feat(phase-4a): groups sync + X-Project-Key header substrate
Foundational work for the upcoming group-scoped sharing feature.
Schema (migration 0003_groups.sql + drizzle schema):
- memory_access enum ('ro' | 'rw') reserved for Agent B's project_shares
- groups (id, oidc_iss, name, display_name, …) keyed by (oidc_iss, name)
so different IdPs can both have e.g. "platform" without colliding
- user_groups (user_id, group_id, synced_at) PK (user_id, group_id)
Auth (auth.ts + lib/auth/sync-groups.ts):
- jwt callback now syncs `profile.groups` after upserting the user
- syncUserGroupsFromClaim runs in a single tx: upserts each group,
inserts new memberships, deletes ones no longer in the claim
- missing/empty claim → user has zero groups (wipe memberships)
- EntraID GUID-vs-name edge case: we treat whatever strings the claim
emits as names verbatim; groups overage (>200 groups → no claim)
is documented as unsupported in v1
UserContext + JWT (lib/mcp/context.ts, lib/auth/jwt.ts):
- AuthenticatedClaims.groups surfaced from verified JWT payload
- UserContext.groups: string[] — live from OIDC token claim, falls
back to DB snapshot for CLI (HMAC) tokens which carry no claim
- UserContext.defaultProjectKey: optional, set from header
MCP route (app/api/mcp/route.ts):
- reads X-Project-Key header, validates against ProjectKey Zod schema,
400 on invalid; empty/missing leaves defaultProjectKey undefined
- auto-upserts the header-supplied project so first-use works without
a separate project.identify call
Tools (lib/mcp/tools.ts):
- withDefaultProject helper injects ctx.defaultProjectKey when the
caller omits `project`. Per-tool defaultScope hint avoids breaking
snippet.put (user-scope default) while making memory.write
(project-scope default) honor the header
- applied to memory.write/list/search/update and all snippet.* tools
Web UI:
- /settings/groups debug page lists current memberships with synced_at
and a clear empty state pointing at README troubleshooting
- /settings/tokens grows a "Pin to project" dropdown; selected key is
baked into the generated `claude mcp add` snippet as
`--header "X-Project-Key: <key>"`. The JWT itself stays
identity-only — pinning is purely a UX shortcut
- settings landing page links to /settings/groups
- README troubleshooting bullet covers the empty-groups path for
Authentik / EntraID / Keycloak
Refactor:
- extracted resolveProjectId + upsertProject from memory-actions.ts
into lib/projects.ts so the MCP route can reuse upsertProject
Verification:
- pnpm typecheck clean
- SKIP_ENV_VALIDATION=true pnpm build clean; /settings/groups in route table
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,29 +1,68 @@
|
||||
import { revalidatePath } from "next/cache";
|
||||
import { and, desc, eq, isNull } from "drizzle-orm";
|
||||
import { and, asc, desc, eq, isNull } from "drizzle-orm";
|
||||
import { auth } from "@/auth";
|
||||
import { db } from "@/lib/db/client";
|
||||
import { cliTokens, users } from "@/lib/db/schema";
|
||||
import { cliTokens, projects, users } from "@/lib/db/schema";
|
||||
import {
|
||||
mintCliToken,
|
||||
revokeCliToken,
|
||||
CLI_TOKEN_TTL_SECONDS,
|
||||
} from "@/lib/auth/cli-token";
|
||||
import { ProjectKey } from "@shared-memory/schemas";
|
||||
import { Container, PageHeader } from "@/app/_components/ui/container";
|
||||
import { Card, CardBody, CardHeader } from "@/app/_components/ui/card";
|
||||
import { Badge } from "@/app/_components/ui/badge";
|
||||
import { EmptyState } from "@/app/_components/ui/empty-state";
|
||||
import TokensManager from "./tokens-manager";
|
||||
import TokensManager, { type CreateTokenState } from "./tokens-manager";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
async function createTokenAction(_prev: { token: string | null; error: string | null }, formData: FormData): Promise<{ token: string | null; error: string | null }> {
|
||||
async function createTokenAction(
|
||||
_prev: CreateTokenState,
|
||||
formData: FormData,
|
||||
): Promise<CreateTokenState> {
|
||||
"use server";
|
||||
try {
|
||||
const session = await auth();
|
||||
if (!session?.user?.id) return { token: null, error: "not authenticated" };
|
||||
if (!session?.user?.id) {
|
||||
return { token: null, error: "not authenticated", projectKey: null };
|
||||
}
|
||||
|
||||
const name = String(formData.get("name") ?? "").trim() || `Token ${new Date().toISOString().slice(0, 10)}`;
|
||||
|
||||
// Optional pin-to-project. The token JWT itself does NOT need a project
|
||||
// claim — pinning is purely a UX shortcut so the generated `claude mcp
|
||||
// add` snippet bakes in `X-Project-Key: <key>` and every call from
|
||||
// that client lands on the right project by default.
|
||||
const rawProject = String(formData.get("projectKey") ?? "").trim();
|
||||
let projectKey: string | null = null;
|
||||
if (rawProject.length > 0) {
|
||||
const parsed = ProjectKey.safeParse(rawProject);
|
||||
if (!parsed.success) {
|
||||
return {
|
||||
token: null,
|
||||
error: `invalid project key: ${parsed.error.issues.map((i) => i.message).join("; ")}`,
|
||||
projectKey: null,
|
||||
};
|
||||
}
|
||||
// Cross-check the project belongs to this user (defense in depth —
|
||||
// the dropdown is built from the user's projects, but the form is
|
||||
// re-submittable so don't trust the value).
|
||||
const found = await db
|
||||
.select({ key: projects.key })
|
||||
.from(projects)
|
||||
.where(and(eq(projects.userId, session.user.id), eq(projects.key, parsed.data)))
|
||||
.limit(1);
|
||||
if (!found[0]) {
|
||||
return {
|
||||
token: null,
|
||||
error: `unknown project '${parsed.data}'`,
|
||||
projectKey: null,
|
||||
};
|
||||
}
|
||||
projectKey = found[0].key;
|
||||
}
|
||||
|
||||
const userRow = await db
|
||||
.select({
|
||||
oidcIss: users.oidcIss,
|
||||
@@ -35,7 +74,7 @@ async function createTokenAction(_prev: { token: string | null; error: string |
|
||||
.where(eq(users.id, session.user.id))
|
||||
.limit(1);
|
||||
const u = userRow[0];
|
||||
if (!u) return { token: null, error: "user row not found" };
|
||||
if (!u) return { token: null, error: "user row not found", projectKey: null };
|
||||
|
||||
const minted = await mintCliToken(
|
||||
{
|
||||
@@ -49,9 +88,13 @@ async function createTokenAction(_prev: { token: string | null; error: string |
|
||||
);
|
||||
|
||||
revalidatePath("/settings/tokens");
|
||||
return { token: minted.token, error: null };
|
||||
return { token: minted.token, error: null, projectKey };
|
||||
} catch (e) {
|
||||
return { token: null, error: e instanceof Error ? e.message : "unknown error" };
|
||||
return {
|
||||
token: null,
|
||||
error: e instanceof Error ? e.message : "unknown error",
|
||||
projectKey: null,
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
@@ -68,19 +111,29 @@ export default async function TokensPage() {
|
||||
const session = await auth();
|
||||
const userId = session!.user.id;
|
||||
|
||||
const tokens = await db
|
||||
.select({
|
||||
id: cliTokens.id,
|
||||
name: cliTokens.name,
|
||||
jti: cliTokens.jti,
|
||||
createdAt: cliTokens.createdAt,
|
||||
lastUsedAt: cliTokens.lastUsedAt,
|
||||
expiresAt: cliTokens.expiresAt,
|
||||
revokedAt: cliTokens.revokedAt,
|
||||
})
|
||||
.from(cliTokens)
|
||||
.where(eq(cliTokens.userId, userId))
|
||||
.orderBy(desc(cliTokens.createdAt));
|
||||
const [tokens, projectRows] = await Promise.all([
|
||||
db
|
||||
.select({
|
||||
id: cliTokens.id,
|
||||
name: cliTokens.name,
|
||||
jti: cliTokens.jti,
|
||||
createdAt: cliTokens.createdAt,
|
||||
lastUsedAt: cliTokens.lastUsedAt,
|
||||
expiresAt: cliTokens.expiresAt,
|
||||
revokedAt: cliTokens.revokedAt,
|
||||
})
|
||||
.from(cliTokens)
|
||||
.where(eq(cliTokens.userId, userId))
|
||||
.orderBy(desc(cliTokens.createdAt)),
|
||||
db
|
||||
.select({
|
||||
key: projects.key,
|
||||
displayName: projects.displayName,
|
||||
})
|
||||
.from(projects)
|
||||
.where(eq(projects.userId, userId))
|
||||
.orderBy(asc(projects.key)),
|
||||
]);
|
||||
|
||||
const active = tokens.filter((t) => !t.revokedAt && t.expiresAt > new Date());
|
||||
const inactive = tokens.filter((t) => t.revokedAt || t.expiresAt <= new Date());
|
||||
@@ -96,7 +149,14 @@ export default async function TokensPage() {
|
||||
<Card className="mb-6">
|
||||
<CardHeader className="text-sm font-medium text-fg">Generate a new token</CardHeader>
|
||||
<CardBody>
|
||||
<TokensManager action={createTokenAction} ttlDays={ttlDays} />
|
||||
<TokensManager
|
||||
action={createTokenAction}
|
||||
ttlDays={ttlDays}
|
||||
projects={projectRows.map((p) => ({
|
||||
key: p.key,
|
||||
displayName: p.displayName,
|
||||
}))}
|
||||
/>
|
||||
</CardBody>
|
||||
</Card>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user