Foundational work for the upcoming group-scoped sharing feature.
Schema (migration 0003_groups.sql + drizzle schema):
- memory_access enum ('ro' | 'rw') reserved for Agent B's project_shares
- groups (id, oidc_iss, name, display_name, …) keyed by (oidc_iss, name)
so different IdPs can both have e.g. "platform" without colliding
- user_groups (user_id, group_id, synced_at) PK (user_id, group_id)
Auth (auth.ts + lib/auth/sync-groups.ts):
- jwt callback now syncs `profile.groups` after upserting the user
- syncUserGroupsFromClaim runs in a single tx: upserts each group,
inserts new memberships, deletes ones no longer in the claim
- missing/empty claim → user has zero groups (wipe memberships)
- EntraID GUID-vs-name edge case: we treat whatever strings the claim
emits as names verbatim; groups overage (>200 groups → no claim)
is documented as unsupported in v1
UserContext + JWT (lib/mcp/context.ts, lib/auth/jwt.ts):
- AuthenticatedClaims.groups surfaced from verified JWT payload
- UserContext.groups: string[] — live from OIDC token claim, falls
back to DB snapshot for CLI (HMAC) tokens which carry no claim
- UserContext.defaultProjectKey: optional, set from header
MCP route (app/api/mcp/route.ts):
- reads X-Project-Key header, validates against ProjectKey Zod schema,
400 on invalid; empty/missing leaves defaultProjectKey undefined
- auto-upserts the header-supplied project so first-use works without
a separate project.identify call
Tools (lib/mcp/tools.ts):
- withDefaultProject helper injects ctx.defaultProjectKey when the
caller omits `project`. Per-tool defaultScope hint avoids breaking
snippet.put (user-scope default) while making memory.write
(project-scope default) honor the header
- applied to memory.write/list/search/update and all snippet.* tools
Web UI:
- /settings/groups debug page lists current memberships with synced_at
and a clear empty state pointing at README troubleshooting
- /settings/tokens grows a "Pin to project" dropdown; selected key is
baked into the generated `claude mcp add` snippet as
`--header "X-Project-Key: <key>"`. The JWT itself stays
identity-only — pinning is purely a UX shortcut
- settings landing page links to /settings/groups
- README troubleshooting bullet covers the empty-groups path for
Authentik / EntraID / Keycloak
Refactor:
- extracted resolveProjectId + upsertProject from memory-actions.ts
into lib/projects.ts so the MCP route can reuse upsertProject
Verification:
- pnpm typecheck clean
- SKIP_ENV_VALIDATION=true pnpm build clean; /settings/groups in route table
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
92 lines
3.0 KiB
TypeScript
92 lines
3.0 KiB
TypeScript
import Link from "next/link";
|
|
import { eq } from "drizzle-orm";
|
|
import { auth } from "@/auth";
|
|
import { db } from "@/lib/db/client";
|
|
import { users } from "@/lib/db/schema";
|
|
import { Container, PageHeader } from "@/app/_components/ui/container";
|
|
import { Card, CardBody, CardHeader } from "@/app/_components/ui/card";
|
|
import { Button } from "@/app/_components/ui/button";
|
|
|
|
export const dynamic = "force-dynamic";
|
|
|
|
export default async function SettingsPage() {
|
|
const session = await auth();
|
|
const userId = session!.user.id;
|
|
|
|
const userRow = await db
|
|
.select()
|
|
.from(users)
|
|
.where(eq(users.id, userId))
|
|
.limit(1);
|
|
const user = userRow[0];
|
|
|
|
return (
|
|
<Container className="pt-6 max-w-3xl">
|
|
<PageHeader title="Settings" />
|
|
|
|
<div className="space-y-6">
|
|
<Card>
|
|
<CardHeader className="text-sm font-medium text-fg">Profile</CardHeader>
|
|
<CardBody className="space-y-2 text-sm">
|
|
<Field label="Name" value={user?.name} />
|
|
<Field label="Email" value={user?.email} />
|
|
<Field label="Internal user id" value={user?.id} mono />
|
|
<Field label="OIDC issuer" value={user?.oidcIss} mono />
|
|
<Field label="OIDC sub" value={user?.oidcSub} mono />
|
|
<Field
|
|
label="Joined"
|
|
value={user?.createdAt ? new Date(user.createdAt).toLocaleString() : null}
|
|
/>
|
|
</CardBody>
|
|
</Card>
|
|
|
|
<Card>
|
|
<CardHeader className="flex items-center">
|
|
<span className="text-sm font-medium text-fg flex-1">CLI tokens</span>
|
|
<Link href="/settings/tokens" className="no-underline">
|
|
<Button variant="secondary" size="sm">Manage tokens</Button>
|
|
</Link>
|
|
</CardHeader>
|
|
<CardBody className="text-sm text-fg-muted">
|
|
Bearer tokens for headless/automated MCP clients. Visit{" "}
|
|
<Link href="/settings/tokens">/settings/tokens</Link> to generate
|
|
and revoke them.
|
|
</CardBody>
|
|
</Card>
|
|
|
|
<Card>
|
|
<CardHeader className="flex items-center">
|
|
<span className="text-sm font-medium text-fg flex-1">Groups</span>
|
|
<Link href="/settings/groups" className="no-underline">
|
|
<Button variant="secondary" size="sm">View groups</Button>
|
|
</Link>
|
|
</CardHeader>
|
|
<CardBody className="text-sm text-fg-muted">
|
|
OIDC group memberships from your IdP, refreshed at sign-in. Used
|
|
by the upcoming sharing feature to scope project visibility.
|
|
</CardBody>
|
|
</Card>
|
|
</div>
|
|
</Container>
|
|
);
|
|
}
|
|
|
|
function Field({
|
|
label,
|
|
value,
|
|
mono,
|
|
}: {
|
|
label: string;
|
|
value: string | null | undefined;
|
|
mono?: boolean;
|
|
}) {
|
|
return (
|
|
<div className="flex items-baseline gap-3">
|
|
<span className="text-fg-muted w-36 shrink-0">{label}</span>
|
|
<span className={`${mono ? "font-mono text-xs" : "text-sm"} text-fg break-all`}>
|
|
{value ?? <span className="text-fg-subtle">—</span>}
|
|
</span>
|
|
</div>
|
|
);
|
|
}
|