mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-10-11 12:18:59 +00:00
* feat(hooks/observe): add structured output validation hook (ObserveHook) - hooks/types.go: Add ObserveHook interface + BuiltInHookType enum - hooks/dispatcher.go: HookDispatcher emits ObserveHook with PhaseResult payload - pipeline/observe_stage.go: ObserveStage emits hook after ObserveResult built - pipeline/substates.go: ObserveStageResult carries hook results + validation errors - hooks/config.go: BuiltInHookTypeObserve added to BuiltInHookType enum PhaseResult carries structured output, token usage, tool calls + validation errors emitted post-ObserveStage. ObserveHook implementations can validate structured output against schemas, detect tool-call loops, enforce token budgets, etc. Hook fires after ObserveStage produces ObserveResult, before results propagate to next stage. ValidationError returned by hook halts pipeline and propagates error to caller without further stage execution. Co-Authored-By: Claude <noreply@anthropic.com> * ui(hooks): add post_model_response event to web UI - Add event to Zod schema, filter dropdown, and form dialog - Implement conditional test panel UI for model response payload - Add translations (en/zh/vi) for new test panel fields - Updated beta description to reference the new event Co-Authored-By: Claude <noreply@anthropic.com> * feat(mcp): add MCP CRUD server exposing goclaw resources at /api/mcp/ with Bearer token auth and X-GoClaw-Tenant-Id header, default to master tenant * feat(mcp): add goclaw_skills_write_file tool to edit skill files on disk The CRUD MCP server's goclaw_skills_update only touched skill DB metadata, with no way to edit a skill's SKILL.md/file content on the filesystem. Extract the versioned write logic from the web UI's skill file editor (SkillsHandler.handleWriteFile) into skills.WriteVersionedFile so both surfaces share identical validation and versioning, and expose it as a new MCP tool. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Bruno Clermont <bruno.clermont@gmail.com> Co-authored-by: Claude <noreply@anthropic.com>
125 lines
4.1 KiB
Go
125 lines
4.1 KiB
Go
package mcp
|
|
|
|
import (
|
|
"context"
|
|
"crypto/rand"
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
"fmt"
|
|
"time"
|
|
|
|
"github.com/google/uuid"
|
|
|
|
mcpgo "github.com/mark3labs/mcp-go/mcp"
|
|
mcpserver "github.com/mark3labs/mcp-go/server"
|
|
|
|
"github.com/nextlevelbuilder/goclaw/internal/store"
|
|
)
|
|
|
|
const apiKeyRawBytes = 32
|
|
|
|
// registerAPIKeyCRUDTools registers the goclaw_api_keys_* MCP tools backed by
|
|
// store.APIKeyStore.
|
|
func registerAPIKeyCRUDTools(srv *mcpserver.MCPServer, apiKeys store.APIKeyStore) {
|
|
srv.AddTool(mcpgo.NewTool("goclaw_api_keys_list",
|
|
mcpgo.WithDescription("List API keys visible to the caller."),
|
|
mcpgo.WithString("owner_id", mcpgo.Description("Filter by owner user ID; empty lists all keys.")),
|
|
mcpgo.WithReadOnlyHintAnnotation(true),
|
|
), handleAPIKeysList(apiKeys))
|
|
|
|
srv.AddTool(mcpgo.NewTool("goclaw_api_keys_create",
|
|
mcpgo.WithDescription("Create a new API key. The raw key value is only returned once."),
|
|
mcpgo.WithString("name", mcpgo.Required(), mcpgo.Description("Descriptive name for the key.")),
|
|
mcpgo.WithArray("scopes", mcpgo.Required(), mcpgo.Description("Scopes granted to this key (e.g. [\"operator.admin\"]).")),
|
|
mcpgo.WithNumber("expires_in", mcpgo.Description("Expiry in seconds from now; omit for a non-expiring key.")),
|
|
mcpgo.WithString("owner_id", mcpgo.Description("User ID this key is bound to.")),
|
|
), handleAPIKeysCreate(apiKeys))
|
|
|
|
srv.AddTool(mcpgo.NewTool("goclaw_api_keys_revoke",
|
|
mcpgo.WithDescription("Revoke an API key."),
|
|
mcpgo.WithString("id", mcpgo.Required(), mcpgo.Description("API key UUID.")),
|
|
mcpgo.WithString("owner_id", mcpgo.Description("If set, also enforces owner_id match before revoking.")),
|
|
mcpgo.WithDestructiveHintAnnotation(true),
|
|
), handleAPIKeysRevoke(apiKeys))
|
|
}
|
|
|
|
func handleAPIKeysList(apiKeys store.APIKeyStore) mcpserver.ToolHandlerFunc {
|
|
return func(ctx context.Context, req mcpgo.CallToolRequest) (*mcpgo.CallToolResult, error) {
|
|
ownerID := req.GetString("owner_id", "")
|
|
list, err := apiKeys.List(ctx, ownerID)
|
|
if err != nil {
|
|
return toolError("api_keys.list", err)
|
|
}
|
|
return jsonToolResult(list)
|
|
}
|
|
}
|
|
|
|
func handleAPIKeysCreate(apiKeys store.APIKeyStore) mcpserver.ToolHandlerFunc {
|
|
return func(ctx context.Context, req mcpgo.CallToolRequest) (*mcpgo.CallToolResult, error) {
|
|
name, err := req.RequireString("name")
|
|
if err != nil {
|
|
return toolError("api_keys.create", err)
|
|
}
|
|
scopesRaw, err := req.RequireStringSlice("scopes")
|
|
if err != nil {
|
|
return toolError("api_keys.create", err)
|
|
}
|
|
|
|
rawKey := make([]byte, apiKeyRawBytes)
|
|
if _, err := rand.Read(rawKey); err != nil {
|
|
return toolError("api_keys.create", fmt.Errorf("generate key: %w", err))
|
|
}
|
|
rawKeyHex := hex.EncodeToString(rawKey)
|
|
hash := sha256.Sum256([]byte(rawKeyHex))
|
|
keyHash := hex.EncodeToString(hash[:])
|
|
|
|
var expiresAt *time.Time
|
|
if expiresIn := req.GetFloat("expires_in", 0); expiresIn > 0 {
|
|
t := time.Now().Add(time.Duration(expiresIn) * time.Second)
|
|
expiresAt = &t
|
|
}
|
|
|
|
data := &store.APIKeyData{
|
|
ID: store.GenNewID(),
|
|
Name: name,
|
|
Prefix: rawKeyHex[:apiKeyPrefixLen],
|
|
KeyHash: keyHash,
|
|
Scopes: scopesRaw,
|
|
OwnerID: req.GetString("owner_id", ""),
|
|
ExpiresAt: expiresAt,
|
|
}
|
|
if err := apiKeys.Create(ctx, data); err != nil {
|
|
return toolError("api_keys.create", err)
|
|
}
|
|
return jsonToolResult(map[string]any{
|
|
"id": data.ID,
|
|
"name": data.Name,
|
|
"prefix": data.Prefix,
|
|
"key": rawKeyHex,
|
|
"scopes": data.Scopes,
|
|
"expires_at": data.ExpiresAt,
|
|
"created_at": data.CreatedAt,
|
|
})
|
|
}
|
|
}
|
|
|
|
const apiKeyPrefixLen = 8
|
|
|
|
func handleAPIKeysRevoke(apiKeys store.APIKeyStore) mcpserver.ToolHandlerFunc {
|
|
return func(ctx context.Context, req mcpgo.CallToolRequest) (*mcpgo.CallToolResult, error) {
|
|
idStr, err := req.RequireString("id")
|
|
if err != nil {
|
|
return toolError("api_keys.revoke", err)
|
|
}
|
|
id, err := uuid.Parse(idStr)
|
|
if err != nil {
|
|
return toolError("api_keys.revoke", fmt.Errorf("invalid id: %w", err))
|
|
}
|
|
ownerID := req.GetString("owner_id", "")
|
|
if err := apiKeys.Revoke(ctx, id, ownerID); err != nil {
|
|
return toolError("api_keys.revoke", err)
|
|
}
|
|
return jsonToolResult(map[string]string{"status": "revoked"})
|
|
}
|
|
}
|