельный ключ подтверждения не используется: решение пользователя возвращается по текущему MCP-подключению.</div>
</div>
</div>
<div class="form-group" id="approval-elicitation-message-group" hidden>
<label class="form-label" for="approval-elicitation-message" data-i18n="wizard.approval.elicitation_message">Сообщение для MCP-клиента</label>
<textarea id="approval-elicitation-message" class="form-textarea" rows="3" maxlength="240" data-i18n-ph="wizard.approval.elicitation_message_placeholder" placeholder="Подтвердите выполнение операции."></textarea>
<div class="form-hint" data-i18n="wizard.approval.elicitation_message_hint">Короткое сообщение для MCP-клиента. Внешний вид окна подтверждения определяет сам клиент.</div>
</div>
<div class="form-group">
<label class="form-label" for="approval-ttl-seconds" data-i18n="wizard.approval.ttl">Сколько ждать подтверждение</label>
<select id="approval-ttl-seconds" class="form-select">
<option value="60">1 минута</option>
<option value="180">3 минуты</option>
<option value="300" selected>5 минут</option>
</select>
</div>
<label class="checkbox-pill approval-preview-pill">
<input id="approval-show-payload-preview" type="checkbox" checked>
<span data-i18n="wizard.approval.show_payload">Передавать параметры вызова в подтверждение</span>
</label>
<div class="info-callout" id="approval-payload-info">
<svg class="info-callout-icon" width="15" height="15" viewBox="0 0 16 16" fill="none" stroke="var(--accent)" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round">
<circle cx="8" cy="8" r="6.5"></circle>
<path d="M8 11V8M8 5.5V5"></path>
</svg>
<div class="info-callout-body">
<div class="info-callout-title" data-i18n="wizard.approval.payload_title">Параметры подтверждения</div>
<div class="info-callout-text" data-i18n="wizard.approval.payload_body">Если включено, Crank передаст параметры вызова вместе с запросом подтверждения. Так внешний интерфейс или MCP-клиент сможет показать пользователю, какое действие он подтверждает. Если параметры содержат чувствительные данные, выключите эту опцию.</div>
</div>
</div>
</div>
</div>
</div>
</div><!-- /step-pane-3-rest -->
+14 -14
View File
@@ -5,7 +5,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Workspace</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/pages.css">
@@ -24,10 +24,10 @@
</div>
Crank
</a>
<a href="javascript:history.back()" class="ws-setup-back">
<button type="button" class="ws-setup-back" data-history-back>
<svg width="13" height="13" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round"><path d="M10 4l-4 4 4 4"/></svg>
<span data-i18n="workspace_setup.back">Back</span>
</a>
</button>
</div>
<!-- Body -->
@@ -48,27 +48,27 @@
<div>
<div class="ws-avatar-hint" data-i18n="workspace_setup.identity.avatar_hint">Avatar is derived from your workspace name.</div>
<div class="ws-color-swatches">
<div class="ws-color-swatch active" style="background:#0d9488;" data-color="#0d9488" onclick="pickColor(this)" title="Teal"></div>
<div class="ws-color-swatch" style="background:#7c3aed;" data-color="#7c3aed" onclick="pickColor(this)" title="Purple"></div>
<div class="ws-color-swatch" style="background:#0891b2;" data-color="#0891b2" onclick="pickColor(this)" title="Cyan"></div>
<div class="ws-color-swatch" style="background:#d29922;" data-color="#d29922" onclick="pickColor(this)" title="Amber"></div>
<div class="ws-color-swatch" style="background:#1a7f37;" data-color="#1a7f37" onclick="pickColor(this)" title="Green"></div>
<div class="ws-color-swatch" style="background:#cf222e;" data-color="#cf222e" onclick="pickColor(this)" title="Red"></div>
<div class="ws-color-swatch" style="background:#5e6ad2;" data-color="#5e6ad2" onclick="pickColor(this)" title="Indigo"></div>
<button class="ws-color-swatch active" style="background:#0d9488;" data-color="#0d9488" type="button" title="Teal"></button>
<button class="ws-color-swatch" style="background:#7c3aed;" data-color="#7c3aed" type="button" title="Purple"></button>
<button class="ws-color-swatch" style="background:#0891b2;" data-color="#0891b2" type="button" title="Cyan"></button>
<button class="ws-color-swatch" style="background:#d29922;" data-color="#d29922" type="button" title="Amber"></button>
<button class="ws-color-swatch" style="background:#1a7f37;" data-color="#1a7f37" type="button" title="Green"></button>
<button class="ws-color-swatch" style="background:#cf222e;" data-color="#cf222e" type="button" title="Red"></button>
<button class="ws-color-swatch" style="background:#5e6ad2;" data-color="#5e6ad2" type="button" title="Indigo"></button>
</div>
</div>
</div>
<div class="form-group" style="margin-bottom:14px;">
<label class="form-label"><span data-i18n="workspace_setup.name">Workspace name</span> <span class="form-label-required" data-i18n="workspace_setup.required">required</span></label>
<input class="form-input" id="ws-name" type="text" placeholder="Acme Inc" autocomplete="off" oninput="onWsNameInput(this.value)">
<input class="form-input" id="ws-name" type="text" placeholder="Acme Inc" autocomplete="off">
</div>
<div class="form-group" style="margin-bottom:14px;">
<label class="form-label"><span data-i18n="workspace_setup.slug">Slug</span> <span class="form-label-required" data-i18n="workspace_setup.required">required</span></label>
<div style="position:relative;">
<span style="position:absolute;left:12px;top:50%;transform:translateY(-50%);font-size:13px;color:var(--text-muted);font-family:monospace;pointer-events:none;">mcp.crank.io/</span>
<input class="form-input input-mono" id="ws-slug" type="text" placeholder="acme-inc" autocomplete="off" style="padding-left: 112px;" oninput="onWsSlugInput(this.value)">
<input class="form-input input-mono" id="ws-slug" type="text" placeholder="acme-inc" autocomplete="off" style="padding-left: 112px;">
</div>
<div class="form-hint" data-i18n="workspace_setup.slug_hint">Only lowercase letters, numbers, and hyphens. Used in MCP endpoint URLs.</div>
</div>
@@ -81,8 +81,8 @@
<!-- ── Actions ── -->
<div class="ws-setup-actions">
<a href="javascript:history.back()" class="btn-ghost-sm" style="padding:9px 18px;font-size:13px;text-decoration:none;color:var(--text-secondary);" data-i18n="btn.cancel">Cancel</a>
<button class="btn-primary ws-submit-btn" id="submit-btn" type="button" onclick="submitForm()" data-i18n="workspace_setup.actions.save">Save changes</button>
<button type="button" class="btn-ghost-sm" data-history-back style="padding:9px 18px;font-size:13px;text-decoration:none;color:var(--text-secondary);" data-i18n="btn.cancel">Cancel</button>
<button class="btn-primary ws-submit-btn" id="submit-btn" type="button" data-i18n="workspace_setup.actions.save">Save changes</button>
</div>
<div class="ws-setup-footer-note" id="footer-note" hidden>
+5 -1
View File
@@ -4,7 +4,7 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Crank — Operations</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap" rel="stylesheet">
<link rel="stylesheet" href="css/fonts.css">
<link rel="stylesheet" href="css/variables.css">
<link rel="stylesheet" href="css/layout.css">
<link rel="stylesheet" href="css/catalog.css">
@@ -392,6 +392,10 @@
<div class="openapi-import-upload">
<label class="openapi-file-label">
<span>Файл OpenAPI/Swagger</span>
<span class="openapi-file-control">
<span class="btn-secondary openapi-file-button">Выбрать файл</span>
<span class="openapi-file-name" id="openapi-import-file-name">Файл не выбран</span>
</span>
<input id="openapi-import-file" type="file" accept=".yaml,.yml,.json,application/json,text/yaml">
</label>
<textarea id="openapi-import-document" spellcheck="false" placeholder="Вставьте openapi.yaml или swagger.json"></textarea>
+82 -8
View File
@@ -2,14 +2,21 @@ var KEYS = [];
var AGENTS = [];
var currentWorkspaceId = null;
var currentAgentId = null;
var activeKeyKind = 'mcp_client';
var selectedScopes = new Set(['read']);
var search = '';
var SCOPES = ['read', 'write', 'deploy'];
var SCOPES_BY_KIND = {
mcp_client: ['read', 'write', 'deploy'],
approval: ['read_pending', 'approve', 'deny'],
};
var SCOPE_DESC = {
read: 'apikeys.scope.read',
write: 'apikeys.scope.write',
deploy: 'apikeys.scope.deploy',
approve: 'apikeys.scope.approve',
deny: 'apikeys.scope.deny',
read_pending: 'apikeys.scope.read_pending',
};
function tKey(key) {
@@ -35,6 +42,7 @@ function mapKeyRecord(record) {
return {
id: apiKey.id,
agentId: apiKey.agent_id || null,
keyKind: apiKey.key_kind || 'mcp_client',
name: apiKey.name,
prefix: apiKey.prefix || '',
scopes: apiKey.scopes || [],
@@ -173,6 +181,7 @@ async function deleteKey(id) {
async function createKey(name, scopes) {
var created = await window.CrankApi.createAgentPlatformApiKey(currentWorkspaceId, currentAgentId, {
name: name,
key_kind: activeKeyKind,
scopes: scopes,
});
return {
@@ -221,13 +230,19 @@ function setCreateButtonState() {
var button = document.getElementById('btn-create-key');
if (!button) return;
button.disabled = !currentAgentId;
var label = document.getElementById('btn-create-key-label');
if (label) {
label.textContent = activeKeyKind === 'approval'
? tKey('apikeys.new_approval')
: tKey('apikeys.new_mcp');
}
}
function renderScopes() {
var el = document.getElementById('scope-checkboxes');
var tmpl = document.getElementById('tmpl-scope-checkbox');
el.innerHTML = '';
SCOPES.forEach(function(scope) {
(SCOPES_BY_KIND[activeKeyKind] || []).forEach(function(scope) {
var node = tmpl.content.cloneNode(true);
var input = node.querySelector('input');
input.dataset.scope = scope;
@@ -242,11 +257,49 @@ function renderScopes() {
});
}
function renderKeyKindTabs() {
document.querySelectorAll('[data-key-kind]').forEach(function(button) {
var kind = button.dataset.keyKind;
button.classList.toggle('active', kind === activeKeyKind);
button.setAttribute('aria-selected', kind === activeKeyKind ? 'true' : 'false');
});
var hint = document.getElementById('key-kind-hint');
if (hint) {
hint.textContent = activeKeyKind === 'approval'
? tKey('apikeys.kind.approval_hint')
: tKey('apikeys.kind.mcp_hint');
}
renderScopeReference();
setCreateButtonState();
}
function renderScopeReference() {
var grid = document.getElementById('scope-reference-grid');
if (!grid) return;
grid.innerHTML = '';
(SCOPES_BY_KIND[activeKeyKind] || []).forEach(function(scope) {
var item = document.createElement('div');
var title = document.createElement('div');
title.style.cssText = 'font-size:12.5px;font-weight:600;color:var(--text-primary);margin-bottom:4px;';
var badge = document.createElement('span');
badge.className = 'badge badge-scope';
badge.textContent = scope;
title.appendChild(badge);
var description = document.createElement('div');
description.style.cssText = 'font-size:12px;color:var(--text-muted);line-height:1.55;';
description.textContent = tKey(SCOPE_DESC[scope]);
item.appendChild(title);
item.appendChild(description);
grid.appendChild(item);
});
}
function renderTable(errorMessage) {
var q = search.toLowerCase();
var tbody = document.getElementById('keys-tbody');
var cardList = document.getElementById('keys-card-list');
var rows = KEYS.filter(function(key) {
var visibleKeys = KEYS.filter(function(key) { return key.keyKind === activeKeyKind; });
var rows = visibleKeys.filter(function(key) {
return !q || key.name.toLowerCase().includes(q) || key.prefix.toLowerCase().includes(q);
});
var subtitle = document.getElementById('keys-summary-subtitle');
@@ -257,8 +310,8 @@ function renderTable(errorMessage) {
}
if (subtitle) {
var active = KEYS.filter(function(key) { return key.status === 'active'; }).length;
var revoked = KEYS.filter(function(key) { return key.status === 'revoked'; }).length;
var active = visibleKeys.filter(function(key) { return key.status === 'active'; }).length;
var revoked = visibleKeys.filter(function(key) { return key.status === 'revoked'; }).length;
subtitle.textContent = currentAgentId
? tfKey('apikeys.active.subtitle', { active: active, revoked: revoked })
: tKey('apikeys.agent.empty_hint');
@@ -282,7 +335,7 @@ function renderTable(errorMessage) {
td.colSpan = 7;
td.style.cssText = 'text-align:center;padding:36px;color:var(--text-muted);';
td.textContent = currentAgentId
? (KEYS.length ? tKey('apikeys.empty.search') : tKey('apikeys.empty.none'))
? (visibleKeys.length ? tKey('apikeys.empty.search') : emptyTextForKind())
: tKey('apikeys.agent.empty_hint');
empty.appendChild(td);
tbody.appendChild(empty);
@@ -349,7 +402,7 @@ function renderKeyCards(rows, errorMessage) {
cardList.appendChild(
buildKeyCardMessage(
currentAgentId
? (KEYS.length ? tKey('apikeys.empty.search') : tKey('apikeys.empty.none'))
? (visibleKeys.length ? tKey('apikeys.empty.search') : emptyTextForKind())
: tKey('apikeys.agent.empty_hint'),
false
)
@@ -424,6 +477,12 @@ function buildKeyCardMessage(text, isError) {
return card;
}
function emptyTextForKind() {
return activeKeyKind === 'approval'
? tKey('apikeys.empty.approval')
: tKey('apikeys.empty.none');
}
function buildMetaItem(labelKey, valueText) {
var item = document.createElement('div');
item.className = 'resource-meta-item';
@@ -456,7 +515,11 @@ function openModal() {
document.getElementById('modal-footer-create').hidden = false;
document.getElementById('modal-footer-done').hidden = true;
document.getElementById('new-key-name').value = '';
selectedScopes = new Set(['read']);
selectedScopes = new Set([activeKeyKind === 'approval' ? 'approve' : 'read']);
document.getElementById('modal-create-title').textContent = activeKeyKind === 'approval'
? tKey('apikeys.modal.title_approval')
: tKey('apikeys.modal.title_mcp');
document.getElementById('approval-key-warning').hidden = activeKeyKind !== 'approval';
renderScopes();
modal.classList.add('open');
setTimeout(function() {
@@ -554,6 +617,16 @@ document.getElementById('agent-select').addEventListener('change', async functio
await loadKeys();
});
document.querySelectorAll('[data-key-kind]').forEach(function(button) {
button.addEventListener('click', function() {
activeKeyKind = this.dataset.keyKind || 'mcp_client';
search = '';
document.getElementById('key-search').value = '';
renderKeyKindTabs();
renderTable();
});
});
function copyPrefix(prefix) {
if (navigator.clipboard) {
navigator.clipboard.writeText(prefix).catch(function() {});
@@ -564,6 +637,7 @@ function copyPrefix(prefix) {
}
document.addEventListener('DOMContentLoaded', async function() {
renderKeyKindTabs();
await (window.whenWorkspacesReady ? window.whenWorkspacesReady() : Promise.resolve());
await loadKeys();
window.addEventListener('crank:workspacechange', function() {
+6 -8
View File
@@ -124,14 +124,6 @@
return encoded ? ('?' + encoded) : '';
}
function postBytes(path, bytes, fileName) {
return request(API_BASE + path, {
method: 'POST',
headers: headers(fileName ? { 'X-File-Name': fileName } : {}),
body: bytes,
});
}
window.CrankApi = {
login: function(payload) {
return request(AUTH_BASE + '/login', {
@@ -327,6 +319,12 @@
getLog: function(workspaceId, logId) {
return get('/workspaces/' + encodeURIComponent(workspaceId) + '/logs/' + encodeURIComponent(logId));
},
listApprovals: function(workspaceId, params) {
return get('/workspaces/' + encodeURIComponent(workspaceId) + '/approvals' + query(params));
},
getApproval: function(workspaceId, approvalId) {
return get('/workspaces/' + encodeURIComponent(workspaceId) + '/approvals/' + encodeURIComponent(approvalId));
},
getUsageOverview: function(workspaceId, params) {
return get('/workspaces/' + encodeURIComponent(workspaceId) + '/usage' + query(params));
},
+104
View File
@@ -95,6 +95,12 @@ var TRANSLATIONS = {
'apikeys.title': 'Agent Keys',
'apikeys.subtitle': 'These keys connect an MCP client to the MCP server and are issued for a specific agent.',
'apikeys.new': 'Create key',
'apikeys.new_mcp': 'Create MCP client key',
'apikeys.new_approval': 'Create approval key',
'apikeys.kind.mcp': 'MCP clients',
'apikeys.kind.approval': 'Approvals',
'apikeys.kind.mcp_hint': 'MCP client keys connect an agent to tools/list and tools/call.',
'apikeys.kind.approval_hint': 'Approval keys are used only by an external human confirmation interface.',
'apikeys.agent.title': 'Agent selection',
'apikeys.agent.subtitle': 'Select the AI agent this key is issued for.',
'apikeys.agent.label': 'AI agent',
@@ -118,7 +124,12 @@ var TRANSLATIONS = {
'apikeys.scope.read': 'Initialize MCP sessions, ping the server, and list tools for the selected AI agent.',
'apikeys.scope.write': 'Execute `tools/call` requests against published agent toolsets.',
'apikeys.scope.deploy': 'Reserved for deploy-scoped automation. Today it also permits MCP read/write flows.',
'apikeys.scope.approve': 'Confirm a pending human approval request for this agent.',
'apikeys.scope.deny': 'Reject a pending human approval request for this agent.',
'apikeys.scope.read_pending': 'Read pending human approval requests for this agent.',
'apikeys.modal.title': 'Create agent key',
'apikeys.modal.title_mcp': 'Create MCP client key',
'apikeys.modal.title_approval': 'Create approval key',
'apikeys.modal.name': 'Key name',
'apikeys.modal.name_hint': 'A descriptive label to identify the key. Only visible to admins.',
'apikeys.modal.name_placeholder': 'e.g. Production, CI pipeline',
@@ -133,6 +144,7 @@ var TRANSLATIONS = {
'apikeys.status.revoked': 'Revoked',
'apikeys.last_used.never': 'Never',
'apikeys.empty.none': 'No API keys yet',
'apikeys.empty.approval': 'No approval keys yet. Create one only if this agent has tools that require human confirmation.',
'apikeys.empty.search': 'No keys match your search',
'apikeys.loading': 'Loading…',
'apikeys.error.api': 'Workspace or API is unavailable',
@@ -160,6 +172,7 @@ var TRANSLATIONS = {
'apikeys.action.revoke': 'Revoke key',
'apikeys.action.delete': 'Delete',
'apikeys.creating': 'Creating…',
'apikeys.approval.warning': 'Do not pass this key to an LLM or MCP client. It is only for an external interface where a human confirms an action.',
// Secrets page
'secrets.title': 'Secrets',
@@ -268,6 +281,27 @@ var TRANSLATIONS = {
'logs.live.off.body': 'Automatic polling is paused.',
'logs.refresh.title': 'Logs refreshed',
'logs.refresh.body': 'The latest invocation records were loaded for the current workspace.',
'approvals.title': 'Human confirmations',
'approvals.subtitle': 'Requests waiting for an external user decision and recent results.',
'approvals.refresh': 'Refresh',
'approvals.refresh.title': 'Confirmations refreshed',
'approvals.refresh.body': 'The latest confirmation requests were loaded.',
'approvals.loading': 'Loading confirmation requests…',
'approvals.empty': 'There are no confirmation requests yet.',
'approvals.error.load': 'Failed to load confirmation requests',
'approvals.untitled': 'Confirmation request',
'approvals.operation': 'Operation',
'approvals.agent': 'Agent',
'approvals.expires_at': 'Expires',
'approvals.updated_at': 'Updated',
'approvals.request': 'Request',
'approvals.response': 'Result',
'approvals.status.pending': 'Pending',
'approvals.status.approved': 'Approved',
'approvals.status.denied': 'Denied',
'approvals.status.expired': 'Expired',
'approvals.status.completed': 'Completed',
'approvals.status.failed': 'Failed',
// Usage page
'usage.title': 'Usage',
@@ -560,6 +594,24 @@ var TRANSLATIONS = {
'wizard.step5.execution': 'Execution settings',
'wizard.step5.exec_title': 'Request execution',
'wizard.step5.exec_subtitle': 'Timeout, retry count and authorization profile',
'wizard.approval.title': 'Human confirmation',
'wizard.approval.subtitle': 'Enable this for actions that must not run without an explicit user decision.',
'wizard.approval.required_label': 'Require confirmation before execution',
'wizard.approval.required_desc': 'The MCP client receives a pending request, and the action runs only after confirmation through a separate approval endpoint.',
'wizard.approval.mode': 'Confirmation mechanism',
'wizard.approval.mode.custom': 'Custom MCP Approval',
'wizard.approval.mode.elicitation': 'MCP Elicitation',
'wizard.approval.custom_title': 'Custom MCP Approval',
'wizard.approval.custom_body': 'Crank returns approval_required to the MCP client with approval_id, approval_url and approve/deny links. Your MCP client must handle this response, show confirmation to the user and send the decision to the approval endpoint. The approval endpoint requires a separate agent approval key.',
'wizard.approval.elicitation_title': 'MCP Elicitation',
'wizard.approval.elicitation_body': 'Crank asks for confirmation through standard MCP Elicitation. The MCP client must support the elicitation capability. No separate approval key is used: the user decision returns through the current MCP session.',
'wizard.approval.elicitation_message': 'Message for the MCP client',
'wizard.approval.elicitation_message_placeholder': 'Confirm operation execution.',
'wizard.approval.elicitation_message_hint': 'Short protocol message. The MCP client still controls the confirmation UI.',
'wizard.approval.ttl': 'How long to wait for confirmation',
'wizard.approval.show_payload': 'Send call parameters to the confirmation flow',
'wizard.approval.payload_title': 'Confirmation parameters',
'wizard.approval.payload_body': 'When enabled, Crank sends call parameters into the approval flow so the external UI or MCP client can show the user what action is being confirmed. Disable this option if parameters contain sensitive data.',
'wizard.step5.security_level_title': 'Operation security',
'wizard.step5.community_security_note': '',
'wizard.step5.live_title': 'Check and publish',
@@ -905,6 +957,12 @@ var TRANSLATIONS = {
'apikeys.title': 'Ключи агентов',
'apikeys.subtitle': 'Эти ключи используются для подключения MCP клиента к MCP серверу и выдаются на конкретного агента.',
'apikeys.new': 'Создать ключ',
'apikeys.new_mcp': 'Создать ключ MCP-клиента',
'apikeys.new_approval': 'Создать ключ подтверждения',
'apikeys.kind.mcp': 'MCP-клиенты',
'apikeys.kind.approval': 'Подтверждения',
'apikeys.kind.mcp_hint': 'Ключи MCP-клиентов используются для подключения к tools/list и tools/call агента.',
'apikeys.kind.approval_hint': 'Ключи подтверждения используются только внешним интерфейсом, где человек подтверждает действие.',
'apikeys.agent.title': 'Выбор агента',
'apikeys.agent.subtitle': 'Выберите AI-агента для которого выпускается ключ.',
'apikeys.agent.label': 'AI-агент',
@@ -928,7 +986,12 @@ var TRANSLATIONS = {
'apikeys.scope.read': 'Инициализация MCP-сессий, ping сервера и получение списка инструментов для выбранного AI-агента.',
'apikeys.scope.write': 'Выполнение `tools/call` для опубликованных наборов инструментов агента.',
'apikeys.scope.deploy': 'Зарезервировано для deploy-автоматизации. Сейчас также разрешает MCP read/write сценарии.',
'apikeys.scope.approve': 'Подтверждение ожидающего запроса для этого агента.',
'apikeys.scope.deny': 'Отклонение ожидающего запроса для этого агента.',
'apikeys.scope.read_pending': 'Получение списка запросов, ожидающих подтверждения для этого агента.',
'apikeys.modal.title': 'Создать ключ агента',
'apikeys.modal.title_mcp': 'Создать ключ MCP-клиента',
'apikeys.modal.title_approval': 'Создать ключ подтверждения',
'apikeys.modal.name': 'Имя ключа',
'apikeys.modal.name_hint': 'Понятная метка для идентификации ключа. Видна только администраторам.',
'apikeys.modal.name_placeholder': 'например, Production, CI pipeline',
@@ -943,6 +1006,7 @@ var TRANSLATIONS = {
'apikeys.status.revoked': 'Отозван',
'apikeys.last_used.never': 'Никогда',
'apikeys.empty.none': 'API-ключей пока нет',
'apikeys.empty.approval': 'Ключей подтверждения пока нет. Они нужны только агентам с инструментами, требующими подтверждения человеком.',
'apikeys.empty.search': 'Нет ключей по текущему поиску',
'apikeys.loading': 'Загрузка…',
'apikeys.error.api': 'Воркспейс или API недоступен',
@@ -970,6 +1034,7 @@ var TRANSLATIONS = {
'apikeys.action.revoke': 'Отозвать ключ',
'apikeys.action.delete': 'Удалить',
'apikeys.creating': 'Создание…',
'apikeys.approval.warning': 'Не передавайте этот ключ LLM или MCP-клиенту. Он нужен только внешнему интерфейсу, где человек подтверждает действие.',
// Secrets page
'secrets.title': 'Секреты',
@@ -1080,6 +1145,27 @@ var TRANSLATIONS = {
'logs.live.off.body': 'Автоматический опрос остановлен.',
'logs.refresh.title': 'Логи обновлены',
'logs.refresh.body': 'Получены последние записи вызовов для текущего воркспейса.',
'approvals.title': 'Подтверждения человеком',
'approvals.subtitle': 'Заявки, которые ожидают решения пользователя, и последние результаты.',
'approvals.refresh': 'Обновить',
'approvals.refresh.title': 'Подтверждения обновлены',
'approvals.refresh.body': 'Получены последние заявки на подтверждение.',
'approvals.loading': 'Загрузка заявок на подтверждение…',
'approvals.empty': 'Заявок на подтверждение пока нет.',
'approvals.error.load': 'Не удалось загрузить заявки на подтверждение',
'approvals.untitled': 'Заявка на подтверждение',
'approvals.operation': 'Операция',
'approvals.agent': 'Агент',
'approvals.expires_at': 'Истекает',
'approvals.updated_at': 'Обновлено',
'approvals.request': 'Запрос',
'approvals.response': 'Результат',
'approvals.status.pending': 'Ожидает',
'approvals.status.approved': 'Подтверждено',
'approvals.status.denied': 'Отклонено',
'approvals.status.expired': 'Истекло',
'approvals.status.completed': 'Выполнено',
'approvals.status.failed': 'Ошибка',
// Usage page
'usage.title': 'Использование',
@@ -1372,6 +1458,24 @@ var TRANSLATIONS = {
'wizard.step5.execution': 'Параметры выполнения',
'wizard.step5.exec_title': 'Выполнение запроса',
'wizard.step5.exec_subtitle': 'Время ожидания, повторные попытки и профиль авторизации',
'wizard.approval.title': 'Подтверждение человеком',
'wizard.approval.subtitle': 'Включайте для действий, которые нельзя выполнять без явного решения пользователя.',
'wizard.approval.required_label': 'Требовать подтверждение перед выполнением',
'wizard.approval.required_desc': 'Инструмент не выполнится сразу. Crank сначала запросит подтверждение выбранным способом.',
'wizard.approval.mode': 'Механизм подтверждения',
'wizard.approval.mode.custom': 'Custom MCP Approval',
'wizard.approval.mode.elicitation': 'MCP Elicitation',
'wizard.approval.custom_title': 'Custom MCP Approval',
'wizard.approval.custom_body': 'Crank вернёт MCP-клиенту ответ о необходимости подтверждения, идентификатор заявки и адреса для подтверждения или отказа. Ваш MCP-клиент должен распознать такой ответ, показать пользователю окно подтверждения и отправить решение на адрес подтверждения. Для этого адреса нужен отдельный ключ подтверждения агента.',
'wizard.approval.elicitation_title': 'MCP Elicitation',
'wizard.approval.elicitation_body': 'Crank запросит подтверждение стандартным способом MCP Elicitation. MCP-клиент должен поддерживать эту возможность. Отдельный ключ подтверждения не используется: решение пользователя возвращается по текущему MCP-подключению.',
'wizard.approval.elicitation_message': 'Сообщение для MCP-клиента',
'wizard.approval.elicitation_message_placeholder': 'Подтвердите выполнение операции.',
'wizard.approval.elicitation_message_hint': 'Короткое сообщение для MCP-клиента. Внешний вид окна подтверждения определяет сам клиент.',
'wizard.approval.ttl': 'Сколько ждать подтверждение',
'wizard.approval.show_payload': 'Передавать параметры вызова в подтверждение',
'wizard.approval.payload_title': 'Параметры подтверждения',
'wizard.approval.payload_body': 'Если включено, Crank передаст параметры вызова вместе с запросом подтверждения. Так внешний интерфейс или MCP-клиент сможет показать пользователю, какое действие он подтверждает. Если параметры содержат чувствительные данные, выключите эту опцию.',
'wizard.step5.security_level_title': 'Защита операции',
'wizard.step5.community_security_note': '',
'wizard.step5.live_title': 'Проверка и публикация',
+168 -4
View File
@@ -11,9 +11,14 @@ document.addEventListener('DOMContentLoaded', function () {
workspaceId: null,
loading: false,
loadError: '',
approvals: [],
approvalsLoading: false,
approvalsError: '',
};
var logList = document.getElementById('log-list');
var approvalList = document.getElementById('approval-list');
var approvalRefreshBtn = document.getElementById('approval-refresh-btn');
var logSearch = document.getElementById('log-search');
var refreshBtn = document.getElementById('refresh-btn');
var timeRangeSel = document.getElementById('time-range');
@@ -54,6 +59,19 @@ document.addEventListener('DOMContentLoaded', function () {
return date.toISOString().slice(11, 23);
}
function formatDateTime(timestamp) {
if (!timestamp) {
return '';
}
var date = new Date(timestamp);
return date.toLocaleString(window.CrankLocale || undefined, {
day: '2-digit',
month: 'short',
hour: '2-digit',
minute: '2-digit',
});
}
function element(tag, className, text) {
var node = document.createElement(tag);
if (className) node.className = className;
@@ -111,6 +129,109 @@ document.addEventListener('DOMContentLoaded', function () {
};
}
function normalizeApproval(record) {
var approval = record.approval || record;
return {
id: approval.id,
agentId: approval.agent_id,
operationId: approval.operation_id,
operationVersion: approval.operation_version,
status: approval.status,
riskLevel: approval.risk_level,
requestPayload: approval.request_payload,
responsePayload: approval.response_payload,
createdAt: approval.created_at,
expiresAt: approval.expires_at,
decidedAt: approval.decided_at,
note: approval.decision_note,
};
}
function approvalStatusLabel(status) {
var key = 'approvals.status.' + status;
var translated = tKey(key);
return translated === key ? status : translated;
}
function renderApprovals() {
if (!approvalList) {
return;
}
approvalList.innerHTML = '';
if (state.approvalsLoading && state.approvals.length === 0) {
var loading = element('div', 'approval-empty', tKey('approvals.loading'));
approvalList.appendChild(loading);
return;
}
if (state.approvalsError) {
var error = element('div', 'approval-empty approval-empty-error', state.approvalsError);
approvalList.appendChild(error);
return;
}
if (!state.approvals.length) {
var empty = element('div', 'approval-empty', tKey('approvals.empty'));
approvalList.appendChild(empty);
return;
}
var fragment = document.createDocumentFragment();
state.approvals.forEach(function (item) {
var card = element('article', 'approval-item approval-' + item.status);
var header = element('div', 'approval-item-header');
var titleWrap = element('div', 'approval-item-title-wrap');
titleWrap.appendChild(element('div', 'approval-item-title', tKey('approvals.untitled') + ' ' + item.id));
var meta = element('div', 'approval-item-meta');
meta.textContent = [
tKey('approvals.operation') + ': ' + item.operationId + ' v' + item.operationVersion,
tKey('approvals.agent') + ': ' + item.agentId,
].join(' · ');
titleWrap.appendChild(meta);
header.appendChild(titleWrap);
var badge = element('span', 'approval-status approval-status-' + item.status, approvalStatusLabel(item.status));
header.appendChild(badge);
card.appendChild(header);
var timing = element('div', 'approval-timing');
timing.textContent = item.status === 'pending'
? tKey('approvals.expires_at') + ': ' + formatDateTime(item.expiresAt)
: tKey('approvals.updated_at') + ': ' + formatDateTime(item.decidedAt || item.createdAt);
card.appendChild(timing);
var payloadGrid = element('div', 'approval-payload-grid');
var requestBlock = element('div', 'approval-payload');
requestBlock.appendChild(element('div', 'approval-payload-label', tKey('approvals.request')));
var requestPre = element('pre', 'approval-payload-code');
requestPre.textContent = formatJson(item.requestPayload);
requestBlock.appendChild(requestPre);
payloadGrid.appendChild(requestBlock);
if (item.responsePayload !== null && item.responsePayload !== undefined) {
var responseBlock = element('div', 'approval-payload');
responseBlock.appendChild(element('div', 'approval-payload-label', tKey('approvals.response')));
var responsePre = element('pre', 'approval-payload-code');
responsePre.textContent = formatJson(item.responsePayload);
responseBlock.appendChild(responsePre);
payloadGrid.appendChild(responseBlock);
}
card.appendChild(payloadGrid);
if (item.note) {
card.appendChild(element('div', 'approval-note', item.note));
}
fragment.appendChild(card);
});
approvalList.appendChild(fragment);
}
function renderEmpty(title, message) {
logList.innerHTML = '';
var empty = element('div', 'empty-state');
@@ -306,6 +427,39 @@ document.addEventListener('DOMContentLoaded', function () {
}
}
async function loadApprovals() {
if (!window.CrankApi) {
state.approvalsError = tKey('logs.error.api');
renderApprovals();
return;
}
state.workspaceId = currentWorkspaceId();
if (!state.workspaceId) {
state.approvalsError = tKey('logs.error.workspace');
renderApprovals();
return;
}
state.approvalsLoading = true;
state.approvalsError = '';
renderApprovals();
try {
var response = await window.CrankApi.listApprovals(state.workspaceId, { limit: 20 });
state.approvals = (response && response.items ? response.items : []).map(normalizeApproval);
} catch (error) {
state.approvalsError = error.message || tKey('approvals.error.load');
} finally {
state.approvalsLoading = false;
renderApprovals();
}
}
async function refreshOperationalData() {
await Promise.all([loadLogs(), loadApprovals()]);
}
async function loadLogDetail(logId) {
if (!window.CrankApi || !state.workspaceId || state.details[logId]) {
return;
@@ -343,7 +497,7 @@ document.addEventListener('DOMContentLoaded', function () {
if (!state.liveMode) {
return;
}
state.timer = setInterval(loadLogs, 4000);
state.timer = setInterval(refreshOperationalData, 4000);
}
function toggleLive() {
@@ -386,6 +540,16 @@ document.addEventListener('DOMContentLoaded', function () {
});
}
if (approvalRefreshBtn) {
approvalRefreshBtn.addEventListener('click', function () {
loadApprovals().then(function () {
if (!state.approvalsError && window.CrankUi) {
window.CrankUi.info(tKey('approvals.refresh.body'), tKey('approvals.refresh.title'));
}
});
});
}
if (timeRangeSel) {
timeRangeSel.value = state.period;
timeRangeSel.addEventListener('change', function () {
@@ -405,15 +569,15 @@ document.addEventListener('DOMContentLoaded', function () {
window.addEventListener('crank:workspacechange', function () {
state.details = {};
state.openId = null;
loadLogs();
refreshOperationalData();
});
setLiveState();
startPolling();
if (window.whenWorkspacesReady) {
window.whenWorkspacesReady().finally(loadLogs);
window.whenWorkspacesReady().finally(refreshOperationalData);
} else {
loadLogs();
refreshOperationalData();
}
});
+2
View File
@@ -495,6 +495,7 @@
state.filterMethod = '';
qs('openapi-import-document').value = '';
qs('openapi-import-file').value = '';
qs('openapi-import-file-name').textContent = 'Файл не выбран';
qs('openapi-import-server-custom').value = '';
qs('openapi-import-conflict-mode').value = 'rename';
if (qs('openapi-import-search')) qs('openapi-import-search').value = '';
@@ -539,6 +540,7 @@
qs('openapi-import-file').addEventListener('change', async function(event) {
var file = event.target.files && event.target.files[0];
if (!file) return;
qs('openapi-import-file-name').textContent = file.name;
qs('openapi-import-document').value = await file.text();
});
document.querySelectorAll('[data-openapi-close]').forEach(function(node) {
+3
View File
@@ -330,6 +330,9 @@ async function loadWorkspaceSettings() {
}
async function initSettingsPage() {
document.querySelectorAll('.lang-btn[data-lang]').forEach(function(button) {
button.addEventListener('click', function() { setLang(button.dataset.lang); });
});
bindSectionNavigation();
await loadProfile();
await loadCapabilities();
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+87 -1
View File
@@ -27,6 +27,44 @@ function buildWizardState() {
};
}
function checkedValue(id) {
var element = document.getElementById(id);
return !!(element && element.checked);
}
function normalizeApprovalTtlSeconds(value) {
var ttl = Number(value || 300);
if (!Number.isFinite(ttl)) return 300;
return Math.max(1, Math.min(300, Math.round(ttl)));
}
function buildApprovalPolicy() {
if (!checkedValue('approval-required')) return null;
return {
required: true,
mode: textValue('approval-mode') || 'custom',
risk_level: 'normal',
ttl_seconds: normalizeApprovalTtlSeconds(textValue('approval-ttl-seconds')),
show_payload_preview: checkedValue('approval-show-payload-preview'),
payload_preview_mode: 'summary',
elicitation_message: textValue('approval-mode') === 'elicitation'
? (textValue('approval-elicitation-message') || null)
: null,
};
}
function applyApprovalPolicyToExecutionConfig(config) {
var next = config || {};
var policy = buildApprovalPolicy();
if (policy) {
next.approval_policy = policy;
} else {
next.approval_policy = null;
}
return next;
}
function collectWizardPayload() {
var name = textValue('tool-name');
if (!name) throw new Error(tKey('wizard.error.tool_name'));
@@ -50,7 +88,7 @@ function collectWizardPayload() {
output_schema: convertJsonSchemaToCrankSchema(outputSchemaValue, []),
input_mapping: buildMappingSet(inputMappingValue, 'input'),
output_mapping: buildMappingSet(outputMappingValue, 'output'),
execution_config: parseExecutionConfig(textValue('tool-exec-config')),
execution_config: applyApprovalPolicyToExecutionConfig(parseExecutionConfig(textValue('tool-exec-config'))),
tool_description: buildToolDescription(),
wizard_state: buildWizardState(),
};
@@ -126,6 +164,7 @@ function bindWizardLiveActions() {
if (window.CrankWizardMapping && typeof window.CrankWizardMapping.initialize === 'function') {
window.CrankWizardMapping.initialize();
}
bindApprovalPolicyControls();
bindAgentFacingPreview();
}
@@ -147,6 +186,52 @@ function bindLiveAction(id, busyLabel, handler) {
});
}
function setApprovalPolicyEditor(policy) {
var enabled = !!(policy && policy.required);
var required = document.getElementById('approval-required');
if (required) required.checked = enabled;
setValue('approval-mode', policy && policy.mode ? policy.mode : 'custom');
setValue('approval-elicitation-message', policy && policy.elicitation_message ? policy.elicitation_message : '');
setValue('approval-ttl-seconds', policy && policy.ttl_seconds ? String(policy.ttl_seconds) : '300');
var showPayload = document.getElementById('approval-show-payload-preview');
if (showPayload) {
showPayload.checked = !policy || policy.show_payload_preview !== false;
}
updateApprovalPolicyUi();
}
function updateApprovalPolicyUi() {
var enabled = checkedValue('approval-required');
var toggle = document.getElementById('approval-required-toggle');
var fields = document.getElementById('approval-config-fields');
var mode = textValue('approval-mode') || 'custom';
var customInfo = document.getElementById('approval-custom-info');
var elicitationInfo = document.getElementById('approval-elicitation-info');
var elicitationMessage = document.getElementById('approval-elicitation-message-group');
if (toggle) toggle.classList.toggle('on', enabled);
if (fields) fields.hidden = !enabled;
if (customInfo) customInfo.hidden = mode !== 'custom';
if (elicitationInfo) elicitationInfo.hidden = mode !== 'elicitation';
if (elicitationMessage) elicitationMessage.hidden = mode !== 'elicitation';
}
function bindApprovalPolicyControls() {
[
'approval-required',
'approval-mode',
'approval-elicitation-message',
'approval-ttl-seconds',
'approval-show-payload-preview',
].forEach(function(id) {
var element = document.getElementById(id);
if (!element || element.dataset.approvalBound === 'true') return;
element.dataset.approvalBound = 'true';
element.addEventListener('input', updateApprovalPolicyUi);
element.addEventListener('change', updateApprovalPolicyUi);
});
updateApprovalPolicyUi();
}
async function runWizardLiveAction(button, busyLabel, handler) {
if (!button || button.dataset.busy === 'true') {
return;
@@ -708,4 +793,5 @@ function copyTestResponseToOutputSample() {
bindWizardLiveActions: bindWizardLiveActions,
updateWizardProtocolVisibility: updateWizardProtocolVisibility,
renderAgentFacingPreview: renderAgentFacingPreview,
setApprovalPolicyEditor: setApprovalPolicyEditor,
};
+36 -9
View File
@@ -346,6 +346,25 @@
return button;
}
function wrapMappingControl(labelText, control) {
var wrapper = document.createElement('label');
wrapper.className = 'mapping-field';
var label = document.createElement('span');
label.className = 'mapping-field-label';
label.textContent = labelText;
wrapper.appendChild(label);
wrapper.appendChild(control);
return wrapper;
}
function makeMappingArrow() {
var arrow = document.createElement('span');
arrow.className = 'mapping-arrow';
arrow.setAttribute('aria-hidden', 'true');
arrow.textContent = '→';
return arrow;
}
function renderRequestRows(rows) {
var root = field('wizard-request-mapping-rows');
if (!root) return;
@@ -364,7 +383,10 @@
var input = makeInput(row.input, 'form-input input-mono mapping-source', 'base');
input.dataset.role = 'input';
item.appendChild(input);
input.title = 'Поле, которое MCP клиент передает инструменту';
item.appendChild(wrapMappingControl('Из инструмента', input));
item.appendChild(makeMappingArrow());
var select = document.createElement('select');
select.className = 'form-select mapping-target';
@@ -378,16 +400,17 @@
select.appendChild(makeOption(entry[0], entry[1], entry[0] === row.target));
});
select.addEventListener('change', syncVisualMappingsToYaml);
item.appendChild(select);
item.appendChild(wrapMappingControl('Куда в API', select));
var apiName = makeInput(row.apiName || row.input, 'form-input input-mono mapping-api-name', 'base');
apiName.dataset.role = 'apiName';
item.appendChild(apiName);
apiName.title = 'Имя path, query, header или body-поля в API-запросе';
item.appendChild(wrapMappingControl('Имя в API', apiName));
var defaultValue = makeInput(row.defaultValue, 'form-input input-mono mapping-default-value', 'по умолчанию');
var defaultValue = makeInput(row.defaultValue, 'form-input input-mono mapping-default-value', 'если не передано');
defaultValue.dataset.role = 'defaultValue';
defaultValue.title = 'Значение по умолчанию, если поле не передано';
item.appendChild(defaultValue);
defaultValue.title = 'Необязательно. Это значение уйдет в API, если агент не передал поле инструмента.';
item.appendChild(wrapMappingControl('Если пусто', defaultValue));
var transform = document.createElement('select');
transform.className = 'form-select mapping-transform';
@@ -398,7 +421,7 @@
});
transform.title = 'Простое преобразование перед отправкой в API';
transform.addEventListener('change', syncVisualMappingsToYaml);
item.appendChild(transform);
item.appendChild(wrapMappingControl('Преобразование', transform));
item.appendChild(makeRemoveButton(item));
return item;
@@ -422,11 +445,15 @@
var responsePath = makeInput(row.responsePath, 'form-input input-mono mapping-response-path', 'rates.EUR');
responsePath.dataset.role = 'responsePath';
item.appendChild(responsePath);
responsePath.title = 'Поле из ответа API';
item.appendChild(wrapMappingControl('Из ответа API', responsePath));
item.appendChild(makeMappingArrow());
var output = makeInput(row.output, 'form-input input-mono mapping-output-field', 'rate');
output.dataset.role = 'output';
item.appendChild(output);
output.title = 'Поле результата, которое получит MCP клиент';
item.appendChild(wrapMappingControl('В результат инструмента', output));
item.appendChild(makeRemoveButton(item));
return item;
}
+8
View File
@@ -429,6 +429,13 @@ function executionConfigToEditorValue(config) {
return window.jsyaml ? window.jsyaml.dump(value, { lineWidth: -1 }) : JSON.stringify(value, null, 2);
}
function setApprovalPolicyFromSnapshot(config) {
if (!window.CrankWizardLive || typeof window.CrankWizardLive.setApprovalPolicyEditor !== 'function') {
return;
}
window.CrankWizardLive.setApprovalPolicyEditor(config && config.approval_policy ? config.approval_policy : null);
}
function operationSnapshot(versionDocument) {
if (!versionDocument) return {};
return versionDocument.snapshot || versionDocument;
@@ -487,6 +494,7 @@ function prefillWizardFromEdit(detail, versionDocument) {
setValue('tool-input-mapping', mappingSetToEditorValue(snapshot.input_mapping, 'input', snapshot.protocol || detail.protocol));
setValue('tool-output-mapping', mappingSetToEditorValue(snapshot.output_mapping, 'output', snapshot.protocol || detail.protocol));
setValue('tool-exec-config', executionConfigToEditorValue(snapshot.execution_config || {}));
setApprovalPolicyFromSnapshot(snapshot.execution_config || {});
prefillWizardSamples(snapshot);
if (window.CrankWizardMapping && typeof window.CrankWizardMapping.renderFromEditors === 'function') {
window.CrankWizardMapping.renderFromEditors();
+31
View File
@@ -83,6 +83,7 @@ async function initWizardPage() {
await loadProtocolCapabilities();
await loadWizardPanels([1, 2, 3, 4, 5]);
bindWizardPanelActions();
if (window.CrankOverlay && typeof window.CrankOverlay.render === 'function') {
await window.CrankOverlay.render(document, {
workspace: workspace,
@@ -248,6 +249,36 @@ function selectMethod(btn) {
}
}
function bindWizardPanelActions() {
var upstreamSearch = document.getElementById('upstream-search');
var authMode = document.getElementById('new-upstream-auth-mode');
var authKind = document.getElementById('new-auth-profile-kind');
if (upstreamSearch) {
upstreamSearch.addEventListener('input', function(event) {
filterUpstreams(event.target.value);
});
}
if (authMode) authMode.addEventListener('change', updateUpstreamAuthUi);
if (authKind) authKind.addEventListener('change', updateAuthProfileCreateUi);
document.querySelectorAll('.method-card[data-method]').forEach(function(button) {
button.addEventListener('click', function() { selectMethod(button); });
});
document.querySelectorAll('[data-wizard-action]').forEach(function(element) {
element.addEventListener('click', function(event) {
var action = element.dataset.wizardAction;
if (action === 'toggle-upstream') toggleUpstreamDropdown(event);
if (action === 'edit-upstream') beginEditSelectedUpstream(event);
if (action === 'new-upstream') startNewUpstream();
if (action === 'quick-secret') openQuickSecretModal(event);
if (action === 'save-upstream') void saveNewUpstream(event);
if (action === 'cancel-upstream') cancelNewUpstream(event);
});
});
}
function escapeHtml(str) {
return String(str).replace(/&/g,'&amp;').replace(/</g,'&lt;').replace(/>/g,'&gt;').replace(/"/g,'&quot;');
}
+11
View File
@@ -207,6 +207,17 @@ async function exportWorkspaceSnapshot() {
async function initPage() {
updatePageMode();
document.querySelectorAll('.ws-color-swatch').forEach(function(swatch) {
swatch.addEventListener('click', function() { pickColor(swatch); });
});
document.querySelectorAll('[data-history-back]').forEach(function(button) {
button.addEventListener('click', function() { window.history.back(); });
});
var elements = formElements();
elements.name.addEventListener('input', function(event) { onWsNameInput(event.target.value); });
elements.slug.addEventListener('input', function(event) { onWsSlugInput(event.target.value); });
elements.submit.addEventListener('click', submitForm);
var exportButton = document.getElementById('export-workspace-btn');
if (exportButton) {
exportButton.addEventListener('click', exportWorkspaceSnapshot);
+7
View File
@@ -6,6 +6,13 @@ server {
root /usr/share/nginx/html;
index index.html;
add_header X-Frame-Options "DENY" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: blob:; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'" always;
location = / {
try_files /index.html =404;
}
+159 -129
View File
@@ -6,18 +6,20 @@
"": {
"name": "crank-ui",
"dependencies": {
"alpinejs": "3.15.9",
"js-yaml": "4.1.1"
"@fontsource/inter": "5.2.8",
"@fontsource/jetbrains-mono": "5.2.8",
"alpinejs": "3.15.12",
"js-yaml": "5.2.1"
},
"devDependencies": {
"@playwright/test": "^1.59.1",
"esbuild": "^0.28.0"
"@playwright/test": "1.61.1",
"esbuild": "0.28.1"
}
},
"node_modules/@esbuild/aix-ppc64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/aix-ppc64/-/aix-ppc64-0.28.0.tgz",
"integrity": "sha512-lhRUCeuOyJQURhTxl4WkpFTjIsbDayJHih5kZC1giwE+MhIzAb7mEsQMqMf18rHLsrb5qI1tafG20mLxEWcWlA==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/aix-ppc64/-/aix-ppc64-0.28.1.tgz",
"integrity": "sha512-Svl7tq8k/08+p6CXPpRjQ1fKX+1odH/BQbb48fV6fj3CWHhsoIOoY87w1oHXm0qEpkIK3ZfVgp0hed3XBXzXMQ==",
"cpu": [
"ppc64"
],
@@ -32,9 +34,9 @@
}
},
"node_modules/@esbuild/android-arm": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/android-arm/-/android-arm-0.28.0.tgz",
"integrity": "sha512-wqh0ByljabXLKHeWXYLqoJ5jKC4XBaw6Hk08OfMrCRd2nP2ZQ5eleDZC41XHyCNgktBGYMbqnrJKq/K/lzPMSQ==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/android-arm/-/android-arm-0.28.1.tgz",
"integrity": "sha512-0k2F129Xdio1TdJfzJ8sy1Q47vUD2NnwdhiAf7drUN1EBTfPf4hsFCtmMgu/6m8JSzsBrlmVjudMBQqOfG8usQ==",
"cpu": [
"arm"
],
@@ -49,9 +51,9 @@
}
},
"node_modules/@esbuild/android-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/android-arm64/-/android-arm64-0.28.0.tgz",
"integrity": "sha512-+WzIXQOSaGs33tLEgYPYe/yQHf0WTU0X42Jca3y8NWMbUVhp7rUnw+vAsRC/QiDrdD31IszMrZy+qwPOPjd+rw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/android-arm64/-/android-arm64-0.28.1.tgz",
"integrity": "sha512-34EGEbCIAgosYz6goLcopX6Mo7NyGv9tfwEM2/7Ce2VcVRk568iSvniGWcUXIy7wEDR1wzolcxcriFVrWYcwBg==",
"cpu": [
"arm64"
],
@@ -66,9 +68,9 @@
}
},
"node_modules/@esbuild/android-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/android-x64/-/android-x64-0.28.0.tgz",
"integrity": "sha512-+VJggoaKhk2VNNqVL7f6S189UzShHC/mR9EE8rDdSkdpN0KflSwWY/gWjDrNxxisg8Fp1ZCD9jLMo4m0OUfeUA==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/android-x64/-/android-x64-0.28.1.tgz",
"integrity": "sha512-dbwY7ltSMDWsRatcRpCnES4F+im88OCUgGZjy52shC7GqHRE/cYlxNbB4Z4UpJswpcc4Qxd2oE/ufM0p61IKng==",
"cpu": [
"x64"
],
@@ -83,9 +85,9 @@
}
},
"node_modules/@esbuild/darwin-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.28.0.tgz",
"integrity": "sha512-0T+A9WZm+bZ84nZBtk1ckYsOvyA3x7e2Acj1KdVfV4/2tdG4fzUp91YHx+GArWLtwqp77pBXVCPn2We7Letr0Q==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.28.1.tgz",
"integrity": "sha512-TZbWkQY7kvTAXbXUT7uVACR5cMHsDiSz9z7ZKAX/RTq/WJEk3QyRr0wZpNhBDX+/0CtdqUIJlOiodQcta6tY3Q==",
"cpu": [
"arm64"
],
@@ -100,9 +102,9 @@
}
},
"node_modules/@esbuild/darwin-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/darwin-x64/-/darwin-x64-0.28.0.tgz",
"integrity": "sha512-fyzLm/DLDl/84OCfp2f/XQ4flmORsjU7VKt8HLjvIXChJoFFOIL6pLJPH4Yhd1n1gGFF9mPwtlN5Wf82DZs+LQ==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/darwin-x64/-/darwin-x64-0.28.1.tgz",
"integrity": "sha512-zfdzgK9ACBNZLI/CyHTOx81SyNbM6YXn7rxSgX97VjyiPl9W1i4Ka4fgKECEoFCKGpvBj5qArWIGgQjOwkgskQ==",
"cpu": [
"x64"
],
@@ -117,9 +119,9 @@
}
},
"node_modules/@esbuild/freebsd-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/freebsd-arm64/-/freebsd-arm64-0.28.0.tgz",
"integrity": "sha512-l9GeW5UZBT9k9brBYI+0WDffcRxgHQD8ShN2Ur4xWq/NFzUKm3k5lsH4PdaRgb2w7mI9u61nr2gI2mLI27Nh3Q==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/freebsd-arm64/-/freebsd-arm64-0.28.1.tgz",
"integrity": "sha512-wG2EA8ENdEI0qhkSZMjfqrdY+ziCYCPMmtZjjIwOmXFjmyzEHn+UUxk5of+SYsjtfs3VpnlC7QLzSI5hY/rOAw==",
"cpu": [
"arm64"
],
@@ -134,9 +136,9 @@
}
},
"node_modules/@esbuild/freebsd-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/freebsd-x64/-/freebsd-x64-0.28.0.tgz",
"integrity": "sha512-BXoQai/A0wPO6Es3yFJ7APCiKGc1tdAEOgeTNy3SsB491S3aHn4S4r3e976eUnPdU+NbdtmBuLncYir2tMU9Nw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/freebsd-x64/-/freebsd-x64-0.28.1.tgz",
"integrity": "sha512-i7dZ9vQgnvSCzi/rYCXNgtF/U+eKZNJBzu3eTQbRgHnM7tNSizLOkRFAl3qzVc/Op/u5YkHHa4pf/3DOYHthLQ==",
"cpu": [
"x64"
],
@@ -151,9 +153,9 @@
}
},
"node_modules/@esbuild/linux-arm": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-arm/-/linux-arm-0.28.0.tgz",
"integrity": "sha512-CjaaREJagqJp7iTaNQjjidaNbCKYcd4IDkzbwwxtSvjI7NZm79qiHc8HqciMddQ6CKvJT6aBd8lO9kN/ZudLlw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-arm/-/linux-arm-0.28.1.tgz",
"integrity": "sha512-qVXBOHQS+d5Y722GwJzJUtOLlX7km3CraOaGormF1pDtPd2C/l1SHRPgjLunLGe51Sh5YYWKMFDyV4SxgMQYTQ==",
"cpu": [
"arm"
],
@@ -168,9 +170,9 @@
}
},
"node_modules/@esbuild/linux-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-arm64/-/linux-arm64-0.28.0.tgz",
"integrity": "sha512-RVyzfb3FWsGA55n6WY0MEIEPURL1FcbhFE6BffZEMEekfCzCIMtB5yyDcFnVbTnwk+CLAgTujmV/Lgvih56W+A==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-arm64/-/linux-arm64-0.28.1.tgz",
"integrity": "sha512-yHs+0uc8+nvEAfAfxrWQKK5peSNzBc4PegcMO0EJ2hT71uA7vB8Ihg2e77R2P7SG5uYjPbHlLLmve4LLLRCf0g==",
"cpu": [
"arm64"
],
@@ -185,9 +187,9 @@
}
},
"node_modules/@esbuild/linux-ia32": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-ia32/-/linux-ia32-0.28.0.tgz",
"integrity": "sha512-KBnSTt1kxl9x70q+ydterVdl+Cn0H18ngRMRCEQfrbqdUuntQQ0LoMZv47uB97NljZFzY6HcfqEZ2SAyIUTQBQ==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-ia32/-/linux-ia32-0.28.1.tgz",
"integrity": "sha512-d1z4ZuP0ajrfz/FhGT4vv278rX8KnPPJx8i5+AtK7TYbx9Le9F1hyzurZpkEyjkGa9dUGhQow4C1NmeGvqxN2w==",
"cpu": [
"ia32"
],
@@ -202,9 +204,9 @@
}
},
"node_modules/@esbuild/linux-loong64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-loong64/-/linux-loong64-0.28.0.tgz",
"integrity": "sha512-zpSlUce1mnxzgBADvxKXX5sl8aYQHo2ezvMNI8I0lbblJtp8V4odlm3Yzlj7gPyt3T8ReksE6bK+pT3WD+aJRg==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-loong64/-/linux-loong64-0.28.1.tgz",
"integrity": "sha512-M5sRjUVZrkm1OAPR3dlOYzNmN+loZKGVi1VUQGrwuqLcbR6qeAz+famMhjASeH3YVKvZz+zT1jlh/keC3Rj/lg==",
"cpu": [
"loong64"
],
@@ -219,9 +221,9 @@
}
},
"node_modules/@esbuild/linux-mips64el": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-mips64el/-/linux-mips64el-0.28.0.tgz",
"integrity": "sha512-2jIfP6mmjkdmeTlsX/9vmdmhBmKADrWqN7zcdtHIeNSCH1SqIoNI63cYsjQR8J+wGa4Y5izRcSHSm8K3QWmk3w==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-mips64el/-/linux-mips64el-0.28.1.tgz",
"integrity": "sha512-mRObBZeHh2OxcBFPWE/FjylkRgZdYuiTR3vaTozquCGOH14iP9oN4x4Ge81CoIDYQrXmIxpFumJBu5MtZpnQJQ==",
"cpu": [
"mips64el"
],
@@ -236,9 +238,9 @@
}
},
"node_modules/@esbuild/linux-ppc64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-ppc64/-/linux-ppc64-0.28.0.tgz",
"integrity": "sha512-bc0FE9wWeC0WBm49IQMPSPILRocGTQt3j5KPCA8os6VprfuJ7KD+5PzESSrJ6GmPIPJK965ZJHTUlSA6GNYEhg==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-ppc64/-/linux-ppc64-0.28.1.tgz",
"integrity": "sha512-slScBsMAb3GFDcdrCgLwZtPYRoH2H/youv10QiZyRjmsP48fznoveWytSgCI/R0ZcUgpc0ZhIUEx6LHts8yrfQ==",
"cpu": [
"ppc64"
],
@@ -253,9 +255,9 @@
}
},
"node_modules/@esbuild/linux-riscv64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-riscv64/-/linux-riscv64-0.28.0.tgz",
"integrity": "sha512-SQPZOwoTTT/HXFXQJG/vBX8sOFagGqvZyXcgLA3NhIqcBv1BJU1d46c0rGcrij2B56Z2rNiSLaZOYW5cUk7yLQ==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-riscv64/-/linux-riscv64-0.28.1.tgz",
"integrity": "sha512-kw0owk1o0GFETUJyW0jc0G4Yzs0BHZn0JDZ8JRT088vjJYX777BAs1fDGxAC+q831qOs2DTC96mNsG2opdfyyQ==",
"cpu": [
"riscv64"
],
@@ -270,9 +272,9 @@
}
},
"node_modules/@esbuild/linux-s390x": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-s390x/-/linux-s390x-0.28.0.tgz",
"integrity": "sha512-SCfR0HN8CEEjnYnySJTd2cw0k9OHB/YFzt5zgJEwa+wL/T/raGWYMBqwDNAC6dqFKmJYZoQBRfHjgwLHGSrn3Q==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-s390x/-/linux-s390x-0.28.1.tgz",
"integrity": "sha512-/lAIjX8aYFRByhh6L5rYtPEDRqa9de/4V/juOXcta5frjvzXO4/sqEtyytse0g3zZFuWu5cDN0MkLz2qRDD2Ag==",
"cpu": [
"s390x"
],
@@ -287,9 +289,9 @@
}
},
"node_modules/@esbuild/linux-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/linux-x64/-/linux-x64-0.28.0.tgz",
"integrity": "sha512-us0dSb9iFxIi8srnpl931Nvs65it/Jd2a2K3qs7fz2WfGPHqzfzZTfec7oxZJRNPXPnNYZtanmRc4AL/JwVzHQ==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/linux-x64/-/linux-x64-0.28.1.tgz",
"integrity": "sha512-u/anNYF2mmVOEDwLtnQ1wOr3EZ9sTNGLWrsYGYwHWzGA3Si84IOkHXlbWTD1NB+9/1lcnweYKO54uhxZydNzfA==",
"cpu": [
"x64"
],
@@ -304,9 +306,9 @@
}
},
"node_modules/@esbuild/netbsd-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/netbsd-arm64/-/netbsd-arm64-0.28.0.tgz",
"integrity": "sha512-CR/RYotgtCKwtftMwJlUU7xCVNg3lMYZ0RzTmAHSfLCXw3NtZtNpswLEj/Kkf6kEL3Gw+BpOekRX0BYCtklhUw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/netbsd-arm64/-/netbsd-arm64-0.28.1.tgz",
"integrity": "sha512-oks0DYbLwWMmaakTsCb+zL4E+aHRVLom9IJZOAthMQEPiQmydXHkziYEsGYRx0uNV/IjEKGAV941JzH02pflqw==",
"cpu": [
"arm64"
],
@@ -321,9 +323,9 @@
}
},
"node_modules/@esbuild/netbsd-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/netbsd-x64/-/netbsd-x64-0.28.0.tgz",
"integrity": "sha512-nU1yhmYutL+fQ71Kxnhg8uEOdC0pwEW9entHykTgEbna2pw2dkbFSMeqjjyHZoCmt8SBkOSvV+yNmm94aUrrqw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/netbsd-x64/-/netbsd-x64-0.28.1.tgz",
"integrity": "sha512-aeL6lAnN89Hz43Mlh1G8ARasbuoYvSITDEx0tHh5b7jJnHcssqgjy9Yx430GDpmCa6OyrKoS0aNRjKundRizGg==",
"cpu": [
"x64"
],
@@ -338,9 +340,9 @@
}
},
"node_modules/@esbuild/openbsd-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/openbsd-arm64/-/openbsd-arm64-0.28.0.tgz",
"integrity": "sha512-cXb5vApOsRsxsEl4mcZ1XY3D4DzcoMxR/nnc4IyqYs0rTI8ZKmW6kyyg+11Z8yvgMfAEldKzP7AdP64HnSC/6g==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/openbsd-arm64/-/openbsd-arm64-0.28.1.tgz",
"integrity": "sha512-MEFJe5C3R8pwXdZ5Y21oo6m7ePiS0d9pWucn99O/wvyJZChoIQKrQDxKrGeW8F5+T0okTHesAmDeiHDTIq0V/Q==",
"cpu": [
"arm64"
],
@@ -355,9 +357,9 @@
}
},
"node_modules/@esbuild/openbsd-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/openbsd-x64/-/openbsd-x64-0.28.0.tgz",
"integrity": "sha512-8wZM2qqtv9UP3mzy7HiGYNH/zjTA355mpeuA+859TyR+e+Tc08IHYpLJuMsfpDJwoLo1ikIJI8jC3GFjnRClzA==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/openbsd-x64/-/openbsd-x64-0.28.1.tgz",
"integrity": "sha512-i/ZLIOafE0Z8cI/XANJAixoJL/uRAoS2xOA3rb0xN+KK0K177cMAsQYkzHtBrtMXAKuAc7HGgcWiZ/sRC1Nxgw==",
"cpu": [
"x64"
],
@@ -372,9 +374,9 @@
}
},
"node_modules/@esbuild/openharmony-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/openharmony-arm64/-/openharmony-arm64-0.28.0.tgz",
"integrity": "sha512-FLGfyizszcef5C3YtoyQDACyg95+dndv79i2EekILBofh5wpCa1KuBqOWKrEHZg3zrL3t5ouE5jgr94vA+Wb2w==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/openharmony-arm64/-/openharmony-arm64-0.28.1.tgz",
"integrity": "sha512-ge+Z7EXFNt2BO1oAMsVpiQ8EwndV9i1xXerAeTIK7AtPs3bKFXQM7nlRxDSIUIMeueR1CNXxqztLzdNeReKBJg==",
"cpu": [
"arm64"
],
@@ -389,9 +391,9 @@
}
},
"node_modules/@esbuild/sunos-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/sunos-x64/-/sunos-x64-0.28.0.tgz",
"integrity": "sha512-1ZgjUoEdHZZl/YlV76TSCz9Hqj9h9YmMGAgAPYd+q4SicWNX3G5GCyx9uhQWSLcbvPW8Ni7lj4gDa1T40akdlw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/sunos-x64/-/sunos-x64-0.28.1.tgz",
"integrity": "sha512-BEjgtECkL3vY+SaSQ6nzVfiALUeFxpawyp8Jmf5PtYhf1Ug40N1h/hxlhts+f1FvSvarEigdxS3BlSMI2PJLcQ==",
"cpu": [
"x64"
],
@@ -406,9 +408,9 @@
}
},
"node_modules/@esbuild/win32-arm64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/win32-arm64/-/win32-arm64-0.28.0.tgz",
"integrity": "sha512-Q9StnDmQ/enxnpxCCLSg0oo4+34B9TdXpuyPeTedN/6+iXBJ4J+zwfQI28u/Jl40nOYAxGoNi7mFP40RUtkmUA==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/win32-arm64/-/win32-arm64-0.28.1.tgz",
"integrity": "sha512-lCv9eK/H6ZJWbE7bh2nw54CZ9M2nupBxJcTsdk/QQnWkdSjKGuxmmH8/GWrlT1eMmZfn4dGcCjRte397WqfQXA==",
"cpu": [
"arm64"
],
@@ -423,9 +425,9 @@
}
},
"node_modules/@esbuild/win32-ia32": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/win32-ia32/-/win32-ia32-0.28.0.tgz",
"integrity": "sha512-zF3ag/gfiCe6U2iczcRzSYJKH1DCI+ByzSENHlM2FcDbEeo5Zd2C86Aq0tKUYAJJ1obRP84ymxIAksZUcdztHA==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/win32-ia32/-/win32-ia32-0.28.1.tgz",
"integrity": "sha512-zvb/mB2bSCoJOpoCBgYKKpX6YM6mJBlBUVUtVj41DlZJVEB6/0CKlRYxP5wWl1C1ILiCoAU5wZZ4q1P3qeS6Eg==",
"cpu": [
"ia32"
],
@@ -440,9 +442,9 @@
}
},
"node_modules/@esbuild/win32-x64": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/@esbuild/win32-x64/-/win32-x64-0.28.0.tgz",
"integrity": "sha512-pEl1bO9mfAmIC+tW5btTmrKaujg3zGtUmWNdCw/xs70FBjwAL3o9OEKNHvNmnyylD6ubxUERiEhdsL0xBQ9efw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/@esbuild/win32-x64/-/win32-x64-0.28.1.tgz",
"integrity": "sha512-bm4Mowrv+GXMlpWX++EcXw/iLyd1o3+bJkC2DkWXYVvgZCqD/bSj9ctZeAMC3cIxgjRVR2Dufaiu4YPxr5gW1A==",
"cpu": [
"x64"
],
@@ -456,14 +458,32 @@
"node": ">=18"
}
},
"node_modules/@fontsource/inter": {
"version": "5.2.8",
"resolved": "https://registry.npmjs.org/@fontsource/inter/-/inter-5.2.8.tgz",
"integrity": "sha512-P6r5WnJoKiNVV+zvW2xM13gNdFhAEpQ9dQJHt3naLvfg+LkF2ldgSLiF4T41lf1SQCM9QmkqPTn4TH568IRagg==",
"license": "OFL-1.1",
"funding": {
"url": "https://github.com/sponsors/ayuhito"
}
},
"node_modules/@fontsource/jetbrains-mono": {
"version": "5.2.8",
"resolved": "https://registry.npmjs.org/@fontsource/jetbrains-mono/-/jetbrains-mono-5.2.8.tgz",
"integrity": "sha512-6w8/SG4kqvIMu7xd7wt6x3idn1Qux3p9N62s6G3rfldOUYHpWcc2FKrqf+Vo44jRvqWj2oAtTHrZXEP23oSKwQ==",
"license": "OFL-1.1",
"funding": {
"url": "https://github.com/sponsors/ayuhito"
}
},
"node_modules/@playwright/test": {
"version": "1.59.1",
"resolved": "https://registry.npmjs.org/@playwright/test/-/test-1.59.1.tgz",
"integrity": "sha512-PG6q63nQg5c9rIi4/Z5lR5IVF7yU5MqmKaPOe0HSc0O2cX1fPi96sUQu5j7eo4gKCkB2AnNGoWt7y4/Xx3Kcqg==",
"version": "1.61.1",
"resolved": "https://registry.npmjs.org/@playwright/test/-/test-1.61.1.tgz",
"integrity": "sha512-8nKv6+0RJSL9FE4jYOEGXnPeM/Hg12qZpmqzZjRh3qM0Y7c3z1mrOTfFLids72RDQYVh9WpLEfR5WdpNX4fkig==",
"dev": true,
"license": "Apache-2.0",
"dependencies": {
"playwright": "1.59.1"
"playwright": "1.61.1"
},
"bin": {
"playwright": "cli.js"
@@ -488,9 +508,9 @@
"license": "MIT"
},
"node_modules/alpinejs": {
"version": "3.15.9",
"resolved": "https://registry.npmjs.org/alpinejs/-/alpinejs-3.15.9.tgz",
"integrity": "sha512-O30m8Tw/aARbLXmeTnISAFgrNm0K71PT7bZy/1NgRqFD36QGb34VJ4a6WBL1iIO/bofN+LkIkKLikUTkfPL2wQ==",
"version": "3.15.12",
"resolved": "https://registry.npmjs.org/alpinejs/-/alpinejs-3.15.12.tgz",
"integrity": "sha512-nJvPAQVNPdZZ0NrExJ/kzQco3ijR8LwvCOadQecllESiqT4NyZ/57sN9V2XyvhlBGAbmlKYgeWZvYdKq99ij/Q==",
"license": "MIT",
"dependencies": {
"@vue/reactivity": "~3.1.1"
@@ -503,9 +523,9 @@
"license": "Python-2.0"
},
"node_modules/esbuild": {
"version": "0.28.0",
"resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.28.0.tgz",
"integrity": "sha512-sNR9MHpXSUV/XB4zmsFKN+QgVG82Cc7+/aaxJ8Adi8hyOac+EXptIp45QBPaVyX3N70664wRbTcLTOemCAnyqw==",
"version": "0.28.1",
"resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.28.1.tgz",
"integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw==",
"dev": true,
"hasInstallScript": true,
"license": "MIT",
@@ -516,32 +536,32 @@
"node": ">=18"
},
"optionalDependencies": {
"@esbuild/aix-ppc64": "0.28.0",
"@esbuild/android-arm": "0.28.0",
"@esbuild/android-arm64": "0.28.0",
"@esbuild/android-x64": "0.28.0",
"@esbuild/darwin-arm64": "0.28.0",
"@esbuild/darwin-x64": "0.28.0",
"@esbuild/freebsd-arm64": "0.28.0",
"@esbuild/freebsd-x64": "0.28.0",
"@esbuild/linux-arm": "0.28.0",
"@esbuild/linux-arm64": "0.28.0",
"@esbuild/linux-ia32": "0.28.0",
"@esbuild/linux-loong64": "0.28.0",
"@esbuild/linux-mips64el": "0.28.0",
"@esbuild/linux-ppc64": "0.28.0",
"@esbuild/linux-riscv64": "0.28.0",
"@esbuild/linux-s390x": "0.28.0",
"@esbuild/linux-x64": "0.28.0",
"@esbuild/netbsd-arm64": "0.28.0",
"@esbuild/netbsd-x64": "0.28.0",
"@esbuild/openbsd-arm64": "0.28.0",
"@esbuild/openbsd-x64": "0.28.0",
"@esbuild/openharmony-arm64": "0.28.0",
"@esbuild/sunos-x64": "0.28.0",
"@esbuild/win32-arm64": "0.28.0",
"@esbuild/win32-ia32": "0.28.0",
"@esbuild/win32-x64": "0.28.0"
"@esbuild/aix-ppc64": "0.28.1",
"@esbuild/android-arm": "0.28.1",
"@esbuild/android-arm64": "0.28.1",
"@esbuild/android-x64": "0.28.1",
"@esbuild/darwin-arm64": "0.28.1",
"@esbuild/darwin-x64": "0.28.1",
"@esbuild/freebsd-arm64": "0.28.1",
"@esbuild/freebsd-x64": "0.28.1",
"@esbuild/linux-arm": "0.28.1",
"@esbuild/linux-arm64": "0.28.1",
"@esbuild/linux-ia32": "0.28.1",
"@esbuild/linux-loong64": "0.28.1",
"@esbuild/linux-mips64el": "0.28.1",
"@esbuild/linux-ppc64": "0.28.1",
"@esbuild/linux-riscv64": "0.28.1",
"@esbuild/linux-s390x": "0.28.1",
"@esbuild/linux-x64": "0.28.1",
"@esbuild/netbsd-arm64": "0.28.1",
"@esbuild/netbsd-x64": "0.28.1",
"@esbuild/openbsd-arm64": "0.28.1",
"@esbuild/openbsd-x64": "0.28.1",
"@esbuild/openharmony-arm64": "0.28.1",
"@esbuild/sunos-x64": "0.28.1",
"@esbuild/win32-arm64": "0.28.1",
"@esbuild/win32-ia32": "0.28.1",
"@esbuild/win32-x64": "0.28.1"
}
},
"node_modules/fsevents": {
@@ -560,25 +580,35 @@
}
},
"node_modules/js-yaml": {
"version": "4.1.1",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz",
"integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==",
"version": "5.2.1",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.2.1.tgz",
"integrity": "sha512-zfLtNfQqxVqq3uaTqSkh4x4hZw3KHobGUA0fJUj4wawW8bsQLTVqpHdXSIzidh7o+4lEW36tANuAGdaFx6Zgnw==",
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/puzrin"
},
{
"type": "github",
"url": "https://github.com/sponsors/nodeca"
}
],
"license": "MIT",
"dependencies": {
"argparse": "^2.0.1"
},
"bin": {
"js-yaml": "bin/js-yaml.js"
"js-yaml": "bin/js-yaml.mjs"
}
},
"node_modules/playwright": {
"version": "1.59.1",
"resolved": "https://registry.npmjs.org/playwright/-/playwright-1.59.1.tgz",
"integrity": "sha512-C8oWjPR3F81yljW9o5OxcWzfh6avkVwDD2VYdwIGqTkl+OGFISgypqzfu7dOe4QNLL2aqcWBmI3PMtLIK233lw==",
"version": "1.61.1",
"resolved": "https://registry.npmjs.org/playwright/-/playwright-1.61.1.tgz",
"integrity": "sha512-DWnY5o3YbLWK4GovuAVwpqL+1VwGNdUGrRr++8j8PtQQzvAVZUIMjKQ90fY689sEJZJBbZVw1rXaOKSTitkzPQ==",
"dev": true,
"license": "Apache-2.0",
"dependencies": {
"playwright-core": "1.59.1"
"playwright-core": "1.61.1"
},
"bin": {
"playwright": "cli.js"
@@ -591,9 +621,9 @@
}
},
"node_modules/playwright-core": {
"version": "1.59.1",
"resolved": "https://registry.npmjs.org/playwright-core/-/playwright-core-1.59.1.tgz",
"integrity": "sha512-HBV/RJg81z5BiiZ9yPzIiClYV/QMsDCKUyogwH9p3MCP6IYjUFu/MActgYAvK0oWyV9NlwM3GLBjADyWgydVyg==",
"version": "1.61.1",
"resolved": "https://registry.npmjs.org/playwright-core/-/playwright-core-1.61.1.tgz",
"integrity": "sha512-h7Qlt6m4REp25qvIdvbDtVmD4LqVXfpRxhORv9L0jzETM05p4fuPJ3dKyuSXQxDSbXnmS79HAgi9589lGSpLkg==",
"dev": true,
"license": "Apache-2.0",
"bin": {
+6 -4
View File
@@ -8,11 +8,13 @@
"e2e:headed": "playwright test --headed"
},
"dependencies": {
"alpinejs": "3.15.9",
"js-yaml": "4.1.1"
"@fontsource/inter": "5.2.8",
"@fontsource/jetbrains-mono": "5.2.8",
"alpinejs": "3.15.12",
"js-yaml": "5.2.1"
},
"devDependencies": {
"@playwright/test": "^1.59.1",
"esbuild": "^0.28.0"
"@playwright/test": "1.61.1",
"esbuild": "0.28.1"
}
}
+20 -1
View File
@@ -10,6 +10,10 @@ const BRAND_IMAGE_PATHS = [
path.join(ROOT_DIR, 'crank-community.png'),
path.resolve(ROOT_DIR, '..', '..', 'crank-community.png'),
];
const FONT_FILES = [
['@fontsource/inter', 'inter', ['400', '500', '600', '700']],
['@fontsource/jetbrains-mono', 'jetbrains-mono', ['400', '500']],
];
const BUNDLES = {
'protected-core': {
@@ -89,7 +93,7 @@ const BUNDLES = {
},
wizard: {
files: [
'node_modules/js-yaml/dist/js-yaml.min.js',
'node_modules/js-yaml/dist/browser/js-yaml.umd.min.js',
'js/wizard-state.js',
'js/wizard-shell.js',
'js/wizard-upstreams.js',
@@ -136,6 +140,20 @@ function copyDirectory(source, destination) {
}
}
function copyFonts() {
FONT_FILES.forEach(function([packageName, family, weights]) {
weights.forEach(function(weight) {
['latin', 'cyrillic'].forEach(function(subset) {
var fileName = `${family}-${subset}-${weight}-normal.woff2`;
copyFile(
path.join(ROOT_DIR, 'node_modules', packageName, 'files', fileName),
path.join(DIST_DIR, 'fonts', fileName)
);
});
});
});
}
function readSource(relativePath) {
return fs.readFileSync(sourcePath(relativePath), 'utf8');
}
@@ -191,6 +209,7 @@ async function main() {
}
copyDirectory(path.join(ROOT_DIR, 'css'), path.join(DIST_DIR, 'css'));
copyFonts();
copyDirectory(path.join(ROOT_DIR, 'data'), path.join(DIST_DIR, 'data'));
ensureDirectory(path.join(DIST_DIR, 'html', 'wizard'));
[
+11 -1
View File
@@ -119,8 +119,18 @@ function proxyRequest(request, response) {
},
},
(proxyResponse) => {
if (response.destroyed || response.writableEnded) {
proxyResponse.resume();
return;
}
response.writeHead(proxyResponse.statusCode || 502, proxyResponse.headers);
pipeline(proxyResponse, response, () => {});
proxyResponse.on('error', function() {
if (!response.destroyed) response.destroy();
});
response.on('close', function() {
if (!proxyResponse.destroyed) proxyResponse.destroy();
});
proxyResponse.pipe(response);
},
);
+18 -1
View File
@@ -22,8 +22,25 @@ test('api keys page opens create key flow', async ({ page }) => {
await expect(page.locator('#btn-create-key')).toBeEnabled();
await page.locator('#btn-create-key').click();
await expect(page.locator('#modal-create')).toHaveClass(/open/);
await expect(page.locator('.modal-title')).toHaveText(localized('Create agent key', 'Создать ключ агента'));
await expect(page.locator('.modal-title')).toHaveText(localized('Create MCP client key', 'Создать ключ MCP-клиента'));
await page.locator('#new-key-name').fill(`playwright-${Date.now()}`);
await page.locator('#modal-confirm-btn').click();
await expect(page.locator('#modal-reveal-body')).toContainText(localized('Copy this key now', 'Скопируйте этот ключ сейчас'));
await page.locator('#modal-done-btn').click();
await page.locator('#key-kind-approval').click();
await expect(page.locator('#key-kind-hint')).toContainText(
localized('human confirmation interface', 'человек подтверждает действие')
);
await expect(page.locator('#btn-create-key')).toContainText(
localized('Create approval key', 'Создать ключ подтверждения')
);
await page.locator('#btn-create-key').click();
await expect(page.locator('.modal-title')).toHaveText(localized('Create approval key', 'Создать ключ подтверждения'));
await expect(page.locator('#approval-key-warning')).toContainText(
localized('Do not pass this key to an LLM', 'Не передавайте этот ключ LLM')
);
await page.locator('#new-key-name').fill(`playwright-approval-${Date.now()}`);
await page.locator('#modal-confirm-btn').click();
await expect(page.locator('#reveal-key-value')).toContainText('crk_appr_');
});
+53
View File
@@ -1,6 +1,29 @@
const { test, expect } = require('@playwright/test');
const { getCurrentWorkspace, login, localized } = require('./helpers');
test('mobile wizard progress connector crosses the indicator centers', async ({ page }) => {
await page.setViewportSize({ width: 720, height: 900 });
await login(page);
await page.goto('/wizard/');
const geometry = await page.locator('.steps-list').evaluate((list) => {
const indicators = [...list.querySelectorAll('.step-indicator')];
const first = indicators[0].getBoundingClientRect();
const last = indicators.at(-1).getBoundingClientRect();
const listRect = list.getBoundingClientRect();
const line = getComputedStyle(list, '::before');
return {
leftDelta: Math.abs(listRect.left + Number.parseFloat(line.left) - (first.left + first.width / 2)),
rightDelta: Math.abs(listRect.right - Number.parseFloat(line.right) - (last.left + last.width / 2)),
topDelta: Math.abs(listRect.top + Number.parseFloat(line.top) - (first.top + first.height / 2)),
};
});
expect(geometry.leftDelta).toBeLessThan(1);
expect(geometry.rightDelta).toBeLessThan(1);
expect(geometry.topDelta).toBeLessThan(1);
});
test('wizard loads and protocol selection updates flow', async ({ page }) => {
await login(page);
await page.goto('/wizard/');
@@ -550,6 +573,13 @@ test('wizard shows agent-facing MCP preview from current draft fields', async ({
headers: {},
protocol_options: null,
streaming: null,
approval_policy: {
required: true,
risk_level: 'financial',
ttl_seconds: 180,
show_payload_preview: true,
payload_preview_mode: 'masked_json',
},
},
tool_description: {
title: 'Получить историю курсов за месяц',
@@ -765,6 +795,13 @@ test('wizard edit mode preserves explicit request mapping targets on save', asyn
headers: {},
protocol_options: null,
streaming: null,
approval_policy: {
required: true,
risk_level: 'financial',
ttl_seconds: 180,
show_payload_preview: true,
payload_preview_mode: 'masked_json',
},
},
tool_description: {
title: 'Получить последний курс',
@@ -810,6 +847,13 @@ test('wizard edit mode preserves explicit request mapping targets on save', asyn
await expect(page.locator('#tool-input-mapping')).toHaveValue(/query\.base/);
await expect(page.locator('#tool-input-mapping')).toHaveValue(/path\.date/);
await expect(page.locator('#tool-input-mapping')).toHaveValue(/transform: to_string/);
await page.evaluate(() => window.CrankWizardShell.doGoToStep(3));
await expect(page.locator('#approval-required')).toBeChecked();
await expect(page.locator('#approval-config-fields')).toBeVisible();
await expect(page.locator('#approval-mode')).toHaveValue('custom');
await expect(page.locator('#approval-risk-level')).toHaveCount(0);
await expect(page.locator('#approval-ttl-seconds')).toHaveValue('180');
await expect(page.locator('#approval-payload-preview-mode')).toHaveCount(0);
await page.locator('.btn-save-draft').click();
await expect.poll(() => updatePayload).not.toBeNull();
@@ -835,6 +879,15 @@ test('wizard edit mode preserves explicit request mapping targets on save', asyn
headers: {},
protocol_options: null,
streaming: null,
approval_policy: {
required: true,
mode: 'custom',
risk_level: 'normal',
ttl_seconds: 180,
show_payload_preview: true,
payload_preview_mode: 'summary',
elicitation_message: null,
},
});
expect(updatePayload.tool_description).toEqual({
title: 'Получить последний курс',
+320 -10
View File
@@ -1,9 +1,18 @@
use std::{collections::BTreeMap, time::Duration};
use std::{
collections::BTreeMap,
env, io,
net::{IpAddr, Ipv4Addr, Ipv6Addr, SocketAddr},
sync::Arc,
time::Duration,
};
use crank_core::{HttpMethod, RestTarget};
use futures_util::StreamExt;
use reqwest::{
Client,
dns::{Addrs, Name, Resolve, Resolving},
header::{HeaderMap, HeaderName, HeaderValue},
redirect,
};
use serde_json::Value;
@@ -11,9 +20,19 @@ use crate::{RestAdapterError, RestRequest, RestResponse};
#[derive(Clone, Debug)]
pub struct RestAdapter {
client: Client,
client: Result<Client, Arc<str>>,
policy: OutboundHttpPolicy,
}
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct OutboundHttpPolicy {
allowed_hosts: Vec<String>,
denied_hosts: Vec<String>,
max_response_bytes: usize,
}
const DEFAULT_MAX_RESPONSE_BYTES: usize = 4 * 1024 * 1024;
impl Default for RestAdapter {
fn default() -> Self {
Self::new()
@@ -22,9 +41,25 @@ impl Default for RestAdapter {
impl RestAdapter {
pub fn new() -> Self {
Self {
client: Client::new(),
}
Self::with_policy(OutboundHttpPolicy::default())
}
pub fn from_env() -> Result<Self, RestAdapterError> {
Ok(Self::with_policy(OutboundHttpPolicy::from_env()?))
}
pub fn with_policy(policy: OutboundHttpPolicy) -> Self {
let resolver = Arc::new(PolicyDnsResolver {
policy: policy.clone(),
});
let client = Client::builder()
.redirect(redirect::Policy::none())
.no_proxy()
.dns_resolver(resolver)
.build()
.map_err(|error| Arc::<str>::from(error.to_string()));
Self { client, policy }
}
pub async fn execute(
@@ -33,9 +68,15 @@ impl RestAdapter {
request: &RestRequest,
) -> Result<RestResponse, RestAdapterError> {
let url = build_url(target, request)?;
self.policy.validate_url(&url)?;
let headers = build_headers(target, request)?;
let mut builder = self
.client
let client =
self.client
.as_ref()
.map_err(|details| RestAdapterError::InvalidConfiguration {
details: details.to_string(),
})?;
let mut builder = client
.request(to_reqwest_method(target.method), url)
.headers(headers)
.timeout(Duration::from_millis(request.timeout_ms));
@@ -47,7 +88,7 @@ impl RestAdapter {
let response = builder.send().await?;
let status = response.status();
let headers = normalize_headers(response.headers());
let body = decode_body(response).await?;
let body = decode_body(response, self.policy.max_response_bytes).await?;
if !status.is_success() {
return Err(RestAdapterError::UnexpectedStatus {
@@ -64,6 +105,254 @@ impl RestAdapter {
}
}
impl Default for OutboundHttpPolicy {
fn default() -> Self {
Self {
allowed_hosts: Vec::new(),
denied_hosts: Vec::new(),
max_response_bytes: DEFAULT_MAX_RESPONSE_BYTES,
}
}
}
impl OutboundHttpPolicy {
pub fn from_env() -> Result<Self, RestAdapterError> {
let max_response_bytes = match env::var("CRANK_OUTBOUND_MAX_RESPONSE_BYTES") {
Ok(value) => {
value
.parse::<usize>()
.map_err(|_| RestAdapterError::InvalidConfiguration {
details: "CRANK_OUTBOUND_MAX_RESPONSE_BYTES must be a positive integer"
.to_owned(),
})?
}
Err(env::VarError::NotPresent) => DEFAULT_MAX_RESPONSE_BYTES,
Err(error) => {
return Err(RestAdapterError::InvalidConfiguration {
details: error.to_string(),
});
}
};
if max_response_bytes == 0 {
return Err(RestAdapterError::InvalidConfiguration {
details: "CRANK_OUTBOUND_MAX_RESPONSE_BYTES must be greater than zero".to_owned(),
});
}
Ok(Self {
allowed_hosts: host_patterns_from_env("CRANK_OUTBOUND_ALLOWED_HOSTS")?,
denied_hosts: host_patterns_from_env("CRANK_OUTBOUND_DENIED_HOSTS")?,
max_response_bytes,
})
}
pub fn allowing_hosts(hosts: impl IntoIterator<Item = impl Into<String>>) -> Self {
Self {
allowed_hosts: hosts.into_iter().map(Into::into).collect(),
..Self::default()
}
}
pub fn with_max_response_bytes(mut self, max_response_bytes: usize) -> Self {
self.max_response_bytes = max_response_bytes;
self
}
pub fn validate_base_url(&self, base_url: &str) -> Result<(), RestAdapterError> {
let url = reqwest::Url::parse(base_url).map_err(|_| RestAdapterError::InvalidBaseUrl {
url: base_url.to_owned(),
})?;
self.validate_url(&url)
}
fn validate_url(&self, url: &reqwest::Url) -> Result<(), RestAdapterError> {
if !matches!(url.scheme(), "http" | "https")
|| !url.username().is_empty()
|| url.password().is_some()
{
return Err(RestAdapterError::TargetNotAllowed {
target: url.to_string(),
});
}
let host = url
.host_str()
.ok_or_else(|| RestAdapterError::TargetNotAllowed {
target: url.to_string(),
})?;
self.validate_host(host)?;
if !self.is_explicitly_allowed(host) && is_local_hostname(host) {
return Err(RestAdapterError::TargetNotAllowed {
target: host.to_owned(),
});
}
if let Ok(address) = host.parse::<IpAddr>()
&& !self.is_explicitly_allowed(host)
&& !is_public_ip(address)
{
return Err(RestAdapterError::TargetNotAllowed {
target: host.to_owned(),
});
}
Ok(())
}
fn validate_host(&self, host: &str) -> Result<(), RestAdapterError> {
let host = normalize_host(host);
let denied = self
.denied_hosts
.iter()
.any(|pattern| host_matches(pattern, &host));
if denied {
return Err(RestAdapterError::TargetNotAllowed { target: host });
}
Ok(())
}
fn is_explicitly_allowed(&self, host: &str) -> bool {
let host = normalize_host(host);
self.allowed_hosts
.iter()
.any(|pattern| host_matches(pattern, &host))
}
}
#[derive(Clone, Debug)]
struct PolicyDnsResolver {
policy: OutboundHttpPolicy,
}
impl Resolve for PolicyDnsResolver {
fn resolve(&self, name: Name) -> Resolving {
let host = normalize_host(name.as_str());
let policy = self.policy.clone();
Box::pin(async move {
policy
.validate_host(&host)
.map_err(|error| boxed_io_error(error.to_string()))?;
let explicitly_allowed = policy.is_explicitly_allowed(&host);
let resolved = tokio::net::lookup_host((host.as_str(), 0))
.await
.map_err(|error| Box::new(error) as Box<dyn std::error::Error + Send + Sync>)?;
let addresses = resolved
.filter(|address| explicitly_allowed || is_public_ip(address.ip()))
.collect::<Vec<SocketAddr>>();
if addresses.is_empty() {
return Err(boxed_io_error(format!(
"outbound target {host} did not resolve to an allowed address"
)));
}
Ok(Box::new(addresses.into_iter()) as Addrs)
})
}
}
fn boxed_io_error(message: String) -> Box<dyn std::error::Error + Send + Sync> {
Box::new(io::Error::new(io::ErrorKind::PermissionDenied, message))
}
fn host_patterns_from_env(name: &str) -> Result<Vec<String>, RestAdapterError> {
let value = match env::var(name) {
Ok(value) => value,
Err(env::VarError::NotPresent) => return Ok(Vec::new()),
Err(error) => {
return Err(RestAdapterError::InvalidConfiguration {
details: error.to_string(),
});
}
};
value
.split(',')
.map(str::trim)
.filter(|value| !value.is_empty())
.map(|value| {
let wildcard = value.starts_with("*.");
let normalized = normalize_host(value.trim_start_matches("*."));
let valid_ip = !wildcard && normalized.parse::<IpAddr>().is_ok();
if normalized.is_empty()
|| normalized.contains('/')
|| (!valid_ip && normalized.contains(':'))
|| (wildcard && normalized.parse::<IpAddr>().is_ok())
{
return Err(RestAdapterError::InvalidConfiguration {
details: format!("{name} contains an invalid host pattern: {value}"),
});
}
Ok(if wildcard {
format!("*.{normalized}")
} else {
normalized
})
})
.collect()
}
fn normalize_host(host: &str) -> String {
host.trim()
.trim_start_matches('[')
.trim_end_matches(']')
.trim_end_matches('.')
.to_ascii_lowercase()
}
fn is_local_hostname(host: &str) -> bool {
let host = normalize_host(host);
host == "localhost" || host.ends_with(".localhost")
}
fn host_matches(pattern: &str, host: &str) -> bool {
pattern.strip_prefix("*.").map_or_else(
|| pattern == host,
|suffix| host != suffix && host.ends_with(&format!(".{suffix}")),
)
}
fn is_public_ip(address: IpAddr) -> bool {
match address {
IpAddr::V4(address) => is_public_ipv4(address),
IpAddr::V6(address) => is_public_ipv6(address),
}
}
fn is_public_ipv4(address: Ipv4Addr) -> bool {
let octets = address.octets();
!(address.is_private()
|| address.is_loopback()
|| address.is_link_local()
|| address.is_broadcast()
|| address.is_documentation()
|| address.is_unspecified()
|| address.is_multicast()
|| octets[0] == 0
|| (octets[0] == 100 && (64..=127).contains(&octets[1]))
|| (octets[0] == 192 && octets[1] == 0 && octets[2] == 0)
|| (octets[0] == 198 && (18..=19).contains(&octets[1]))
|| octets[0] >= 240)
}
fn is_public_ipv6(address: Ipv6Addr) -> bool {
let segments = address.segments();
if let Some(address) = address.to_ipv4_mapped() {
return is_public_ipv4(address);
}
if segments[..6].iter().all(|segment| *segment == 0) {
let [a, b] = segments[6].to_be_bytes();
let [c, d] = segments[7].to_be_bytes();
return is_public_ipv4(Ipv4Addr::new(a, b, c, d));
}
!(address.is_unspecified()
|| address.is_loopback()
|| address.is_multicast()
|| (segments[0] & 0xfe00) == 0xfc00
|| (segments[0] & 0xffc0) == 0xfe80
|| (segments[0] & 0xffc0) == 0xfec0
|| (segments[0] == 0x0064
&& segments[1] == 0xff9b
&& segments[2..6].iter().all(|segment| *segment == 0))
|| (segments[0] == 0x0064 && segments[1] == 0xff9b && segments[2] == 1)
|| segments[0] == 0x2002
|| (segments[0] == 0x2001 && matches!(segments[1], 0 | 0x0db8)))
}
fn build_url(target: &RestTarget, request: &RestRequest) -> Result<reqwest::Url, RestAdapterError> {
let base_url =
reqwest::Url::parse(&target.base_url).map_err(|_| RestAdapterError::InvalidBaseUrl {
@@ -127,8 +416,29 @@ fn insert_header(headers: &mut HeaderMap, name: &str, value: &str) -> Result<(),
Ok(())
}
async fn decode_body(response: reqwest::Response) -> Result<Value, RestAdapterError> {
let bytes = response.bytes().await?;
async fn decode_body(
response: reqwest::Response,
max_response_bytes: usize,
) -> Result<Value, RestAdapterError> {
if response
.content_length()
.is_some_and(|length| length > max_response_bytes as u64)
{
return Err(RestAdapterError::ResponseTooLarge {
limit_bytes: max_response_bytes,
});
}
let mut stream = response.bytes_stream();
let mut bytes = Vec::new();
while let Some(chunk) = stream.next().await {
let chunk = chunk?;
if bytes.len().saturating_add(chunk.len()) > max_response_bytes {
return Err(RestAdapterError::ResponseTooLarge {
limit_bytes: max_response_bytes,
});
}
bytes.extend_from_slice(&chunk);
}
if bytes.is_empty() {
return Ok(Value::Null);
+6
View File
@@ -13,6 +13,12 @@ pub enum RestAdapterError {
InvalidHeaderName { header: String },
#[error("invalid header value for {header}")]
InvalidHeaderValue { header: String },
#[error("outbound target is not allowed: {target}")]
TargetNotAllowed { target: String },
#[error("rest response exceeds the configured limit of {limit_bytes} bytes")]
ResponseTooLarge { limit_bytes: usize },
#[error("invalid outbound HTTP configuration: {details}")]
InvalidConfiguration { details: String },
#[error("request failed")]
Transport(#[from] reqwest::Error),
#[error("sse collection window expired before stream completed")]
+1 -1
View File
@@ -8,7 +8,7 @@ use crank_core::{
ProtocolAdapterError, RestTarget, RuntimeRequestContext, Target,
};
pub use client::RestAdapter;
pub use client::{OutboundHttpPolicy, RestAdapter};
pub use error::RestAdapterError;
pub use model::{RestRequest, RestResponse};
@@ -3,10 +3,11 @@ use std::collections::BTreeMap;
use axum::{
Json, Router,
extract::{Path, Query},
http::HeaderMap,
http::{HeaderMap, StatusCode},
response::Redirect,
routing::{get, post},
};
use crank_adapter_rest::{RestAdapter, RestAdapterError, RestRequest};
use crank_adapter_rest::{OutboundHttpPolicy, RestAdapter, RestAdapterError, RestRequest};
use crank_core::{HttpMethod, RestTarget};
use serde_json::{Value, json};
use tokio::net::TcpListener;
@@ -14,7 +15,7 @@ use tokio::net::TcpListener;
#[tokio::test]
async fn executes_rest_request_and_normalizes_json_response() {
let base_url = spawn_test_server().await;
let adapter = RestAdapter::new();
let adapter = test_adapter();
let target = RestTarget {
base_url,
method: HttpMethod::Post,
@@ -47,7 +48,7 @@ async fn executes_rest_request_and_normalizes_json_response() {
#[tokio::test]
async fn returns_unexpected_status_with_normalized_body() {
let base_url = spawn_test_server().await;
let adapter = RestAdapter::new();
let adapter = test_adapter();
let target = RestTarget {
base_url,
method: HttpMethod::Get,
@@ -73,10 +74,94 @@ async fn returns_unexpected_status_with_normalized_body() {
));
}
#[test]
fn rejects_private_targets_by_default() {
let policy = OutboundHttpPolicy::default();
let error = policy
.validate_base_url("http://127.0.0.1:8080")
.unwrap_err();
assert!(matches!(error, RestAdapterError::TargetNotAllowed { .. }));
}
#[test]
fn accepts_explicit_private_ipv4_and_ipv6_targets() {
let policy = OutboundHttpPolicy::allowing_hosts(["192.168.1.10", "::1"]);
assert!(policy.validate_base_url("http://192.168.1.10:8080").is_ok());
assert!(policy.validate_base_url("http://[::1]:8080").is_ok());
}
#[tokio::test]
async fn does_not_follow_redirects() {
let base_url = spawn_test_server().await;
let adapter = test_adapter();
let target = RestTarget {
base_url,
method: HttpMethod::Get,
path_template: "/redirect".to_owned(),
static_headers: BTreeMap::new(),
};
let error = adapter
.execute(&target, &empty_request())
.await
.unwrap_err();
assert!(matches!(
error,
RestAdapterError::UnexpectedStatus { status: 303, .. }
));
}
#[tokio::test]
async fn rejects_responses_over_the_configured_limit() {
let base_url = spawn_test_server().await;
let adapter = RestAdapter::with_policy(
OutboundHttpPolicy::allowing_hosts(["127.0.0.1"]).with_max_response_bytes(8),
);
let target = RestTarget {
base_url,
method: HttpMethod::Get,
path_template: "/large".to_owned(),
static_headers: BTreeMap::new(),
};
let error = adapter
.execute(&target, &empty_request())
.await
.unwrap_err();
assert!(matches!(
error,
RestAdapterError::ResponseTooLarge { limit_bytes: 8 }
));
}
fn empty_request() -> RestRequest {
RestRequest {
path_params: BTreeMap::new(),
query_params: BTreeMap::new(),
headers: BTreeMap::new(),
body: None,
timeout_ms: 1_000,
}
}
fn test_adapter() -> RestAdapter {
RestAdapter::with_policy(OutboundHttpPolicy::allowing_hosts(["127.0.0.1"]))
}
async fn spawn_test_server() -> String {
let app = Router::new()
.route("/users/{user_id}", post(create_user))
.route("/fail", get(fail));
.route("/fail", get(fail))
.route("/redirect", get(|| async { Redirect::to("/large") }))
.route(
"/large",
get(|| async { "response larger than eight bytes" }),
);
let listener = TcpListener::bind("127.0.0.1:0").await.unwrap();
let address = listener.local_addr().unwrap();
@@ -113,7 +198,7 @@ async fn create_user(
async fn fail() -> (axum::http::StatusCode, Json<Value>) {
(
axum::http::StatusCode::BAD_GATEWAY,
StatusCode::BAD_GATEWAY,
Json(json!({ "error": "upstream failed" })),
)
}
@@ -1,7 +1,7 @@
use axum_extra::extract::cookie::{Cookie, CookieJar, SameSite};
use base64::{Engine as _, engine::general_purpose::URL_SAFE_NO_PAD};
use crank_core::UserSessionId;
use rand::RngCore;
use rand::RngExt;
use sha2::{Digest, Sha256};
use time::{Duration, OffsetDateTime};
@@ -23,7 +23,7 @@ pub enum SessionCookieError {
pub fn create_session_cookie(session_ttl_hours: i64) -> Result<SessionCookie, SessionCookieError> {
let session_id = UserSessionId::new(format!("sess_{}", uuid::Uuid::now_v7().simple()));
let mut secret_bytes = [0_u8; 32];
rand::thread_rng().fill_bytes(&mut secret_bytes);
rand::rng().fill(&mut secret_bytes);
let secret = URL_SAFE_NO_PAD.encode(secret_bytes);
let expires_at = OffsetDateTime::now_utc()
.checked_add(Duration::hours(session_ttl_hours))
+1
View File
@@ -15,6 +15,7 @@ crank-registry = { path = "../crank-registry" }
crank-runtime = { path = "../crank-runtime" }
crank-schema = { path = "../crank-schema" }
futures-util = "0.3"
reqwest.workspace = true
serde.workspace = true
serde_json.workspace = true
sha2.workspace = true
+52
View File
@@ -27,6 +27,41 @@ pub(super) async fn require_machine_access(
Ok(credential)
}
pub(super) async fn require_approval_access(
state: &Arc<AppState>,
path: &AgentRoutePath,
headers: &HeaderMap,
required_scope: PlatformApiKeyScope,
) -> Result<crank_registry::PlatformApiKeyRecord, StatusCode> {
let secret = bearer_token(headers).ok_or(StatusCode::UNAUTHORIZED)?;
let secret_hash = hash_access_secret(secret);
let Some(api_key) = state
.registry
.get_approval_api_key_by_secret_for_agent_slug(
&path.workspace_slug,
&path.agent_slug,
&secret_hash,
)
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR)?
else {
return Err(StatusCode::UNAUTHORIZED);
};
if !approval_allows_scope(&api_key.api_key.scopes, required_scope) {
return Err(StatusCode::FORBIDDEN);
}
let used_at = OffsetDateTime::now_utc();
state
.registry
.touch_platform_api_key(&api_key.api_key.workspace_id, &api_key.api_key.id, &used_at)
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR)?;
Ok(api_key)
}
pub(super) fn bearer_token(headers: &HeaderMap) -> Option<&str> {
let value = headers.get(AUTHORIZATION)?.to_str().ok()?;
let (scheme, token) = value.split_once(' ')?;
@@ -130,9 +165,26 @@ fn allows_scope(scopes: &[PlatformApiKeyScope], required_scope: PlatformApiKeySc
PlatformApiKeyScope::Deploy => scopes
.iter()
.any(|scope| matches!(scope, PlatformApiKeyScope::Deploy)),
PlatformApiKeyScope::Approve
| PlatformApiKeyScope::Deny
| PlatformApiKeyScope::ReadPending => false,
}
}
fn approval_allows_scope(
scopes: &[PlatformApiKeyScope],
required_scope: PlatformApiKeyScope,
) -> bool {
scopes.iter().any(|scope| match required_scope {
PlatformApiKeyScope::Approve => matches!(scope, PlatformApiKeyScope::Approve),
PlatformApiKeyScope::Deny => matches!(scope, PlatformApiKeyScope::Deny),
PlatformApiKeyScope::ReadPending => matches!(scope, PlatformApiKeyScope::ReadPending),
PlatformApiKeyScope::Read | PlatformApiKeyScope::Write | PlatformApiKeyScope::Deploy => {
false
}
})
}
fn security_level_rank(level: OperationSecurityLevel) -> u8 {
match level {
OperationSecurityLevel::Standard => 0,
+602 -45
View File
@@ -10,13 +10,17 @@ use axum::{
extract::{Path, State},
http::{HeaderMap, StatusCode},
response::{IntoResponse, Response, sse::Event},
routing::get,
routing::{get, post},
};
use crank_core::{
AuthProfile, CoordinationStateStore, InvocationLevel, InvocationLog, InvocationLogId,
InvocationSource, InvocationStatus, PlatformApiKeyScope, SecretId,
ApprovalRequest, ApprovalRequestId, ApprovalRequestStatus, AuthProfile, CoordinationStateStore,
InvocationLevel, InvocationLog, InvocationLogId, InvocationSource, InvocationStatus,
OperationApprovalMode, PlatformApiKeyScope, SecretId,
};
use crank_registry::{
CreateApprovalRequest, CreateInvocationLogRequest, DecideApprovalRequest,
ExpireApprovalRequest, PostgresRegistry, PublishedAgentTool,
};
use crank_registry::{CreateInvocationLogRequest, PostgresRegistry, PublishedAgentTool};
use crank_runtime::{
RequestRateLimiter, ResolvedAuth, RuntimeError, RuntimeExecutionRequest, RuntimeExecutor,
RuntimeOperation, RuntimeRequestContext, SecretCrypto,
@@ -25,13 +29,14 @@ use futures_util::stream;
use serde::{Deserialize, Serialize};
use serde_json::{Value, json};
use time::OffsetDateTime;
use tracing::info;
use tracing::{info, warn};
use crate::{
access::{
credential_allows_security_level, require_machine_access, serialize_machine_access_mode,
serialize_security_level,
credential_allows_security_level, require_approval_access, require_machine_access,
serialize_machine_access_mode, serialize_security_level,
},
approval_execution::{execute_approved_request, spawn_approval_recovery},
auth::{SharedMachineCredentialVerifier, VerifiedMachineCredential},
catalog::PublishedToolCatalog,
jsonrpc::{
@@ -61,8 +66,8 @@ const TRANSPORT_SESSION_TTL_MS: u64 = 86_400_000;
#[derive(Clone)]
pub(super) struct AppState {
pub(super) registry: PostgresRegistry,
catalog: PublishedToolCatalog,
runtime: RuntimeExecutor,
pub(super) catalog: PublishedToolCatalog,
pub(super) runtime: RuntimeExecutor,
pub(super) api_rate_limiter: RequestRateLimiter,
secret_crypto: SecretCrypto,
sessions: SharedSessionStore,
@@ -74,6 +79,8 @@ pub(super) struct AppState {
struct InitializeParams {
#[serde(rename = "protocolVersion")]
protocol_version: String,
#[serde(default)]
capabilities: Value,
}
#[derive(Debug, Serialize, Deserialize)]
@@ -83,6 +90,13 @@ struct ToolCallParams {
arguments: Value,
}
#[derive(Debug, Deserialize)]
struct ApprovalDecisionPayload {
approve: String,
#[serde(default)]
note: Option<String>,
}
#[derive(Clone)]
struct ResolvedToolCall {
tool: PublishedAgentTool,
@@ -100,6 +114,13 @@ pub(super) struct AgentRoutePath {
pub(super) agent_slug: String,
}
#[derive(Clone, Debug, Deserialize)]
struct ApprovalRoutePath {
workspace_slug: String,
agent_slug: String,
approval_id: String,
}
#[allow(clippy::too_many_arguments)]
pub fn build_app(
registry: PostgresRegistry,
@@ -111,6 +132,59 @@ pub fn build_app(
coordination_store: Arc<dyn CoordinationStateStore>,
sessions: SharedSessionStore,
credential_verifier: SharedMachineCredentialVerifier,
) -> Router {
build_app_inner(
registry,
refresh_interval,
public_base_url,
secret_crypto,
runtime,
api_rate_limiter,
coordination_store,
sessions,
credential_verifier,
false,
)
}
#[allow(clippy::too_many_arguments)]
pub fn build_app_with_background_workers(
registry: PostgresRegistry,
refresh_interval: Duration,
public_base_url: Option<String>,
secret_crypto: SecretCrypto,
runtime: RuntimeExecutor,
api_rate_limiter: RequestRateLimiter,
coordination_store: Arc<dyn CoordinationStateStore>,
sessions: SharedSessionStore,
credential_verifier: SharedMachineCredentialVerifier,
) -> Router {
build_app_inner(
registry,
refresh_interval,
public_base_url,
secret_crypto,
runtime,
api_rate_limiter,
coordination_store,
sessions,
credential_verifier,
true,
)
}
#[allow(clippy::too_many_arguments)]
fn build_app_inner(
registry: PostgresRegistry,
refresh_interval: Duration,
public_base_url: Option<String>,
secret_crypto: SecretCrypto,
runtime: RuntimeExecutor,
api_rate_limiter: RequestRateLimiter,
coordination_store: Arc<dyn CoordinationStateStore>,
sessions: SharedSessionStore,
credential_verifier: SharedMachineCredentialVerifier,
start_background_workers: bool,
) -> Router {
let state = Arc::new(AppState {
registry: registry.clone(),
@@ -122,6 +196,9 @@ pub fn build_app(
credential_verifier,
allowed_origins: AllowedOrigins::new(public_base_url),
});
if start_background_workers {
spawn_approval_recovery(Arc::clone(&state));
}
Router::new()
.route("/health", get(health))
@@ -129,6 +206,22 @@ pub fn build_app(
"/v1/{workspace_slug}/{agent_slug}",
get(mcp_get).post(mcp_post).delete(mcp_delete),
)
.route(
"/v1/{workspace_slug}/{agent_slug}/approvals",
get(list_pending_approvals),
)
.route(
"/v1/{workspace_slug}/{agent_slug}/approvals/{approval_id}/approve",
post(approve_request),
)
.route(
"/v1/{workspace_slug}/{agent_slug}/approvals/{approval_id}",
get(get_approval_request),
)
.route(
"/v1/{workspace_slug}/{agent_slug}/approvals/{approval_id}/deny",
post(deny_request),
)
.with_state(state)
}
@@ -139,6 +232,252 @@ async fn health() -> Json<Value> {
}))
}
async fn list_pending_approvals(
Path(path): Path<AgentRoutePath>,
State(state): State<Arc<AppState>>,
headers: HeaderMap,
) -> Response {
let key =
match require_approval_access(&state, &path, &headers, PlatformApiKeyScope::ReadPending)
.await
{
Ok(key) => key,
Err(status) => return status.into_response(),
};
let Some(agent_id) = key.api_key.agent_id.as_ref() else {
return StatusCode::FORBIDDEN.into_response();
};
match state
.registry
.list_pending_approval_requests_for_agent(&key.api_key.workspace_id, agent_id)
.await
{
Ok(items) => Json(json!({ "items": items })).into_response(),
Err(_) => StatusCode::INTERNAL_SERVER_ERROR.into_response(),
}
}
async fn approve_request(
Path(path): Path<ApprovalRoutePath>,
State(state): State<Arc<AppState>>,
headers: HeaderMap,
Json(payload): Json<ApprovalDecisionPayload>,
) -> Response {
decide_approval_request(
path,
state,
headers,
payload,
PlatformApiKeyScope::Approve,
ApprovalRequestStatus::Approved,
)
.await
}
async fn get_approval_request(
Path(path): Path<ApprovalRoutePath>,
State(state): State<Arc<AppState>>,
headers: HeaderMap,
) -> Response {
let agent_path = AgentRoutePath {
workspace_slug: path.workspace_slug,
agent_slug: path.agent_slug,
};
let key = match require_approval_access(
&state,
&agent_path,
&headers,
PlatformApiKeyScope::ReadPending,
)
.await
{
Ok(key) => key,
Err(status) => return status.into_response(),
};
let Some(agent_id) = key.api_key.agent_id.as_ref() else {
return StatusCode::FORBIDDEN.into_response();
};
let approval_id = ApprovalRequestId::new(path.approval_id);
approval_record_response(&state, &key.api_key.workspace_id, agent_id, &approval_id).await
}
async fn deny_request(
Path(path): Path<ApprovalRoutePath>,
State(state): State<Arc<AppState>>,
headers: HeaderMap,
Json(payload): Json<ApprovalDecisionPayload>,
) -> Response {
decide_approval_request(
path,
state,
headers,
payload,
PlatformApiKeyScope::Deny,
ApprovalRequestStatus::Denied,
)
.await
}
async fn decide_approval_request(
path: ApprovalRoutePath,
state: Arc<AppState>,
headers: HeaderMap,
payload: ApprovalDecisionPayload,
required_scope: PlatformApiKeyScope,
status: ApprovalRequestStatus,
) -> Response {
let agent_path = AgentRoutePath {
workspace_slug: path.workspace_slug,
agent_slug: path.agent_slug,
};
let key = match require_approval_access(&state, &agent_path, &headers, required_scope).await {
Ok(key) => key,
Err(status) => return status.into_response(),
};
if (status == ApprovalRequestStatus::Approved && !payload.approve.eq_ignore_ascii_case("yes"))
|| (status == ApprovalRequestStatus::Denied && !payload.approve.eq_ignore_ascii_case("no"))
{
return (
StatusCode::BAD_REQUEST,
Json(json!({
"error": "invalid_decision_payload",
"message": "approve must be yes for approve endpoint and no for deny endpoint"
})),
)
.into_response();
}
let Some(agent_id) = key.api_key.agent_id.as_ref() else {
return StatusCode::FORBIDDEN.into_response();
};
let approval_id = ApprovalRequestId::new(path.approval_id);
match state
.registry
.decide_approval_request(DecideApprovalRequest {
workspace_id: &key.api_key.workspace_id,
agent_id,
approval_id: &approval_id,
status,
decided_at: OffsetDateTime::now_utc(),
decided_by_key_id: &key.api_key.id,
response_payload: Some(json!({ "approve": payload.approve })),
decision_note: payload.note.as_deref(),
})
.await
{
Ok(Some(record)) if status == ApprovalRequestStatus::Approved => {
let claimed = match state
.registry
.claim_approval_request(
&record.approval.workspace_id,
&record.approval.agent_id,
&record.approval.id,
OffsetDateTime::now_utc(),
)
.await
{
Ok(Some(claimed)) => claimed,
Ok(None) => return StatusCode::CONFLICT.into_response(),
Err(_) => return StatusCode::INTERNAL_SERVER_ERROR.into_response(),
};
match execute_approved_request(&state, &agent_path, claimed).await {
Ok(record) => Json(json!(record)).into_response(),
Err(response) => response,
}
}
Ok(Some(record)) => Json(json!(record)).into_response(),
Ok(None) => {
terminal_decision_response(&state, &key.api_key.workspace_id, agent_id, &approval_id)
.await
}
Err(_) => StatusCode::INTERNAL_SERVER_ERROR.into_response(),
}
}
async fn approval_record_response(
state: &Arc<AppState>,
workspace_id: &crank_core::WorkspaceId,
agent_id: &crank_core::AgentId,
approval_id: &ApprovalRequestId,
) -> Response {
match state
.registry
.get_approval_request_for_agent(workspace_id, agent_id, approval_id)
.await
{
Ok(Some(record))
if record.approval.status == ApprovalRequestStatus::Pending
&& record.approval.expires_at <= OffsetDateTime::now_utc() =>
{
expire_approval_response(state, workspace_id, agent_id, approval_id).await
}
Ok(Some(record)) => Json(json!(record)).into_response(),
Ok(None) => StatusCode::NOT_FOUND.into_response(),
Err(_) => StatusCode::INTERNAL_SERVER_ERROR.into_response(),
}
}
async fn terminal_decision_response(
state: &Arc<AppState>,
workspace_id: &crank_core::WorkspaceId,
agent_id: &crank_core::AgentId,
approval_id: &ApprovalRequestId,
) -> Response {
match state
.registry
.get_approval_request_for_agent(workspace_id, agent_id, approval_id)
.await
{
Ok(Some(record))
if record.approval.status == ApprovalRequestStatus::Pending
&& record.approval.expires_at <= OffsetDateTime::now_utc() =>
{
expire_approval_response(state, workspace_id, agent_id, approval_id).await
}
Ok(Some(record))
if matches!(
record.approval.status,
ApprovalRequestStatus::Completed
| ApprovalRequestStatus::Failed
| ApprovalRequestStatus::Denied
| ApprovalRequestStatus::Expired
) =>
{
Json(json!(record)).into_response()
}
Ok(Some(_)) => StatusCode::CONFLICT.into_response(),
Ok(None) => StatusCode::NOT_FOUND.into_response(),
Err(_) => StatusCode::INTERNAL_SERVER_ERROR.into_response(),
}
}
async fn expire_approval_response(
state: &Arc<AppState>,
workspace_id: &crank_core::WorkspaceId,
agent_id: &crank_core::AgentId,
approval_id: &ApprovalRequestId,
) -> Response {
match state
.registry
.expire_approval_request(ExpireApprovalRequest {
workspace_id,
agent_id,
approval_id,
expired_at: OffsetDateTime::now_utc(),
})
.await
{
Ok(Some(record)) => Json(json!(record)).into_response(),
Ok(None) => StatusCode::CONFLICT.into_response(),
Err(_) => StatusCode::INTERNAL_SERVER_ERROR.into_response(),
}
}
async fn mcp_get(
Path(path): Path<AgentRoutePath>,
State(state): State<Arc<AppState>>,
@@ -275,24 +614,23 @@ async fn mcp_post(
);
}
if let Some(session_id) = headers.get(HEADER_MCP_SESSION_ID) {
if let Ok(session_id) = session_id.to_str() {
let session = match state.sessions.get(session_id).await {
Ok(session) => session,
Err(_) => {
return with_request_id_header(
StatusCode::INTERNAL_SERVER_ERROR.into_response(),
&transport_request_id,
);
}
};
if let Some(session) = session {
if let Err(status) =
validate_session_protocol_version(&headers, &session.protocol_version)
{
return with_request_id_header(status.into_response(), &transport_request_id);
}
if let Some(session_id) = headers.get(HEADER_MCP_SESSION_ID)
&& let Ok(session_id) = session_id.to_str()
{
let session = match state.sessions.get(session_id).await {
Ok(session) => session,
Err(_) => {
return with_request_id_header(
StatusCode::INTERNAL_SERVER_ERROR.into_response(),
&transport_request_id,
);
}
};
if let Some(session) = session
&& let Err(status) =
validate_session_protocol_version(&headers, &session.protocol_version)
{
return with_request_id_header(status.into_response(), &transport_request_id);
}
}
@@ -492,7 +830,7 @@ async fn handle_tool_call(
.await
}
async fn resolve_operation_auth(
pub(super) async fn resolve_operation_auth(
state: &Arc<AppState>,
workspace_id: &crank_core::WorkspaceId,
execution_config: &crank_core::ExecutionConfig,
@@ -591,6 +929,20 @@ async fn handle_base_tool_call(
let tool = execution.tool;
let arguments = execution.arguments;
let operation = runtime_operation(&tool);
if let Some(response) = maybe_handle_approval_policy(
&state,
session,
message,
response_mode,
&tool,
&arguments,
transport_request_id,
)
.await
{
return response;
}
let mut runtime_request_context = RuntimeRequestContext::from_request_id(transport_request_id)
.with_response_cache_scope(
tool.workspace_id.as_str().to_owned(),
@@ -625,7 +977,7 @@ async fn handle_base_tool_call(
match result {
Ok(output) => {
let _ = persist_invocation(
if let Err(error) = persist_invocation(
&state,
&tool,
InvocationRecord {
@@ -641,12 +993,15 @@ async fn handle_base_tool_call(
response_preview: output.clone(),
},
)
.await;
.await
{
warn!(error = %error, "successful invocation log write failed");
}
success_tool_response(message, response_mode, &session.protocol_version, output)
}
Err(error) => {
let _ = persist_invocation(
if let Err(log_error) = persist_invocation(
&state,
&tool,
InvocationRecord {
@@ -662,7 +1017,10 @@ async fn handle_base_tool_call(
response_preview: Value::Null,
},
)
.await;
.await
{
warn!(error = %log_error, "failed invocation log write failed");
}
tool_error_response(
message,
@@ -674,6 +1032,200 @@ async fn handle_base_tool_call(
}
}
async fn maybe_handle_approval_policy(
state: &Arc<AppState>,
session: &SessionState,
message: &Value,
response_mode: ResponseMode,
tool: &PublishedAgentTool,
arguments: &Value,
transport_request_id: &str,
) -> Option<Response> {
let policy = tool.operation.execution_config.approval_policy.as_ref()?;
if !policy.required {
return None;
}
match policy.mode {
OperationApprovalMode::Custom => {
maybe_create_custom_pending_approval(
state,
session,
message,
response_mode,
tool,
arguments,
transport_request_id,
)
.await
}
OperationApprovalMode::Elicitation => Some(handle_elicitation_approval(
session,
message,
response_mode,
tool,
arguments,
policy.elicitation_message.as_deref(),
transport_request_id,
)),
}
}
async fn maybe_create_custom_pending_approval(
state: &Arc<AppState>,
session: &SessionState,
message: &Value,
response_mode: ResponseMode,
tool: &PublishedAgentTool,
arguments: &Value,
transport_request_id: &str,
) -> Option<Response> {
let policy = tool.operation.execution_config.approval_policy.as_ref()?;
let approval_id = ApprovalRequestId::new(format!("approval_{}", uuid::Uuid::now_v7().simple()));
let now = OffsetDateTime::now_utc();
let expires_at = now + time::Duration::seconds(i64::from(policy.ttl_seconds));
let approval_url = approval_url_for(tool, &approval_id);
let response_payload = json!({
"status": "approval_required",
"approval_id": approval_id.as_str(),
"approval_url": approval_url,
"approve": {
"method": "POST",
"url": format!("{approval_url}/approve"),
"body": { "approve": "yes" }
},
"deny": {
"method": "POST",
"url": format!("{approval_url}/deny"),
"body": { "approve": "no" }
},
"expires_at": expires_at,
"risk_level": policy.risk_level,
"payload_preview": if policy.show_payload_preview {
arguments.clone()
} else {
Value::Null
},
});
let approval = ApprovalRequest {
id: approval_id,
workspace_id: tool.workspace_id.clone(),
agent_id: tool.agent_id.clone(),
operation_id: tool.operation.id.clone(),
operation_version: tool.operation.version,
status: ApprovalRequestStatus::Pending,
risk_level: policy.risk_level,
request_payload: arguments.clone(),
response_payload: None,
created_at: now,
expires_at,
decided_at: None,
decided_by_key_id: None,
decision_note: None,
};
let persisted_approval = match state
.registry
.create_approval_request(CreateApprovalRequest {
approval: &approval,
})
.await
{
Ok(approval) => approval,
Err(error) => return Some(internal_jsonrpc_error(message, error)),
};
let response_payload = persisted_approval
.approval
.response_payload
.unwrap_or(response_payload);
if let Err(error) = persist_invocation(
state,
tool,
InvocationRecord {
request_id: Some(transport_request_id),
tool_name: &tool.tool_name,
status: InvocationStatus::Ok,
level: InvocationLevel::Info,
message: "agent tool call is waiting for human approval",
status_code: None,
error_kind: None,
duration: Duration::from_millis(0),
request_preview: arguments.clone(),
response_preview: response_payload.clone(),
},
)
.await
{
warn!(error = %error, "pending approval invocation log write failed");
}
Some(success_tool_response(
message,
response_mode,
&session.protocol_version,
response_payload,
))
}
fn handle_elicitation_approval(
session: &SessionState,
message: &Value,
response_mode: ResponseMode,
tool: &PublishedAgentTool,
arguments: &Value,
elicitation_message: Option<&str>,
transport_request_id: &str,
) -> Response {
if !session.supports_elicitation {
return tool_error_response(
message,
response_mode,
&session.protocol_version,
generic_tool_error_contract(
"approval_elicitation_not_supported",
"operation requires MCP Elicitation, but the MCP client did not advertise elicitation capability",
transport_request_id,
false,
Some(
"Выберите Custom MCP Approval или подключите MCP-клиент с поддержкой elicitation.",
),
),
);
}
let payload_preview = tool
.operation
.execution_config
.approval_policy
.as_ref()
.and_then(|policy| policy.show_payload_preview.then(|| arguments.clone()))
.unwrap_or(Value::Null);
success_tool_response(
message,
response_mode,
&session.protocol_version,
json!({
"status": "elicitation_required",
"message": elicitation_message.unwrap_or("Confirm operation execution."),
"tool": tool.tool_name,
"payload_preview": payload_preview,
"note": "This MCP client advertised elicitation support. Full elicitation/create continuation is handled by compatible client integrations.",
}),
)
}
fn approval_url_for(tool: &PublishedAgentTool, approval_id: &ApprovalRequestId) -> String {
format!(
"/v1/{}/{}/approvals/{}",
tool.workspace_slug,
tool.agent_slug,
approval_id.as_str()
)
}
async fn handle_initialize(
state: Arc<AppState>,
path: &AgentRoutePath,
@@ -711,12 +1263,17 @@ async fn handle_initialize(
};
let now = OffsetDateTime::now_utc();
let expires_at = add_millis(now, TRANSPORT_SESSION_TTL_MS);
let supports_elicitation = initialize_params
.capabilities
.get("elicitation")
.is_some_and(Value::is_object);
let session_id = match state
.sessions
.create(
protocol_version,
&path.workspace_slug,
&path.agent_slug,
supports_elicitation,
now,
Some(expires_at),
)
@@ -834,7 +1391,7 @@ fn take_confirmation_token(arguments: &mut Value) -> Option<String> {
.filter(|value| !value.trim().is_empty())
}
fn build_request_preview(
pub(super) fn build_request_preview(
runtime: &RuntimeExecutor,
operation: &RuntimeOperation,
arguments: &Value,
@@ -850,20 +1407,20 @@ fn build_request_preview(
}
}
struct InvocationRecord<'a> {
request_id: Option<&'a str>,
tool_name: &'a str,
status: InvocationStatus,
level: InvocationLevel,
message: &'a str,
status_code: Option<u16>,
error_kind: Option<&'a str>,
duration: Duration,
request_preview: Value,
response_preview: Value,
pub(super) struct InvocationRecord<'a> {
pub(super) request_id: Option<&'a str>,
pub(super) tool_name: &'a str,
pub(super) status: InvocationStatus,
pub(super) level: InvocationLevel,
pub(super) message: &'a str,
pub(super) status_code: Option<u16>,
pub(super) error_kind: Option<&'a str>,
pub(super) duration: Duration,
pub(super) request_preview: Value,
pub(super) response_preview: Value,
}
async fn persist_invocation(
pub(super) async fn persist_invocation(
state: &Arc<AppState>,
tool: &PublishedAgentTool,
record: InvocationRecord<'_>,
@@ -973,7 +1530,7 @@ fn resolve_generated_tool(
None
}
fn runtime_operation(tool: &PublishedAgentTool) -> RuntimeOperation {
pub(super) fn runtime_operation(tool: &PublishedAgentTool) -> RuntimeOperation {
let mut operation = RuntimeOperation::from(tool.operation.clone());
operation.tool_name = tool.tool_name.clone();
operation.tool_description.title = tool.tool_title.clone();
@@ -0,0 +1,237 @@
use std::{sync::Arc, time::Instant};
use axum::{
http::StatusCode,
response::{IntoResponse, Response},
};
use crank_core::{ApprovalRequestStatus, InvocationLevel, InvocationSource, InvocationStatus};
use crank_registry::{ApprovalRequestRecord, FinishApprovalRequest};
use crank_runtime::{RuntimeExecutionRequest, RuntimeRequestContext};
use serde_json::json;
use time::OffsetDateTime;
use tracing::warn;
use crate::{
app::{
AgentRoutePath, AppState, InvocationRecord, build_request_preview, persist_invocation,
resolve_operation_auth, runtime_operation,
},
tool_error::runtime_error_code,
};
const RECOVERY_INTERVAL: std::time::Duration = std::time::Duration::from_secs(5);
const RECOVERY_GRACE: time::Duration = time::Duration::seconds(5);
const EXECUTION_LEASE: time::Duration = time::Duration::minutes(6);
pub(super) fn spawn_approval_recovery(state: Arc<AppState>) {
tokio::spawn(async move {
let mut interval = tokio::time::interval(RECOVERY_INTERVAL);
interval.set_missed_tick_behavior(tokio::time::MissedTickBehavior::Skip);
loop {
interval.tick().await;
recover_approved_requests(&state).await;
}
});
}
async fn recover_approved_requests(state: &Arc<AppState>) {
for _ in 0..32 {
let now = OffsetDateTime::now_utc();
let approval = match state
.registry
.claim_next_recoverable_approval_request(
now,
now - RECOVERY_GRACE,
now - EXECUTION_LEASE,
)
.await
{
Ok(Some(approval)) => approval,
Ok(None) => break,
Err(error) => {
warn!(error = %error, "approval recovery query failed");
break;
}
};
let Some(path) = approval_agent_path(state, &approval).await else {
continue;
};
if execute_approved_request(state, &path, approval)
.await
.is_err()
{
warn!("recovered approval execution did not finish");
}
}
}
async fn approval_agent_path(
state: &Arc<AppState>,
approval: &ApprovalRequestRecord,
) -> Option<AgentRoutePath> {
let workspace = match state
.registry
.get_workspace(&approval.approval.workspace_id)
.await
{
Ok(Some(workspace)) => workspace,
Ok(None) => return None,
Err(error) => {
warn!(error = %error, "approval workspace lookup failed");
return None;
}
};
let agent = match state
.registry
.get_agent_summary(&approval.approval.workspace_id, &approval.approval.agent_id)
.await
{
Ok(Some(agent)) => agent,
Ok(None) => return None,
Err(error) => {
warn!(error = %error, "approval agent lookup failed");
return None;
}
};
Some(AgentRoutePath {
workspace_slug: workspace.workspace.slug,
agent_slug: agent.slug,
})
}
pub(super) async fn execute_approved_request(
state: &Arc<AppState>,
path: &AgentRoutePath,
approval: ApprovalRequestRecord,
) -> Result<ApprovalRequestRecord, Response> {
let tools = state
.catalog
.list_tools(&path.workspace_slug, &path.agent_slug)
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR.into_response())?;
let Some(tool) = tools.into_iter().find(|tool| {
tool.operation.id == approval.approval.operation_id
&& tool.operation.version == approval.approval.operation_version
}) else {
return finish_unavailable_approval(state, &approval).await;
};
let operation = runtime_operation(&tool);
let request_preview = build_request_preview(
&state.runtime,
&operation,
&approval.approval.request_payload,
);
let started_at = Instant::now();
let runtime_request_context =
RuntimeRequestContext::from_request_id(approval.approval.id.as_str().to_owned())
.with_response_cache_scope(
tool.workspace_id.as_str().to_owned(),
tool.agent_id.as_str().to_owned(),
)
.with_metering_context(
tool.workspace_id.clone(),
Some(tool.agent_id.clone()),
InvocationSource::AgentToolCall,
)
.with_approval_granted();
let resolved_auth =
resolve_operation_auth(state, &tool.workspace_id, &operation.execution_config).await;
let result = match resolved_auth {
Ok(resolved_auth) => {
state
.runtime
.execute_request(
RuntimeExecutionRequest::new(&operation, &approval.approval.request_payload)
.with_optional_auth(resolved_auth.as_ref())
.with_context(&runtime_request_context),
)
.await
}
Err(error) => Err(error),
};
let (status, response_payload, invocation_status, invocation_level, message, error_kind) =
match result {
Ok(output) => (
ApprovalRequestStatus::Completed,
output,
InvocationStatus::Ok,
InvocationLevel::Info,
"approved tool call completed",
None,
),
Err(error) => (
ApprovalRequestStatus::Failed,
json!({
"error": {
"code": runtime_error_code(&error),
"message": error.to_string(),
}
}),
InvocationStatus::Error,
InvocationLevel::Error,
"approved tool call failed",
Some(runtime_error_code(&error)),
),
};
if let Err(error) = persist_invocation(
state,
&tool,
InvocationRecord {
request_id: Some(approval.approval.id.as_str()),
tool_name: &tool.tool_name,
status: invocation_status,
level: invocation_level,
message,
status_code: None,
error_kind,
duration: started_at.elapsed(),
request_preview,
response_preview: response_payload.clone(),
},
)
.await
{
warn!(error = %error, "approved invocation log write failed");
}
state
.registry
.finish_approval_request(FinishApprovalRequest {
workspace_id: &approval.approval.workspace_id,
agent_id: &approval.approval.agent_id,
approval_id: &approval.approval.id,
status,
response_payload: Some(response_payload),
decision_note: None,
})
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR.into_response())?
.ok_or_else(|| StatusCode::CONFLICT.into_response())
}
async fn finish_unavailable_approval(
state: &Arc<AppState>,
approval: &ApprovalRequestRecord,
) -> Result<ApprovalRequestRecord, Response> {
state
.registry
.finish_approval_request(FinishApprovalRequest {
workspace_id: &approval.approval.workspace_id,
agent_id: &approval.approval.agent_id,
approval_id: &approval.approval.id,
status: ApprovalRequestStatus::Failed,
response_payload: Some(json!({
"error": {
"code": "approved_operation_unavailable",
"message": "the approved operation version is no longer published"
}
})),
decision_note: None,
})
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR.into_response())?
.ok_or_else(|| StatusCode::CONFLICT.into_response())
}
+80 -9
View File
@@ -1,14 +1,16 @@
use std::{
collections::HashMap,
sync::Arc,
time::{Duration, Instant},
time::{Duration, Instant, SystemTime, UNIX_EPOCH},
};
use crank_core::{CacheScope, CoordinationStateStore, CoordinationStateValue};
use crank_registry::{PostgresRegistry, PublishedAgentTool, RegistryError};
use serde::{Deserialize, Serialize};
use tokio::sync::RwLock;
use tracing::info;
use tokio::sync::{Mutex, RwLock};
use tracing::{info, warn};
use crate::manifest::analyze_published_tool_catalog;
#[derive(Clone)]
pub struct PublishedToolCatalog {
@@ -16,6 +18,7 @@ pub struct PublishedToolCatalog {
refresh_interval: Duration,
coordination_store: Arc<dyn CoordinationStateStore>,
cached: Arc<RwLock<HashMap<CatalogKey, CachedCatalog>>>,
refresh_locks: Arc<Mutex<HashMap<CatalogKey, Arc<Mutex<()>>>>>,
}
#[derive(Clone, Debug, PartialEq, Eq, Hash)]
@@ -33,6 +36,7 @@ struct CachedCatalog {
#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
struct CatalogSnapshot {
tools: Vec<PublishedAgentTool>,
generated_at_ms: u64,
}
impl PublishedToolCatalog {
@@ -46,6 +50,7 @@ impl PublishedToolCatalog {
refresh_interval,
coordination_store,
cached: Arc::new(RwLock::new(HashMap::new())),
refresh_locks: Arc::new(Mutex::new(HashMap::new())),
}
}
@@ -81,12 +86,33 @@ impl PublishedToolCatalog {
return Ok(());
}
if let Some(tools) = self.load_shared_snapshot(workspace_slug, agent_slug).await {
let refresh_lock = {
let mut locks = self.refresh_locks.lock().await;
Arc::clone(
locks
.entry(key.clone())
.or_insert_with(|| Arc::new(Mutex::new(()))),
)
};
let _refresh_guard = refresh_lock.lock().await;
let still_stale = {
let guard = self.cached.read().await;
match guard.get(&key).and_then(|entry| entry.loaded_at) {
Some(loaded_at) => loaded_at.elapsed() >= self.refresh_interval,
None => true,
}
};
if !still_stale {
return Ok(());
}
if let Some((tools, age)) = self.load_shared_snapshot(workspace_slug, agent_slug).await {
log_catalog_analysis(workspace_slug, agent_slug, "shared_cache", &tools);
let mut guard = self.cached.write().await;
guard.insert(
key,
CachedCatalog {
loaded_at: Some(Instant::now()),
loaded_at: Instant::now().checked_sub(age),
tools,
},
);
@@ -102,6 +128,7 @@ impl PublishedToolCatalog {
Err(RegistryError::PublishedAgentNotFound { .. }) => Vec::new(),
Err(error) => return Err(error),
};
log_catalog_analysis(workspace_slug, agent_slug, "postgres", &tools);
self.store_shared_snapshot(workspace_slug, agent_slug, &tools)
.await;
let mut guard = self.cached.write().await;
@@ -136,7 +163,7 @@ impl PublishedToolCatalog {
&self,
workspace_slug: &str,
agent_slug: &str,
) -> Option<Vec<PublishedAgentTool>> {
) -> Option<(Vec<PublishedAgentTool>, Duration)> {
if self.refresh_interval.is_zero() {
return None;
}
@@ -150,9 +177,9 @@ impl PublishedToolCatalog {
Ok(value) => value?,
Err(_) => return None,
};
serde_json::from_value::<CatalogSnapshot>(value.payload)
.ok()
.map(|snapshot| snapshot.tools)
let snapshot = serde_json::from_value::<CatalogSnapshot>(value.payload).ok()?;
let age = Duration::from_millis(now_unix_ms().saturating_sub(snapshot.generated_at_ms));
(age < self.refresh_interval).then_some((snapshot.tools, age))
}
async fn store_shared_snapshot(
@@ -167,6 +194,7 @@ impl PublishedToolCatalog {
let payload = match serde_json::to_value(CatalogSnapshot {
tools: tools.to_vec(),
generated_at_ms: now_unix_ms(),
}) {
Ok(payload) => payload,
Err(_) => return,
@@ -184,6 +212,49 @@ impl PublishedToolCatalog {
}
}
fn log_catalog_analysis(
workspace_slug: &str,
agent_slug: &str,
source: &str,
tools: &[PublishedAgentTool],
) {
let analysis = match analyze_published_tool_catalog(tools) {
Ok(analysis) => analysis,
Err(error) => {
warn!(workspace_slug, agent_slug, source, %error, "published catalog analysis failed");
return;
}
};
let warning_count = analysis
.quality
.findings
.iter()
.filter(|finding| finding.severity == crank_core::ToolQualitySeverity::Warning)
.count();
info!(
workspace_slug,
agent_slug,
source,
tool_count = analysis.budget.tool_count,
serialized_bytes = analysis.budget.serialized_bytes,
estimated_context_tokens = analysis.budget.estimated_context_tokens,
largest_tool_estimated_context_tokens =
analysis.budget.largest_tool_estimated_context_tokens,
recommended_context_tokens = analysis.budget.recommended_context_tokens,
exceeds_recommended_budget = analysis.budget.exceeds_recommended_budget,
catalog_quality_warning_count = warning_count,
"published agent catalog analyzed"
);
}
fn now_unix_ms() -> u64 {
SystemTime::now()
.duration_since(UNIX_EPOCH)
.map(|duration| u64::try_from(duration.as_millis()).unwrap_or(u64::MAX))
.unwrap_or_default()
}
impl CatalogKey {
fn new(workspace_slug: &str, agent_slug: &str) -> Self {
Self {
+2 -1
View File
@@ -1,5 +1,6 @@
mod access;
mod app;
mod approval_execution;
pub mod auth;
pub mod catalog;
pub mod jsonrpc;
@@ -9,4 +10,4 @@ pub mod session;
pub mod tool_error;
mod transport;
pub use app::build_app;
pub use app::{build_app, build_app_with_background_workers};
+35 -1
View File
@@ -1,4 +1,7 @@
use crank_core::{HttpMethod, OperationSafetyClass, OperationSafetyPolicy, Target};
use crank_core::{
HttpMethod, OperationSafetyClass, OperationSafetyPolicy, Target, ToolCatalogAnalysis,
ToolCatalogAnalysisError, ToolQualityCatalogTool, analyze_tool_catalog,
};
use crank_registry::PublishedAgentTool;
use serde_json::{Value, json};
@@ -27,6 +30,37 @@ pub fn tool_definitions(tool: &PublishedAgentTool) -> Vec<Value> {
)]
}
pub fn analyze_published_tool_catalog(
tools: &[PublishedAgentTool],
) -> Result<ToolCatalogAnalysis, ToolCatalogAnalysisError> {
let mut quality_tools = Vec::new();
let mut definitions = Vec::new();
for tool in tools {
for definition in tool_definitions(tool) {
quality_tools.push(ToolQualityCatalogTool {
name: definition_string(&definition, "name")?,
display_name: definition_string(&definition, "title")?,
description: definition_string(&definition, "description")?,
});
definitions.push(definition);
}
}
analyze_tool_catalog(&quality_tools, &definitions)
}
fn definition_string(
definition: &Value,
field: &'static str,
) -> Result<String, ToolCatalogAnalysisError> {
definition
.get(field)
.and_then(Value::as_str)
.map(ToOwned::to_owned)
.ok_or(ToolCatalogAnalysisError::DefinitionFieldMissing(field))
}
pub fn tool_definition(name: &str, title: &str, description: &str, input_schema: Value) -> Value {
json!({
"name": name,
+32 -15
View File
@@ -3,7 +3,7 @@ use std::{collections::HashMap, sync::Arc};
use async_trait::async_trait;
use crank_registry::PostgresPoolConfig;
use sqlx::{
PgPool,
PgPool, Row,
postgres::{PgConnectOptions, PgPoolOptions},
query,
};
@@ -17,6 +17,7 @@ pub struct SessionState {
pub id: String,
pub protocol_version: String,
pub initialized: bool,
pub supports_elicitation: bool,
pub workspace_slug: String,
pub agent_slug: String,
pub created_at: OffsetDateTime,
@@ -37,6 +38,7 @@ pub trait TransportSessionStore: Send + Sync {
protocol_version: &str,
workspace_slug: &str,
agent_slug: &str,
supports_elicitation: bool,
now: OffsetDateTime,
expires_at: Option<OffsetDateTime>,
) -> Result<String, SessionStoreError>;
@@ -100,6 +102,7 @@ impl TransportSessionStore for InMemorySessionStore {
protocol_version: &str,
workspace_slug: &str,
agent_slug: &str,
supports_elicitation: bool,
now: OffsetDateTime,
expires_at: Option<OffsetDateTime>,
) -> Result<String, SessionStoreError> {
@@ -112,6 +115,7 @@ impl TransportSessionStore for InMemorySessionStore {
id: session_id.clone(),
protocol_version: protocol_version.to_owned(),
initialized: false,
supports_elicitation,
workspace_slug: workspace_slug.to_owned(),
agent_slug: agent_slug.to_owned(),
created_at: now,
@@ -169,6 +173,7 @@ impl TransportSessionStore for PostgresTransportSessionStore {
protocol_version: &str,
workspace_slug: &str,
agent_slug: &str,
supports_elicitation: bool,
now: OffsetDateTime,
expires_at: Option<OffsetDateTime>,
) -> Result<String, SessionStoreError> {
@@ -178,17 +183,19 @@ impl TransportSessionStore for PostgresTransportSessionStore {
id,
protocol_version,
initialized,
supports_elicitation,
workspace_slug,
agent_slug,
created_at,
updated_at,
expires_at
) values (
$1, $2, false, $3, $4, $5::timestamptz, $5::timestamptz, $6::timestamptz
$1, $2, false, $3, $4, $5, $6::timestamptz, $6::timestamptz, $7::timestamptz
)",
)
.bind(&session_id)
.bind(protocol_version)
.bind(supports_elicitation)
.bind(workspace_slug)
.bind(agent_slug)
.bind(now)
@@ -203,20 +210,21 @@ impl TransportSessionStore for PostgresTransportSessionStore {
}
async fn get(&self, session_id: &str) -> Result<Option<SessionState>, SessionStoreError> {
let row = sqlx::query!(
let row = sqlx::query(
"select
id,
protocol_version,
initialized,
supports_elicitation,
workspace_slug,
agent_slug,
created_at as \"created_at!: OffsetDateTime\",
updated_at as \"updated_at!: OffsetDateTime\",
expires_at as \"expires_at: OffsetDateTime\"
created_at,
updated_at,
expires_at
from mcp_transport_sessions
where id = $1",
session_id,
)
.bind(session_id)
.fetch_optional(&self.pool)
.await
.map_err(|error| SessionStoreError {
@@ -224,14 +232,15 @@ impl TransportSessionStore for PostgresTransportSessionStore {
})?;
let Some(session) = row.map(|row| SessionState {
id: row.id,
protocol_version: row.protocol_version,
initialized: row.initialized,
workspace_slug: row.workspace_slug,
agent_slug: row.agent_slug,
created_at: row.created_at,
updated_at: row.updated_at,
expires_at: row.expires_at,
id: row.get("id"),
protocol_version: row.get("protocol_version"),
initialized: row.get("initialized"),
supports_elicitation: row.get("supports_elicitation"),
workspace_slug: row.get("workspace_slug"),
agent_slug: row.get("agent_slug"),
created_at: row.get("created_at"),
updated_at: row.get("updated_at"),
expires_at: row.get("expires_at"),
}) else {
return Ok(None);
};
@@ -291,6 +300,7 @@ async fn apply_postgres_migrations(pool: &PgPool) -> Result<(), SessionStoreErro
id text primary key,
protocol_version text not null,
initialized boolean not null default false,
supports_elicitation boolean not null default false,
workspace_slug text not null,
agent_slug text not null,
created_at timestamptz not null,
@@ -304,6 +314,13 @@ async fn apply_postgres_migrations(pool: &PgPool) -> Result<(), SessionStoreErro
details: error.to_string(),
})?;
query("alter table mcp_transport_sessions add column if not exists supports_elicitation boolean not null default false")
.execute(pool)
.await
.map_err(|error| SessionStoreError {
details: error.to_string(),
})?;
query(
"alter table mcp_transport_sessions add column if not exists expires_at timestamptz null",
)
+81 -13
View File
@@ -12,6 +12,7 @@ use axum::{
},
};
use futures_util::stream;
use reqwest::Url;
use serde_json::Value;
use crate::jsonrpc::{
@@ -42,21 +43,44 @@ impl AllowedOrigins {
}
pub(super) fn is_allowed(&self, origin: &str) -> bool {
if origin.starts_with("http://localhost")
|| origin.starts_with("http://127.0.0.1")
|| origin.starts_with("https://localhost")
|| origin.starts_with("https://127.0.0.1")
{
let Some(origin) = parse_origin(origin, true) else {
return false;
};
if is_loopback_origin(&origin) {
return true;
}
match &self.public_origin {
Some(public_origin) => public_origin == origin,
Some(public_origin) => public_origin == &origin.origin().ascii_serialization(),
None => false,
}
}
}
fn is_loopback_origin(origin: &Url) -> bool {
matches!(origin.host_str(), Some("localhost" | "127.0.0.1" | "[::1]"))
}
fn parse_origin(value: &str, origin_only: bool) -> Option<Url> {
let origin = Url::parse(value).ok()?;
if !matches!(origin.scheme(), "http" | "https")
|| origin.host_str().is_none()
|| !origin.username().is_empty()
|| origin.password().is_some()
{
return None;
}
if origin_only
&& (origin.path() != "/" || origin.query().is_some() || origin.fragment().is_some())
{
return None;
}
Some(origin)
}
pub(super) fn validate_origin(
allowed_origins: &AllowedOrigins,
headers: &HeaderMap,
@@ -298,14 +322,58 @@ pub(super) fn is_valid_request_id(value: &str) -> bool {
}
pub(super) fn extract_origin(url: &str) -> Option<String> {
let mut parts = url.split('/');
let scheme = parts.next()?;
let empty = parts.next()?;
let authority = parts.next()?;
Some(parse_origin(url, false)?.origin().ascii_serialization())
}
if empty.is_empty() {
return Some(format!("{scheme}//{authority}"));
#[cfg(test)]
mod tests {
use super::AllowedOrigins;
#[test]
fn allows_loopback_origins_with_and_without_port() {
let origins = AllowedOrigins::new(None);
assert!(origins.is_allowed("http://localhost"));
assert!(origins.is_allowed("http://localhost:3000"));
assert!(origins.is_allowed("https://127.0.0.1:8443"));
assert!(origins.is_allowed("http://[::1]:3000"));
}
None
#[test]
fn rejects_hosts_that_only_prefix_match_loopback() {
let origins = AllowedOrigins::new(None);
assert!(!origins.is_allowed("http://localhost.attacker.com"));
assert!(!origins.is_allowed("http://127.0.0.1.attacker.com"));
assert!(!origins.is_allowed("http://localhost@attacker.com"));
assert!(!origins.is_allowed("http://attacker.com/http://localhost"));
assert!(!origins.is_allowed("http://[::1].attacker.com"));
assert!(!origins.is_allowed("http://attacker@[::1]"));
}
#[test]
fn matches_configured_public_origin_exactly() {
let origins = AllowedOrigins::new(Some("https://crank.example.com".to_owned()));
assert!(origins.is_allowed("https://crank.example.com"));
assert!(!origins.is_allowed("https://crank.example.com.attacker.com"));
assert!(!origins.is_allowed("https://evil.example.com"));
}
#[test]
fn rejects_non_http_schemes() {
let origins = AllowedOrigins::new(None);
assert!(!origins.is_allowed("file://localhost"));
assert!(!origins.is_allowed("javascript://localhost"));
}
#[test]
fn rejects_values_that_are_not_origins() {
let origins = AllowedOrigins::new(None);
assert!(!origins.is_allowed("http://localhost/path"));
assert!(!origins.is_allowed("http://localhost?query=value"));
assert!(!origins.is_allowed("http://localhost#fragment"));
}
}
@@ -32,6 +32,7 @@ async fn postgres_transport_sessions_survive_store_reconnect() {
"2025-11-25",
"default",
"sales",
false,
created_at,
Some(created_at + time::Duration::days(30)),
)
@@ -73,6 +74,7 @@ async fn postgres_transport_sessions_evict_expired_rows_on_read() {
"2025-11-25",
"default",
"sales",
false,
timestamp("2026-05-01T10:00:00Z"),
Some(timestamp("2026-05-01T10:00:01Z")),
)
@@ -1,6 +1,6 @@
use std::collections::BTreeMap;
use crank_community_mcp::manifest::tool_definitions;
use crank_community_mcp::manifest::{analyze_published_tool_catalog, tool_definitions};
use crank_core::{
ExecutionConfig, HttpMethod, Operation, OperationId, OperationSecurityLevel, OperationStatus,
Protocol, RestTarget, Target, ToolDescription, WorkspaceId,
@@ -57,6 +57,20 @@ fn marks_destructive_tools_as_two_step_confirmation_calls() {
assert_eq!(definition["inputSchema"]["required"], json!(["base"]));
}
#[test]
fn catalog_budget_uses_the_same_definitions_as_tools_list() {
let tool = published_tool();
let definitions = tool_definitions(&tool);
let analysis = analyze_published_tool_catalog(&[tool]).unwrap();
assert_eq!(analysis.budget.tool_count, definitions.len());
assert_eq!(
analysis.budget.serialized_bytes,
serde_json::to_vec(&definitions[0]).unwrap().len()
);
assert!(!analysis.budget.exceeds_recommended_budget);
}
fn published_tool() -> PublishedAgentTool {
PublishedAgentTool {
workspace_id: WorkspaceId::new("ws_01"),
@@ -106,6 +120,7 @@ fn operation() -> RegistryOperation {
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
},
@@ -13,7 +13,7 @@ async fn creates_and_reads_transport_sessions() {
let created_at = timestamp("2026-05-01T10:00:00Z");
let session_id = store
.create("2025-11-25", "default", "sales", created_at, None)
.create("2025-11-25", "default", "sales", false, created_at, None)
.await
.unwrap();
let session = store.get(&session_id).await.unwrap().unwrap();
@@ -23,6 +23,7 @@ async fn creates_and_reads_transport_sessions() {
assert_eq!(session.workspace_slug, "default");
assert_eq!(session.agent_slug, "sales");
assert!(!session.initialized);
assert!(!session.supports_elicitation);
assert_eq!(session.created_at, created_at);
assert_eq!(session.updated_at, created_at);
}
@@ -34,7 +35,7 @@ async fn marks_transport_sessions_initialized() {
let initialized_at = timestamp("2026-05-01T10:00:05Z");
let session_id = store
.create("2025-11-25", "default", "sales", created_at, None)
.create("2025-11-25", "default", "sales", false, created_at, None)
.await
.unwrap();
@@ -61,6 +62,7 @@ async fn drops_expired_in_memory_transport_sessions_on_read() {
"2025-11-25",
"default",
"sales",
false,
created_at,
Some(expires_at),
)
+28 -1
View File
@@ -35,12 +35,22 @@ pub enum PlatformApiKeyStatus {
Revoked,
}
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum PlatformApiKeyKind {
McpClient,
Approval,
}
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum PlatformApiKeyScope {
Read,
Write,
Deploy,
Approve,
Deny,
ReadPending,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
@@ -82,6 +92,8 @@ pub struct PlatformApiKey {
pub workspace_id: WorkspaceId,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub agent_id: Option<AgentId>,
#[serde(default = "default_platform_api_key_kind")]
pub key_kind: PlatformApiKeyKind,
pub name: String,
pub prefix: String,
pub scopes: Vec<PlatformApiKeyScope>,
@@ -90,6 +102,14 @@ pub struct PlatformApiKey {
pub created_at: OffsetDateTime,
#[serde(with = "time::serde::rfc3339::option")]
pub last_used_at: Option<OffsetDateTime>,
#[serde(with = "time::serde::rfc3339::option")]
pub expires_at: Option<OffsetDateTime>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub allowed_origins: Vec<String>,
}
fn default_platform_api_key_kind() -> PlatformApiKeyKind {
PlatformApiKeyKind::McpClient
}
#[cfg(test)]
@@ -97,7 +117,10 @@ mod tests {
use serde_json::json;
use time::{OffsetDateTime, format_description::well_known::Rfc3339};
use super::{PlatformApiKey, PlatformApiKeyScope, PlatformApiKeyStatus, User, UserStatus};
use super::{
PlatformApiKey, PlatformApiKeyKind, PlatformApiKeyScope, PlatformApiKeyStatus, User,
UserStatus,
};
use crate::ids::{AgentId, PlatformApiKeyId, UserId, WorkspaceId};
#[test]
@@ -138,16 +161,20 @@ mod tests {
id: PlatformApiKeyId::new("pk_01"),
workspace_id: WorkspaceId::new("ws_01"),
agent_id: Some(AgentId::new("agent_01")),
key_kind: PlatformApiKeyKind::McpClient,
name: "Primary".to_owned(),
prefix: "crk_live".to_owned(),
scopes: vec![PlatformApiKeyScope::Read, PlatformApiKeyScope::Write],
status: PlatformApiKeyStatus::Active,
created_at: OffsetDateTime::parse("2026-03-25T12:01:00Z", &Rfc3339).unwrap(),
last_used_at: Some(OffsetDateTime::parse("2026-03-25T12:05:00Z", &Rfc3339).unwrap()),
expires_at: None,
allowed_origins: Vec::new(),
};
let value = serde_json::to_value(&api_key).unwrap();
assert_eq!(value["key_kind"], json!("mcp_client"));
assert_eq!(value["created_at"], json!("2026-03-25T12:01:00Z"));
assert_eq!(value["last_used_at"], json!("2026-03-25T12:05:00Z"));
}
+40
View File
@@ -0,0 +1,40 @@
use serde::{Deserialize, Serialize};
use serde_json::Value;
use time::OffsetDateTime;
use crate::ids::{AgentId, ApprovalRequestId, OperationId, PlatformApiKeyId, WorkspaceId};
use crate::operation::OperationApprovalRiskLevel;
#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ApprovalRequestStatus {
#[default]
Pending,
Approved,
Executing,
Denied,
Expired,
Completed,
Failed,
}
#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
pub struct ApprovalRequest {
pub id: ApprovalRequestId,
pub workspace_id: WorkspaceId,
pub agent_id: AgentId,
pub operation_id: OperationId,
pub operation_version: u32,
pub status: ApprovalRequestStatus,
pub risk_level: OperationApprovalRiskLevel,
pub request_payload: Value,
pub response_payload: Option<Value>,
#[serde(with = "time::serde::rfc3339")]
pub created_at: OffsetDateTime,
#[serde(with = "time::serde::rfc3339")]
pub expires_at: OffsetDateTime,
#[serde(with = "time::serde::rfc3339::option")]
pub decided_at: Option<OffsetDateTime>,
pub decided_by_key_id: Option<PlatformApiKeyId>,
pub decision_note: Option<String>,
}
+2 -7
View File
@@ -14,18 +14,13 @@ pub enum MachineAccessMode {
StaticAgentKey,
}
#[derive(Clone, Copy, Debug, Serialize, Deserialize, PartialEq, Eq)]
#[derive(Clone, Copy, Debug, Default, Serialize, Deserialize, PartialEq, Eq)]
#[serde(rename_all = "snake_case")]
pub enum OperationSecurityLevel {
#[default]
Standard,
}
impl Default for OperationSecurityLevel {
fn default() -> Self {
Self::Standard
}
}
#[derive(Clone, Debug, Serialize, Deserialize, PartialEq, Eq)]
pub struct EditionLimits {
pub max_workspaces: Option<u32>,
+1
View File
@@ -53,6 +53,7 @@ define_id!(UserSessionId);
define_id!(AgentId);
define_id!(InvitationId);
define_id!(PlatformApiKeyId);
define_id!(ApprovalRequestId);
define_id!(InvocationLogId);
define_id!(AuditEventId);
define_id!(SecretId);
+29 -16
View File
@@ -1,5 +1,6 @@
pub mod access;
pub mod agent;
pub mod approval;
pub mod auth;
pub mod cache;
pub mod edition;
@@ -9,15 +10,17 @@ pub mod observability;
pub mod operation;
pub mod protocol;
pub mod secret;
pub mod tool_catalog;
pub mod tool_quality;
pub mod workspace;
pub mod domain {
pub use crate::access::{
InvitationStatus, InvitationToken, Membership, MembershipRole, PlatformApiKey,
PlatformApiKeyScope, PlatformApiKeyStatus, User, UserStatus,
PlatformApiKeyKind, PlatformApiKeyScope, PlatformApiKeyStatus, User, UserStatus,
};
pub use crate::agent::{Agent, AgentOperationBinding, AgentStatus, AgentVersion};
pub use crate::approval::{ApprovalRequest, ApprovalRequestStatus};
pub use crate::auth::{
ApiKeyHeaderAuthConfig, ApiKeyQueryAuthConfig, AuthConfig, AuthProfile, BasicAuthConfig,
BearerAuthConfig,
@@ -31,22 +34,24 @@ pub mod domain {
ProductEdition,
};
pub use crate::ids::{
AgentId, AuditEventId, AuthProfileId, DescriptorId, InvitationId, InvocationLogId,
OperationId, PlatformApiKeyId, SampleId, SecretId, ToolId, UserId, UserSessionId,
WorkspaceId,
AgentId, ApprovalRequestId, AuditEventId, AuthProfileId, DescriptorId, InvitationId,
InvocationLogId, OperationId, PlatformApiKeyId, SampleId, SecretId, ToolId, UserId,
UserSessionId, WorkspaceId,
};
pub use crate::observability::{
InvocationLevel, InvocationLog, InvocationSource, InvocationStatus, UsagePeriod,
UsageRollup,
INVOCATION_PREVIEW_MAX_BYTES, InvocationLevel, InvocationLog, InvocationSource,
InvocationStatus, UsagePeriod, UsageRollup, sanitize_invocation_preview,
};
pub use crate::operation::{
ConfigExport, ConfirmationPolicy, ExecutionConfig, GeneratedDraft, GeneratedDraftStatus,
IdempotencyMode, IdempotencyPolicy, Operation, OperationSafetyClass, OperationSafetyPolicy,
OperationStatus, ResponseCachePolicy, RestTarget, RetryPolicy, Samples, Target,
ToolDescription, ToolExample, WizardState,
IdempotencyMode, IdempotencyPolicy, Operation, OperationApprovalMode,
OperationApprovalPayloadPreviewMode, OperationApprovalPolicy, OperationApprovalRiskLevel,
OperationSafetyClass, OperationSafetyPolicy, OperationStatus, ResponseCachePolicy,
RestTarget, RetryPolicy, Samples, Target, ToolDescription, ToolExample, WizardState,
};
pub use crate::protocol::{AuthKind, ExportMode, HttpMethod, Protocol};
pub use crate::secret::{Secret, SecretKind, SecretStatus, SecretVersion};
pub use crate::tool_catalog::{ToolCatalogAnalysis, ToolCatalogBudget};
pub use crate::tool_quality::{
ToolQualityCatalogTool, ToolQualityFinding, ToolQualityMappingRule, ToolQualityMappingSet,
ToolQualityReport, ToolQualitySchemaKind, ToolQualitySchemaNode, ToolQualitySeverity,
@@ -85,9 +90,10 @@ pub mod ports {
pub use access::{
InvitationStatus, InvitationToken, Membership, MembershipRole, PlatformApiKey,
PlatformApiKeyScope, PlatformApiKeyStatus, User, UserStatus,
PlatformApiKeyKind, PlatformApiKeyScope, PlatformApiKeyStatus, User, UserStatus,
};
pub use agent::{Agent, AgentOperationBinding, AgentStatus, AgentVersion};
pub use approval::{ApprovalRequest, ApprovalRequestStatus};
pub use auth::{
ApiKeyHeaderAuthConfig, ApiKeyQueryAuthConfig, AuthConfig, AuthProfile, BasicAuthConfig,
BearerAuthConfig,
@@ -120,20 +126,27 @@ pub use ext::protocol::{
SharedProtocolAdapter,
};
pub use ids::{
AgentId, AuditEventId, AuthProfileId, DescriptorId, InvitationId, InvocationLogId, OperationId,
PlatformApiKeyId, SampleId, SecretId, ToolId, UserId, UserSessionId, WorkspaceId,
AgentId, ApprovalRequestId, AuditEventId, AuthProfileId, DescriptorId, InvitationId,
InvocationLogId, OperationId, PlatformApiKeyId, SampleId, SecretId, ToolId, UserId,
UserSessionId, WorkspaceId,
};
pub use observability::{
InvocationLevel, InvocationLog, InvocationSource, InvocationStatus, UsagePeriod, UsageRollup,
INVOCATION_PREVIEW_MAX_BYTES, InvocationLevel, InvocationLog, InvocationSource,
InvocationStatus, UsagePeriod, UsageRollup, sanitize_invocation_preview,
};
pub use operation::{
ConfigExport, ConfirmationPolicy, ExecutionConfig, GeneratedDraft, GeneratedDraftStatus,
IdempotencyMode, IdempotencyPolicy, Operation, OperationSafetyClass, OperationSafetyPolicy,
OperationStatus, ResponseCachePolicy, RestTarget, RetryPolicy, Samples, Target,
ToolDescription, ToolExample, WizardState,
IdempotencyMode, IdempotencyPolicy, Operation, OperationApprovalMode,
OperationApprovalPayloadPreviewMode, OperationApprovalPolicy, OperationApprovalRiskLevel,
OperationSafetyClass, OperationSafetyPolicy, OperationStatus, ResponseCachePolicy, RestTarget,
RetryPolicy, Samples, Target, ToolDescription, ToolExample, WizardState,
};
pub use protocol::{AuthKind, ExportMode, HttpMethod, Protocol};
pub use secret::{Secret, SecretKind, SecretStatus, SecretVersion};
pub use tool_catalog::{
RECOMMENDED_TOOL_CATALOG_CONTEXT_TOKENS, ToolCatalogAnalysis, ToolCatalogAnalysisError,
ToolCatalogBudget, analyze_tool_catalog,
};
pub use tool_quality::{
ToolQualityCatalogTool, ToolQualityFinding, ToolQualityMappingRule, ToolQualityMappingSet,
ToolQualityReport, ToolQualitySchemaKind, ToolQualitySchemaNode, ToolQualitySeverity,
+93 -2
View File
@@ -1,9 +1,68 @@
use serde::{Deserialize, Serialize};
use serde_json::Value;
use serde_json::{Map, Value, json};
use time::OffsetDateTime;
use crate::{AgentId, OperationId, WorkspaceId};
pub const INVOCATION_PREVIEW_MAX_BYTES: usize = 16 * 1024;
pub fn sanitize_invocation_preview(value: &Value) -> Value {
let redacted = redact_sensitive_fields(value);
let Ok(encoded) = serde_json::to_vec(&redacted) else {
return Value::Null;
};
if encoded.len() <= INVOCATION_PREVIEW_MAX_BYTES {
return redacted;
}
let preview = String::from_utf8_lossy(&encoded[..INVOCATION_PREVIEW_MAX_BYTES]).into_owned();
json!({
"truncated": true,
"original_bytes": encoded.len(),
"preview": preview,
})
}
fn redact_sensitive_fields(value: &Value) -> Value {
match value {
Value::Object(object) => Value::Object(
object
.iter()
.map(|(key, value)| {
let value = if is_sensitive_key(key) {
Value::String("[REDACTED]".to_owned())
} else {
redact_sensitive_fields(value)
};
(key.clone(), value)
})
.collect::<Map<String, Value>>(),
),
Value::Array(items) => Value::Array(items.iter().map(redact_sensitive_fields).collect()),
_ => value.clone(),
}
}
fn is_sensitive_key(key: &str) -> bool {
let normalized = key.to_ascii_lowercase().replace('-', "_");
let compact = normalized
.chars()
.filter(char::is_ascii_alphanumeric)
.collect::<String>();
[
"authorization",
"cookie",
"password",
"passwd",
"secret",
"token",
]
.iter()
.any(|sensitive| compact.contains(sensitive))
|| ["apikey", "accesskey", "privatekey"]
.iter()
.any(|sensitive| compact.contains(sensitive))
}
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum InvocationSource {
@@ -87,7 +146,10 @@ mod tests {
use serde_json::json;
use time::{OffsetDateTime, format_description::well_known::Rfc3339};
use super::{InvocationLevel, InvocationLog, InvocationSource, InvocationStatus, UsagePeriod};
use super::{
INVOCATION_PREVIEW_MAX_BYTES, InvocationLevel, InvocationLog, InvocationSource,
InvocationStatus, UsagePeriod, sanitize_invocation_preview,
};
use crate::{AgentId, OperationId, WorkspaceId, ids::InvocationLogId};
fn timestamp(value: &str) -> OffsetDateTime {
@@ -129,4 +191,33 @@ mod tests {
assert_eq!(value, "7d");
}
#[test]
fn redacts_sensitive_fields_recursively() {
let preview = sanitize_invocation_preview(&json!({
"authorization": "Bearer secret",
"nested": {
"api_key": "key",
"refreshToken": "token",
"client_secret_value": "secret",
"value": 42
}
}));
assert_eq!(preview["authorization"], "[REDACTED]");
assert_eq!(preview["nested"]["api_key"], "[REDACTED]");
assert_eq!(preview["nested"]["refreshToken"], "[REDACTED]");
assert_eq!(preview["nested"]["client_secret_value"], "[REDACTED]");
assert_eq!(preview["nested"]["value"], 42);
}
#[test]
fn truncates_large_previews() {
let preview = sanitize_invocation_preview(&json!({
"body": "x".repeat(INVOCATION_PREVIEW_MAX_BYTES * 2)
}));
assert_eq!(preview["truncated"], true);
assert!(preview["original_bytes"].as_u64().unwrap() > INVOCATION_PREVIEW_MAX_BYTES as u64);
}
}
+42
View File
@@ -103,6 +103,45 @@ pub struct OperationSafetyPolicy {
pub confirmation: Option<ConfirmationPolicy>,
}
#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum OperationApprovalRiskLevel {
#[default]
Normal,
Dangerous,
Financial,
Irreversible,
}
#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum OperationApprovalPayloadPreviewMode {
#[default]
Summary,
MaskedJson,
}
#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum OperationApprovalMode {
#[default]
Custom,
Elicitation,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct OperationApprovalPolicy {
pub required: bool,
#[serde(default)]
pub mode: OperationApprovalMode,
pub risk_level: OperationApprovalRiskLevel,
pub ttl_seconds: u32,
pub show_payload_preview: bool,
pub payload_preview_mode: OperationApprovalPayloadPreviewMode,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub elicitation_message: Option<String>,
}
#[derive(Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
pub struct ExecutionConfig {
pub timeout_ms: u64,
@@ -115,6 +154,8 @@ pub struct ExecutionConfig {
#[serde(skip_serializing_if = "Option::is_none")]
pub safety: Option<OperationSafetyPolicy>,
#[serde(skip_serializing_if = "Option::is_none")]
pub approval_policy: Option<OperationApprovalPolicy>,
#[serde(skip_serializing_if = "Option::is_none")]
pub auth_profile_ref: Option<AuthProfileId>,
#[serde(default, skip_serializing_if = "BTreeMap::is_empty")]
pub headers: BTreeMap<String, String>,
@@ -411,6 +452,7 @@ updated_at: 2026-03-25T08:10:00Z
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: Some(AuthProfileId::new("auth_01")),
headers: BTreeMap::new(),
},
+89
View File
@@ -0,0 +1,89 @@
use serde::{Deserialize, Serialize};
use serde_json::Value;
use thiserror::Error;
use crate::tool_quality::{
ToolQualityCatalogTool, ToolQualityFinding, ToolQualityReport, ToolQualitySeverity,
analyze_agent_tool_catalog_quality,
};
pub const RECOMMENDED_TOOL_CATALOG_CONTEXT_TOKENS: usize = 4_096;
const ESTIMATED_TOKEN_UTF8_BYTES: usize = 3;
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ToolCatalogBudget {
pub tool_count: usize,
pub serialized_bytes: usize,
pub estimated_context_tokens: usize,
pub largest_tool_estimated_context_tokens: usize,
pub recommended_context_tokens: usize,
pub exceeds_recommended_budget: bool,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ToolCatalogAnalysis {
pub budget: ToolCatalogBudget,
pub quality: ToolQualityReport,
}
#[derive(Debug, Error)]
pub enum ToolCatalogAnalysisError {
#[error("tool catalog and definitions length mismatch")]
DefinitionCountMismatch,
#[error("tool catalog definition is missing string field: {0}")]
DefinitionFieldMissing(&'static str),
#[error("tool catalog definition serialization failed: {0}")]
Serialization(#[from] serde_json::Error),
}
pub fn analyze_tool_catalog(
tools: &[ToolQualityCatalogTool],
definitions: &[Value],
) -> Result<ToolCatalogAnalysis, ToolCatalogAnalysisError> {
if tools.len() != definitions.len() {
return Err(ToolCatalogAnalysisError::DefinitionCountMismatch);
}
let mut serialized_bytes = 0usize;
let mut estimated_context_tokens = 0usize;
let mut largest_tool_estimated_context_tokens = 0usize;
for definition in definitions {
let definition_bytes = serde_json::to_vec(definition)?.len();
let definition_tokens = estimate_context_tokens(definition_bytes);
serialized_bytes = serialized_bytes.saturating_add(definition_bytes);
estimated_context_tokens = estimated_context_tokens.saturating_add(definition_tokens);
largest_tool_estimated_context_tokens =
largest_tool_estimated_context_tokens.max(definition_tokens);
}
let exceeds_recommended_budget =
estimated_context_tokens > RECOMMENDED_TOOL_CATALOG_CONTEXT_TOKENS;
let budget = ToolCatalogBudget {
tool_count: tools.len(),
serialized_bytes,
estimated_context_tokens,
largest_tool_estimated_context_tokens,
recommended_context_tokens: RECOMMENDED_TOOL_CATALOG_CONTEXT_TOKENS,
exceeds_recommended_budget,
};
let mut quality = analyze_agent_tool_catalog_quality(tools);
if exceeds_recommended_budget {
quality.findings.push(ToolQualityFinding {
severity: ToolQualitySeverity::Warning,
code: "agent_catalog_context_budget_high".to_owned(),
message: "Каталог инструментов занимает слишком много контекста модели.".to_owned(),
suggested_action: Some(
"Сократите описания и схемы либо разделите инструменты между специализированными агентами."
.to_owned(),
),
field_path: Some("agent.operations".to_owned()),
});
quality = ToolQualityReport::new(quality.findings);
}
Ok(ToolCatalogAnalysis { budget, quality })
}
fn estimate_context_tokens(serialized_bytes: usize) -> usize {
serialized_bytes.div_ceil(ESTIMATED_TOKEN_UTF8_BYTES)
}
+1
View File
@@ -1,3 +1,4 @@
mod unit {
mod tool_catalog;
mod tool_quality;
}
@@ -0,0 +1,79 @@
use crank_core::{
ToolCatalogAnalysis, ToolQualityCatalogTool, ToolQualitySeverity, analyze_tool_catalog,
};
use serde_json::json;
#[test]
fn measures_the_actual_serialized_catalog_definition() {
let definitions = vec![json!({
"name": "get_exchange_rate",
"title": "Получить курс",
"description": "Возвращает актуальный курс выбранной валютной пары.",
"inputSchema": {
"type": "object",
"properties": {
"base": {"type": "string"},
"quote": {"type": "string"}
},
"required": ["base", "quote"]
}
})];
let analysis = analyze_tool_catalog(&[tool("get_exchange_rate")], &definitions).unwrap();
let expected_bytes = serde_json::to_vec(&definitions[0]).unwrap().len();
assert_eq!(analysis.budget.tool_count, 1);
assert_eq!(analysis.budget.serialized_bytes, expected_bytes);
assert!(analysis.budget.estimated_context_tokens > 0);
assert_eq!(
analysis.budget.largest_tool_estimated_context_tokens,
analysis.budget.estimated_context_tokens
);
}
#[test]
fn warns_when_actual_catalog_exceeds_context_budget() {
let tools = (0..9)
.map(|index| tool(&format!("large_tool_{index}")))
.collect::<Vec<_>>();
let definitions = (0..9)
.map(|index| {
json!({
"name": format!("large_tool_{index}"),
"description": "x".repeat(1_500),
"inputSchema": {"type": "object", "properties": {}}
})
})
.collect::<Vec<_>>();
let analysis = analyze_tool_catalog(&tools, &definitions).unwrap();
assert!(analysis.budget.exceeds_recommended_budget);
assert!(has_warning(&analysis, "agent_catalog_context_budget_high"));
}
#[test]
fn rejects_mismatch_between_catalog_tools_and_definitions() {
let error = analyze_tool_catalog(&[tool("one")], &[]).unwrap_err();
assert_eq!(
error.to_string(),
"tool catalog and definitions length mismatch"
);
}
fn tool(name: &str) -> ToolQualityCatalogTool {
ToolQualityCatalogTool {
name: name.to_owned(),
display_name: name.to_owned(),
description: format!("Инструмент {name} выполняет одну конкретную операцию."),
}
}
fn has_warning(analysis: &ToolCatalogAnalysis, code: &str) -> bool {
analysis
.quality
.findings
.iter()
.any(|finding| finding.code == code && finding.severity == ToolQualitySeverity::Warning)
}
+1
View File
@@ -231,6 +231,7 @@ fn default_execution_config() -> ExecutionConfig {
response_cache: None,
idempotency: None,
safety: None,
approval_policy: None,
auth_profile_ref: None,
headers: BTreeMap::new(),
}
+4 -4
View File
@@ -193,10 +193,10 @@ fn text(value: &Value, key: &str) -> Option<String> {
fn collapse_composition(value: &Value) -> Value {
for key in ["allOf", "oneOf", "anyOf"] {
if let Some(items) = value.get(key).and_then(Value::as_array) {
if let Some(first) = items.first() {
return first.clone();
}
if let Some(items) = value.get(key).and_then(Value::as_array)
&& let Some(first) = items.first()
{
return first.clone();
}
}
value.clone()
+1
View File
@@ -11,6 +11,7 @@ crank-mapping = { path = "../crank-mapping" }
crank-schema = { path = "../crank-schema" }
serde.workspace = true
serde_json.workspace = true
sha2.workspace = true
sqlx.workspace = true
thiserror.workspace = true
time.workspace = true
+32 -28
View File
@@ -9,12 +9,12 @@ pub use ext::{ExtensionMigration, RegistryExtension, apply_extension_migrations}
pub mod records {
pub use crate::model::{
AgentSummary, AgentVersionRecord, AuthUserRecord, DescriptorKind, DescriptorMetadata,
ImportJob, ImportJobId, ImportJobKind, ImportJobStatus, InvitationRecord,
InvocationLogRecord, MembershipRecord, OperationAgentRef, OperationSampleMetadata,
OperationSummary, OperationUsageSummary, OperationVersionRecord, Page,
PlatformApiKeyRecord, PublishedAgentTool, RegistryOperation, SampleKind, SecretRecord,
SecretVersionRecord, SessionRecord, UsageAgentBreakdown, UsageBucket,
AgentSummary, AgentVersionRecord, ApprovalRequestRecord, AuthUserRecord, DescriptorKind,
DescriptorMetadata, ImportJob, ImportJobId, ImportJobKind, ImportJobStatus,
InvitationRecord, InvocationLogRecord, MembershipRecord, OperationAgentRef,
OperationSampleMetadata, OperationSummary, OperationUsageSummary, OperationVersionRecord,
Page, PlatformApiKeyRecord, PublishedAgentTool, RegistryOperation, SampleKind,
SecretRecord, SecretVersionRecord, SessionRecord, UsageAgentBreakdown, UsageBucket,
UsageOperationBreakdown, UsageRollupRecord, UsageSummary, UsageTimelinePoint,
WorkspaceMembershipRecord, WorkspaceRecord, WorkspaceUpstream, WorkspaceUpstreamId,
YamlImportJob, YamlImportJobCompletion, YamlImportJobId, YamlImportJobStatus,
@@ -23,13 +23,15 @@ pub mod records {
pub mod requests {
pub use crate::model::{
CreateAgentDraftVersionRequest, CreateAgentRequest, CreateImportJobRequest,
CreateInvitationRequest, CreateInvocationLogRequest, CreatePlatformApiKeyRequest,
CreateSecretRequest, CreateVersionRequest, CreateWorkspaceRequest,
CreateYamlImportJobRequest, FinishImportJobRequest, ListInvocationLogsQuery,
PublishAgentRequest, PublishRequest, RotateSecretRequest, SaveAgentBindingsRequest,
SaveAuthProfileRequest, SaveDescriptorMetadataRequest, SaveSampleMetadataRequest,
SaveWorkspaceUpstreamRequest, UpdateWorkspaceRequest, UsageQuery,
CreateAgentDraftVersionRequest, CreateAgentRequest, CreateApprovalRequest,
CreateImportJobRequest, CreateInvitationRequest, CreateInvocationLogRequest,
CreatePlatformApiKeyRequest, CreateSecretRequest, CreateVersionRequest,
CreateWorkspaceRequest, CreateYamlImportJobRequest, DecideApprovalRequest,
ExpireApprovalRequest, FinishApprovalRequest, FinishImportJobRequest,
ListApprovalRequestsQuery, ListInvocationLogsQuery, PublishAgentRequest, PublishRequest,
RotateSecretRequest, SaveAgentBindingsRequest, SaveAuthProfileRequest,
SaveDescriptorMetadataRequest, SaveSampleMetadataRequest, SaveWorkspaceUpstreamRequest,
UpdateWorkspaceRequest, UsageQuery,
};
}
@@ -39,20 +41,22 @@ pub mod infrastructure {
}
pub use model::{
AgentSummary, AgentVersionRecord, AuthUserRecord, CreateAgentDraftVersionRequest,
CreateAgentRequest, CreateImportJobRequest, CreateInvitationRequest,
CreateInvocationLogRequest, CreatePlatformApiKeyRequest, CreateSecretRequest,
CreateVersionRequest, CreateWorkspaceRequest, CreateYamlImportJobRequest, DescriptorKind,
DescriptorMetadata, FinishImportJobRequest, ImportJob, ImportJobId, ImportJobKind,
ImportJobStatus, InvitationRecord, InvocationLogRecord, ListInvocationLogsQuery,
MembershipRecord, OperationAgentRef, OperationSampleMetadata, OperationSummary,
OperationUsageSummary, OperationVersionRecord, Page, PlatformApiKeyRecord, PublishAgentRequest,
PublishRequest, PublishedAgentTool, RegistryOperation, RotateSecretRequest, SampleKind,
SaveAgentBindingsRequest, SaveAuthProfileRequest, SaveDescriptorMetadataRequest,
SaveSampleMetadataRequest, SaveWorkspaceUpstreamRequest, SecretRecord, SecretVersionRecord,
SessionRecord, UpdateWorkspaceRequest, UsageAgentBreakdown, UsageBucket,
UsageOperationBreakdown, UsageQuery, UsageRollupRecord, UsageSummary, UsageTimelinePoint,
WorkspaceMembershipRecord, WorkspaceRecord, WorkspaceUpstream, WorkspaceUpstreamId,
YamlImportJob, YamlImportJobCompletion, YamlImportJobId, YamlImportJobStatus,
AgentSummary, AgentVersionRecord, ApprovalRequestRecord, AuthUserRecord,
CreateAgentDraftVersionRequest, CreateAgentRequest, CreateApprovalRequest,
CreateImportJobRequest, CreateInvitationRequest, CreateInvocationLogRequest,
CreatePlatformApiKeyRequest, CreateSecretRequest, CreateVersionRequest, CreateWorkspaceRequest,
CreateYamlImportJobRequest, DecideApprovalRequest, DescriptorKind, DescriptorMetadata,
ExpireApprovalRequest, FinishApprovalRequest, FinishImportJobRequest, ImportJob, ImportJobId,
ImportJobKind, ImportJobStatus, InvitationRecord, InvocationLogRecord,
ListApprovalRequestsQuery, ListInvocationLogsQuery, MembershipRecord, OperationAgentRef,
OperationSampleMetadata, OperationSummary, OperationUsageSummary, OperationVersionRecord, Page,
PlatformApiKeyRecord, PublishAgentRequest, PublishRequest, PublishedAgentTool,
RegistryOperation, RotateSecretRequest, SampleKind, SaveAgentBindingsRequest,
SaveAuthProfileRequest, SaveDescriptorMetadataRequest, SaveSampleMetadataRequest,
SaveWorkspaceUpstreamRequest, SecretRecord, SecretVersionRecord, SessionRecord,
UpdateWorkspaceRequest, UsageAgentBreakdown, UsageBucket, UsageOperationBreakdown, UsageQuery,
UsageRollupRecord, UsageSummary, UsageTimelinePoint, WorkspaceMembershipRecord,
WorkspaceRecord, WorkspaceUpstream, WorkspaceUpstreamId, YamlImportJob,
YamlImportJobCompletion, YamlImportJobId, YamlImportJobStatus,
};
pub use postgres::{PostgresPoolConfig, PostgresPoolConfigError, PostgresRegistry};
+67 -1
View File
@@ -148,11 +148,14 @@ pub async fn apply_postgres(pool: &PgPool) -> Result<(), sqlx::Error> {
name text not null,
prefix text not null,
secret_hash text not null,
key_kind text not null default 'mcp_client',
scopes_json jsonb not null,
status text not null,
created_at timestamptz not null,
last_used_at timestamptz null,
revoked_at timestamptz null
revoked_at timestamptz null,
expires_at timestamptz null,
allowed_origins_json jsonb not null default '[]'::jsonb
)",
)
.execute(pool)
@@ -166,6 +169,19 @@ pub async fn apply_postgres(pool: &PgPool) -> Result<(), sqlx::Error> {
query("alter table platform_api_keys add column if not exists agent_id text null")
.execute(pool)
.await?;
query(
"alter table platform_api_keys add column if not exists key_kind text not null default 'mcp_client'",
)
.execute(pool)
.await?;
query("alter table platform_api_keys add column if not exists expires_at timestamptz null")
.execute(pool)
.await?;
query(
"alter table platform_api_keys add column if not exists allowed_origins_json jsonb not null default '[]'::jsonb",
)
.execute(pool)
.await?;
query(
"insert into workspaces (
@@ -543,6 +559,56 @@ pub async fn apply_postgres(pool: &PgPool) -> Result<(), sqlx::Error> {
.execute(pool)
.await?;
query(
"create table if not exists approval_requests (
id text primary key,
workspace_id text not null references workspaces(id) on delete cascade,
agent_id text not null references agents(id) on delete cascade,
operation_id text not null references operations(id) on delete cascade,
operation_version integer not null,
status text not null,
risk_level text not null,
request_payload_json jsonb not null,
response_payload_json jsonb null,
created_at timestamptz not null,
expires_at timestamptz not null,
decided_at timestamptz null,
decided_by_key_id text null references platform_api_keys(id) on delete set null,
decision_note text null
)",
)
.execute(pool)
.await?;
query("alter table approval_requests drop column if exists confirmation_title")
.execute(pool)
.await?;
query("alter table approval_requests drop column if exists confirmation_body")
.execute(pool)
.await?;
query("alter table approval_requests add column if not exists execution_started_at timestamptz null")
.execute(pool)
.await?;
query("alter table approval_requests add column if not exists execution_attempts integer not null default 0")
.execute(pool)
.await?;
query("alter table approval_requests add column if not exists request_fingerprint text null")
.execute(pool)
.await?;
query(
"create unique index if not exists approval_requests_pending_fingerprint_idx
on approval_requests(agent_id, operation_id, operation_version, request_fingerprint)
where status = 'pending' and request_fingerprint is not null",
)
.execute(pool)
.await?;
query(
"create index if not exists approval_requests_agent_status_idx
on approval_requests(workspace_id, agent_id, status, expires_at)",
)
.execute(pool)
.await?;
query(
"create table if not exists invocation_logs (
id text primary key,

Some files were not shown because too many files have changed in this diff Show More