feat(phase-4a): groups sync + X-Project-Key header substrate
Foundational work for the upcoming group-scoped sharing feature.
Schema (migration 0003_groups.sql + drizzle schema):
- memory_access enum ('ro' | 'rw') reserved for Agent B's project_shares
- groups (id, oidc_iss, name, display_name, …) keyed by (oidc_iss, name)
so different IdPs can both have e.g. "platform" without colliding
- user_groups (user_id, group_id, synced_at) PK (user_id, group_id)
Auth (auth.ts + lib/auth/sync-groups.ts):
- jwt callback now syncs `profile.groups` after upserting the user
- syncUserGroupsFromClaim runs in a single tx: upserts each group,
inserts new memberships, deletes ones no longer in the claim
- missing/empty claim → user has zero groups (wipe memberships)
- EntraID GUID-vs-name edge case: we treat whatever strings the claim
emits as names verbatim; groups overage (>200 groups → no claim)
is documented as unsupported in v1
UserContext + JWT (lib/mcp/context.ts, lib/auth/jwt.ts):
- AuthenticatedClaims.groups surfaced from verified JWT payload
- UserContext.groups: string[] — live from OIDC token claim, falls
back to DB snapshot for CLI (HMAC) tokens which carry no claim
- UserContext.defaultProjectKey: optional, set from header
MCP route (app/api/mcp/route.ts):
- reads X-Project-Key header, validates against ProjectKey Zod schema,
400 on invalid; empty/missing leaves defaultProjectKey undefined
- auto-upserts the header-supplied project so first-use works without
a separate project.identify call
Tools (lib/mcp/tools.ts):
- withDefaultProject helper injects ctx.defaultProjectKey when the
caller omits `project`. Per-tool defaultScope hint avoids breaking
snippet.put (user-scope default) while making memory.write
(project-scope default) honor the header
- applied to memory.write/list/search/update and all snippet.* tools
Web UI:
- /settings/groups debug page lists current memberships with synced_at
and a clear empty state pointing at README troubleshooting
- /settings/tokens grows a "Pin to project" dropdown; selected key is
baked into the generated `claude mcp add` snippet as
`--header "X-Project-Key: <key>"`. The JWT itself stays
identity-only — pinning is purely a UX shortcut
- settings landing page links to /settings/groups
- README troubleshooting bullet covers the empty-groups path for
Authentik / EntraID / Keycloak
Refactor:
- extracted resolveProjectId + upsertProject from memory-actions.ts
into lib/projects.ts so the MCP route can reuse upsertProject
Verification:
- pnpm typecheck clean
- SKIP_ENV_VALIDATION=true pnpm build clean; /settings/groups in route table
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,7 +1,9 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { ProjectKey } from "@shared-memory/schemas";
|
||||
import { authenticateBearer, UnauthorizedError } from "@/lib/auth/jwt";
|
||||
import { userContextFromClaims } from "@/lib/mcp/context";
|
||||
import { dispatchMcpMessage } from "@/lib/mcp/server";
|
||||
import { upsertProject } from "@/lib/projects";
|
||||
|
||||
export const runtime = "nodejs";
|
||||
export const dynamic = "force-dynamic";
|
||||
@@ -49,8 +51,37 @@ export async function POST(req: Request) {
|
||||
);
|
||||
}
|
||||
|
||||
// ---- optional X-Project-Key header → default project for this request ----
|
||||
// The header lets a client (e.g. a `claude mcp add` snippet generated from
|
||||
// /settings/tokens) pin every call to a specific project without having to
|
||||
// pass `project` on each tool invocation. Tools that take an optional
|
||||
// `project` arg fall back to this when the caller omits it.
|
||||
let defaultProjectKey: string | undefined;
|
||||
const rawProjectKey = req.headers.get("x-project-key");
|
||||
if (rawProjectKey !== null && rawProjectKey !== "") {
|
||||
const parsed = ProjectKey.safeParse(rawProjectKey);
|
||||
if (!parsed.success) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
error: "invalid X-Project-Key",
|
||||
detail: parsed.error.issues.map((i) => i.message).join("; "),
|
||||
},
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
defaultProjectKey = parsed.data;
|
||||
}
|
||||
|
||||
// ---- resolve user, dispatch ----
|
||||
const ctx = await userContextFromClaims(claims);
|
||||
const ctx = await userContextFromClaims(claims, { defaultProjectKey });
|
||||
|
||||
// Auto-create the header-supplied project if it doesn't exist yet. This
|
||||
// makes pinning via `X-Project-Key` work transparently — the user doesn't
|
||||
// have to call `project.identify` first when they paste the generated
|
||||
// `claude mcp add` snippet from /settings/tokens.
|
||||
if (defaultProjectKey) {
|
||||
await upsertProject(ctx.userId, defaultProjectKey);
|
||||
}
|
||||
|
||||
// MCP supports batched requests (array) and single. Handle both.
|
||||
if (Array.isArray(body)) {
|
||||
|
||||
Reference in New Issue
Block a user