Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4ebea7d023 | ||
|
|
711dc46e5e | ||
|
|
039598855c | ||
|
|
d45ba712ce | ||
|
|
4d658004ae | ||
|
|
3329ff3088 | ||
|
|
2ebaee8d03 | ||
|
|
e30951ad72 | ||
|
|
e3cdd23260 |
+54
-8
@@ -27,6 +27,14 @@ and climate/sustainability tech.
|
||||
|
||||
These rules apply to every task across every project, regardless of harness.
|
||||
|
||||
0. **Pre-task ritual — before ANY implementation (non-negotiable).** Run this before writing a single line:
|
||||
- **Query the brain** (`brain_query`) for the domain + symptom. If the result changes your approach, surface it before acting. 5 seconds beats 5 hours.
|
||||
- **Load the relevant skill** — see trigger table in *Engineering Skills* below.
|
||||
- **Write the failing test first.** Name the test before the function. If the target is untestable (e.g. `main()` wiring), extract the logic into a testable function first. No implementation without a red test.
|
||||
- **State the observable success criterion** — what specific behavior, output, or passing test proves this is done?
|
||||
|
||||
**TDD is non-negotiable.** "Tests pass" is not proof of correctness — only proof the tests ran. Write tests that would catch the bug before writing code that fixes it.
|
||||
|
||||
1. **No assumptions.** Don't hide confusion — surface it. Surface tradeoffs explicitly.
|
||||
Think before coding; if the problem is unclear, ask or state assumptions before acting.
|
||||
2. **Minimum viable code.** Solve with the smallest change that works. Nothing
|
||||
@@ -49,6 +57,22 @@ These rules apply to every task across every project, regardless of harness.
|
||||
PR flow only when a human reviewer outside the project is required. Document
|
||||
the reason in PROJECT.md.
|
||||
|
||||
6. **Close the loop — every substantive task ends with the same ritual.** Shipping
|
||||
the code is not the end of the task; capturing it is. Run this unprompted:
|
||||
- **Tag + bump SemVer** on the change (annotated tag; minor for a feature or
|
||||
new/changed ADR, patch for a fix; docs in the same commit). Check the repo's
|
||||
actual last tag — stated versions in docs drift stale.
|
||||
- **Push** main and the tag (CI is the gate).
|
||||
- **Persist generalizable learnings to the brain** (`brain_write`, wing/hall) —
|
||||
the reusable patterns and the footguns that would bite anyone again, never
|
||||
project status. See *Knowledge base — when to write* below.
|
||||
- **File discovered-but-deferred work as tracker issues** on the project's own
|
||||
repo — token-budget gaps, recorded ADR limitations, v2 follow-ups. Don't let
|
||||
"out of scope, recorded" rot in a commit message; make it a ticket with a
|
||||
source pointer.
|
||||
- Surface the brain entries and issue numbers in the closing summary so the
|
||||
trail is auditable.
|
||||
|
||||
## Default stack
|
||||
|
||||
| Layer | Default | Fallback | Last resort |
|
||||
@@ -78,6 +102,26 @@ Exploratory: Rust, Zig — I'll tell you when I want these.
|
||||
- **Security**: no secrets in code, govulncheck before adding deps, SOPS for encrypted config
|
||||
- **Dependencies**: prefer stdlib. testify, slog, templ, sqlc, google.golang.org/adk (agent projects only) are pre-approved; anything else needs justification in the commit message
|
||||
|
||||
## Secret handling (every harness, every command)
|
||||
|
||||
Tool output is persisted: terminal → `~/.claude/projects` transcripts →
|
||||
claudewatcher → brain/wiki → gitea history. A secret printed once is
|
||||
searchable forever, and clearing it means rotating the key. So:
|
||||
|
||||
1. **Never print, echo, log, or transform a secret to inspect it.** No
|
||||
`base64`/`xxd`/`cat` of a key, and never pipe a secret through a transform
|
||||
to defeat `op run`'s output masking (it masks raw values; base64 hides them
|
||||
from the mask — that exact trick leaked a key on 2026-06-11).
|
||||
2. **Secrets stay in the subprocess.** Reference them only as env vars consumed
|
||||
*inside* `op run --env-file ~/.op-env -- <cmd>`. Never place a literal secret
|
||||
in a command's argv (it lands in the tool call and the transcript).
|
||||
3. **Existence check without revealing the value:** `[ -n "$X" ] && echo set` —
|
||||
never `${X:-...}` (returns the value when set) and never echo a substring of it.
|
||||
4. **Cross-host secrets:** run the secret-consuming command on the host that has
|
||||
the secret; do not forward a raw key over ssh argv/stdout.
|
||||
5. If a secret does leak into output, say so immediately and flag it for rotation —
|
||||
don't bury it.
|
||||
|
||||
## Infrastructure
|
||||
|
||||
Three machines on Tailscale:
|
||||
@@ -157,7 +201,7 @@ entries that age well are about *why*, *how to avoid*, and *what to do when*.
|
||||
| **Claude Code, Claude Desktop** | `brain_query` (BM25), `brain_answer` (LLM-synth + sources) MCP tools | `brain_write` MCP tool |
|
||||
| **Crush, Pi, Antigravity, other MCP-capable** | same MCP server: `ingestion-brain` (via the `mcp__*_brain__*` namespace once authenticated) | same |
|
||||
| **Anything HTTP-only (curl, scripts)** | `POST https://brain-mcp.d-ma.be/query` with `{"query":"..."}` (auth via `BRAIN_MCP_TOKEN`) | `POST .../write` with `{"content":"...","filename":"..."}` |
|
||||
| **Browser / human inspection** | `https://gitea.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
| **Browser / human inspection** | `https://git.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
|
||||
- **Scoping**: defaults to `public` collection; client projects filter to `{client}` + `public`.
|
||||
- **Routing**: brain_answer's LLM uses berget.ai as primary, iguana ollama as
|
||||
@@ -219,15 +263,17 @@ unconditionally on every host, every harness.
|
||||
|
||||
## Engineering Skills
|
||||
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load on demand via the index.
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load at task start — not "on demand" but on schedule, before writing code. See `~/dev/.skills/SKILLS_INDEX.md` for the full list.
|
||||
|
||||
See `~/dev/.skills/SKILLS_INDEX.md` for the full list with descriptions and "use when" triggers.
|
||||
**Skill trigger table — load before starting, not after getting stuck:**
|
||||
|
||||
Key skills:
|
||||
- **TDD**: always write tests first — load `tdd` skill
|
||||
- **Code Review**: load `code-review` skill before any review
|
||||
- **SOLID/Clean Code**: load `solid` or `clean-code` skill for design work
|
||||
- **Problem first**: load `problem-analysis` skill before coding non-trivial features
|
||||
| Task type | Load |
|
||||
|-----------|------|
|
||||
| Any feature or bug fix | `tdd` |
|
||||
| Refactor or design | `clean-code` or `solid` |
|
||||
| Debug | `problem-analysis` |
|
||||
| Review code or PRs | `code-review` |
|
||||
| Frame a problem before coding | `problem-analysis` |
|
||||
|
||||
---
|
||||
|
||||
|
||||
+1
-4
@@ -16,10 +16,7 @@
|
||||
},
|
||||
"infra": {
|
||||
"type": "http",
|
||||
"url": "https://infra-mcp.d-ma.be/mcp",
|
||||
"headers": {
|
||||
"Authorization": "Bearer ${INFRA_MCP_TOKEN}"
|
||||
}
|
||||
"url": "https://infra-mcp.d-ma.be/mcp"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -32,6 +32,14 @@ and climate/sustainability tech.
|
||||
|
||||
These rules apply to every task across every project, regardless of harness.
|
||||
|
||||
0. **Pre-task ritual — before ANY implementation (non-negotiable).** Run this before writing a single line:
|
||||
- **Query the brain** (`brain_query`) for the domain + symptom. If the result changes your approach, surface it before acting. 5 seconds beats 5 hours.
|
||||
- **Load the relevant skill** — see trigger table in *Engineering Skills* below.
|
||||
- **Write the failing test first.** Name the test before the function. If the target is untestable (e.g. `main()` wiring), extract the logic into a testable function first. No implementation without a red test.
|
||||
- **State the observable success criterion** — what specific behavior, output, or passing test proves this is done?
|
||||
|
||||
**TDD is non-negotiable.** "Tests pass" is not proof of correctness — only proof the tests ran. Write tests that would catch the bug before writing code that fixes it.
|
||||
|
||||
1. **No assumptions.** Don't hide confusion — surface it. Surface tradeoffs explicitly.
|
||||
Think before coding; if the problem is unclear, ask or state assumptions before acting.
|
||||
2. **Minimum viable code.** Solve with the smallest change that works. Nothing
|
||||
@@ -54,6 +62,22 @@ These rules apply to every task across every project, regardless of harness.
|
||||
PR flow only when a human reviewer outside the project is required. Document
|
||||
the reason in PROJECT.md.
|
||||
|
||||
6. **Close the loop — every substantive task ends with the same ritual.** Shipping
|
||||
the code is not the end of the task; capturing it is. Run this unprompted:
|
||||
- **Tag + bump SemVer** on the change (annotated tag; minor for a feature or
|
||||
new/changed ADR, patch for a fix; docs in the same commit). Check the repo's
|
||||
actual last tag — stated versions in docs drift stale.
|
||||
- **Push** main and the tag (CI is the gate).
|
||||
- **Persist generalizable learnings to the brain** (`brain_write`, wing/hall) —
|
||||
the reusable patterns and the footguns that would bite anyone again, never
|
||||
project status. See *Knowledge base — when to write* below.
|
||||
- **File discovered-but-deferred work as tracker issues** on the project's own
|
||||
repo — token-budget gaps, recorded ADR limitations, v2 follow-ups. Don't let
|
||||
"out of scope, recorded" rot in a commit message; make it a ticket with a
|
||||
source pointer.
|
||||
- Surface the brain entries and issue numbers in the closing summary so the
|
||||
trail is auditable.
|
||||
|
||||
## Default stack
|
||||
|
||||
| Layer | Default | Fallback | Last resort |
|
||||
@@ -83,6 +107,26 @@ Exploratory: Rust, Zig — I'll tell you when I want these.
|
||||
- **Security**: no secrets in code, govulncheck before adding deps, SOPS for encrypted config
|
||||
- **Dependencies**: prefer stdlib. testify, slog, templ, sqlc, google.golang.org/adk (agent projects only) are pre-approved; anything else needs justification in the commit message
|
||||
|
||||
## Secret handling (every harness, every command)
|
||||
|
||||
Tool output is persisted: terminal → `~/.claude/projects` transcripts →
|
||||
claudewatcher → brain/wiki → gitea history. A secret printed once is
|
||||
searchable forever, and clearing it means rotating the key. So:
|
||||
|
||||
1. **Never print, echo, log, or transform a secret to inspect it.** No
|
||||
`base64`/`xxd`/`cat` of a key, and never pipe a secret through a transform
|
||||
to defeat `op run`'s output masking (it masks raw values; base64 hides them
|
||||
from the mask — that exact trick leaked a key on 2026-06-11).
|
||||
2. **Secrets stay in the subprocess.** Reference them only as env vars consumed
|
||||
*inside* `op run --env-file ~/.op-env -- <cmd>`. Never place a literal secret
|
||||
in a command's argv (it lands in the tool call and the transcript).
|
||||
3. **Existence check without revealing the value:** `[ -n "$X" ] && echo set` —
|
||||
never `${X:-...}` (returns the value when set) and never echo a substring of it.
|
||||
4. **Cross-host secrets:** run the secret-consuming command on the host that has
|
||||
the secret; do not forward a raw key over ssh argv/stdout.
|
||||
5. If a secret does leak into output, say so immediately and flag it for rotation —
|
||||
don't bury it.
|
||||
|
||||
## Infrastructure
|
||||
|
||||
Three machines on Tailscale:
|
||||
@@ -162,7 +206,7 @@ entries that age well are about *why*, *how to avoid*, and *what to do when*.
|
||||
| **Claude Code, Claude Desktop** | `brain_query` (BM25), `brain_answer` (LLM-synth + sources) MCP tools | `brain_write` MCP tool |
|
||||
| **Crush, Pi, Antigravity, other MCP-capable** | same MCP server: `ingestion-brain` (via the `mcp__*_brain__*` namespace once authenticated) | same |
|
||||
| **Anything HTTP-only (curl, scripts)** | `POST https://brain-mcp.d-ma.be/query` with `{"query":"..."}` (auth via `BRAIN_MCP_TOKEN`) | `POST .../write` with `{"content":"...","filename":"..."}` |
|
||||
| **Browser / human inspection** | `https://gitea.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
| **Browser / human inspection** | `https://git.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
|
||||
- **Scoping**: defaults to `public` collection; client projects filter to `{client}` + `public`.
|
||||
- **Routing**: brain_answer's LLM uses berget.ai as primary, iguana ollama as
|
||||
@@ -224,15 +268,17 @@ unconditionally on every host, every harness.
|
||||
|
||||
## Engineering Skills
|
||||
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load on demand via the index.
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load at task start — not "on demand" but on schedule, before writing code. See `~/dev/.skills/SKILLS_INDEX.md` for the full list.
|
||||
|
||||
See `~/dev/.skills/SKILLS_INDEX.md` for the full list with descriptions and "use when" triggers.
|
||||
**Skill trigger table — load before starting, not after getting stuck:**
|
||||
|
||||
Key skills:
|
||||
- **TDD**: always write tests first — load `tdd` skill
|
||||
- **Code Review**: load `code-review` skill before any review
|
||||
- **SOLID/Clean Code**: load `solid` or `clean-code` skill for design work
|
||||
- **Problem first**: load `problem-analysis` skill before coding non-trivial features
|
||||
| Task type | Load |
|
||||
|-----------|------|
|
||||
| Any feature or bug fix | `tdd` |
|
||||
| Refactor or design | `clean-code` or `solid` |
|
||||
| Debug | `problem-analysis` |
|
||||
| Review code or PRs | `code-review` |
|
||||
| Frame a problem before coding | `problem-analysis` |
|
||||
|
||||
---
|
||||
|
||||
|
||||
+54
-8
@@ -30,6 +30,14 @@ and climate/sustainability tech.
|
||||
|
||||
These rules apply to every task across every project, regardless of harness.
|
||||
|
||||
0. **Pre-task ritual — before ANY implementation (non-negotiable).** Run this before writing a single line:
|
||||
- **Query the brain** (`brain_query`) for the domain + symptom. If the result changes your approach, surface it before acting. 5 seconds beats 5 hours.
|
||||
- **Load the relevant skill** — see trigger table in *Engineering Skills* below.
|
||||
- **Write the failing test first.** Name the test before the function. If the target is untestable (e.g. `main()` wiring), extract the logic into a testable function first. No implementation without a red test.
|
||||
- **State the observable success criterion** — what specific behavior, output, or passing test proves this is done?
|
||||
|
||||
**TDD is non-negotiable.** "Tests pass" is not proof of correctness — only proof the tests ran. Write tests that would catch the bug before writing code that fixes it.
|
||||
|
||||
1. **No assumptions.** Don't hide confusion — surface it. Surface tradeoffs explicitly.
|
||||
Think before coding; if the problem is unclear, ask or state assumptions before acting.
|
||||
2. **Minimum viable code.** Solve with the smallest change that works. Nothing
|
||||
@@ -52,6 +60,22 @@ These rules apply to every task across every project, regardless of harness.
|
||||
PR flow only when a human reviewer outside the project is required. Document
|
||||
the reason in PROJECT.md.
|
||||
|
||||
6. **Close the loop — every substantive task ends with the same ritual.** Shipping
|
||||
the code is not the end of the task; capturing it is. Run this unprompted:
|
||||
- **Tag + bump SemVer** on the change (annotated tag; minor for a feature or
|
||||
new/changed ADR, patch for a fix; docs in the same commit). Check the repo's
|
||||
actual last tag — stated versions in docs drift stale.
|
||||
- **Push** main and the tag (CI is the gate).
|
||||
- **Persist generalizable learnings to the brain** (`brain_write`, wing/hall) —
|
||||
the reusable patterns and the footguns that would bite anyone again, never
|
||||
project status. See *Knowledge base — when to write* below.
|
||||
- **File discovered-but-deferred work as tracker issues** on the project's own
|
||||
repo — token-budget gaps, recorded ADR limitations, v2 follow-ups. Don't let
|
||||
"out of scope, recorded" rot in a commit message; make it a ticket with a
|
||||
source pointer.
|
||||
- Surface the brain entries and issue numbers in the closing summary so the
|
||||
trail is auditable.
|
||||
|
||||
## Default stack
|
||||
|
||||
| Layer | Default | Fallback | Last resort |
|
||||
@@ -81,6 +105,26 @@ Exploratory: Rust, Zig — I'll tell you when I want these.
|
||||
- **Security**: no secrets in code, govulncheck before adding deps, SOPS for encrypted config
|
||||
- **Dependencies**: prefer stdlib. testify, slog, templ, sqlc, google.golang.org/adk (agent projects only) are pre-approved; anything else needs justification in the commit message
|
||||
|
||||
## Secret handling (every harness, every command)
|
||||
|
||||
Tool output is persisted: terminal → `~/.claude/projects` transcripts →
|
||||
claudewatcher → brain/wiki → gitea history. A secret printed once is
|
||||
searchable forever, and clearing it means rotating the key. So:
|
||||
|
||||
1. **Never print, echo, log, or transform a secret to inspect it.** No
|
||||
`base64`/`xxd`/`cat` of a key, and never pipe a secret through a transform
|
||||
to defeat `op run`'s output masking (it masks raw values; base64 hides them
|
||||
from the mask — that exact trick leaked a key on 2026-06-11).
|
||||
2. **Secrets stay in the subprocess.** Reference them only as env vars consumed
|
||||
*inside* `op run --env-file ~/.op-env -- <cmd>`. Never place a literal secret
|
||||
in a command's argv (it lands in the tool call and the transcript).
|
||||
3. **Existence check without revealing the value:** `[ -n "$X" ] && echo set` —
|
||||
never `${X:-...}` (returns the value when set) and never echo a substring of it.
|
||||
4. **Cross-host secrets:** run the secret-consuming command on the host that has
|
||||
the secret; do not forward a raw key over ssh argv/stdout.
|
||||
5. If a secret does leak into output, say so immediately and flag it for rotation —
|
||||
don't bury it.
|
||||
|
||||
## Infrastructure
|
||||
|
||||
Three machines on Tailscale:
|
||||
@@ -160,7 +204,7 @@ entries that age well are about *why*, *how to avoid*, and *what to do when*.
|
||||
| **Claude Code, Claude Desktop** | `brain_query` (BM25), `brain_answer` (LLM-synth + sources) MCP tools | `brain_write` MCP tool |
|
||||
| **Crush, Pi, Antigravity, other MCP-capable** | same MCP server: `ingestion-brain` (via the `mcp__*_brain__*` namespace once authenticated) | same |
|
||||
| **Anything HTTP-only (curl, scripts)** | `POST https://brain-mcp.d-ma.be/query` with `{"query":"..."}` (auth via `BRAIN_MCP_TOKEN`) | `POST .../write` with `{"content":"...","filename":"..."}` |
|
||||
| **Browser / human inspection** | `https://gitea.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
| **Browser / human inspection** | `https://git.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
|
||||
- **Scoping**: defaults to `public` collection; client projects filter to `{client}` + `public`.
|
||||
- **Routing**: brain_answer's LLM uses berget.ai as primary, iguana ollama as
|
||||
@@ -222,15 +266,17 @@ unconditionally on every host, every harness.
|
||||
|
||||
## Engineering Skills
|
||||
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load on demand via the index.
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load at task start — not "on demand" but on schedule, before writing code. See `~/dev/.skills/SKILLS_INDEX.md` for the full list.
|
||||
|
||||
See `~/dev/.skills/SKILLS_INDEX.md` for the full list with descriptions and "use when" triggers.
|
||||
**Skill trigger table — load before starting, not after getting stuck:**
|
||||
|
||||
Key skills:
|
||||
- **TDD**: always write tests first — load `tdd` skill
|
||||
- **Code Review**: load `code-review` skill before any review
|
||||
- **SOLID/Clean Code**: load `solid` or `clean-code` skill for design work
|
||||
- **Problem first**: load `problem-analysis` skill before coding non-trivial features
|
||||
| Task type | Load |
|
||||
|-----------|------|
|
||||
| Any feature or bug fix | `tdd` |
|
||||
| Refactor or design | `clean-code` or `solid` |
|
||||
| Debug | `problem-analysis` |
|
||||
| Review code or PRs | `code-review` |
|
||||
| Frame a problem before coding | `problem-analysis` |
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -27,6 +27,14 @@ and climate/sustainability tech.
|
||||
|
||||
These rules apply to every task across every project, regardless of harness.
|
||||
|
||||
0. **Pre-task ritual — before ANY implementation (non-negotiable).** Run this before writing a single line:
|
||||
- **Query the brain** (`brain_query`) for the domain + symptom. If the result changes your approach, surface it before acting. 5 seconds beats 5 hours.
|
||||
- **Load the relevant skill** — see trigger table in *Engineering Skills* below.
|
||||
- **Write the failing test first.** Name the test before the function. If the target is untestable (e.g. `main()` wiring), extract the logic into a testable function first. No implementation without a red test.
|
||||
- **State the observable success criterion** — what specific behavior, output, or passing test proves this is done?
|
||||
|
||||
**TDD is non-negotiable.** "Tests pass" is not proof of correctness — only proof the tests ran. Write tests that would catch the bug before writing code that fixes it.
|
||||
|
||||
1. **No assumptions.** Don't hide confusion — surface it. Surface tradeoffs explicitly.
|
||||
Think before coding; if the problem is unclear, ask or state assumptions before acting.
|
||||
2. **Minimum viable code.** Solve with the smallest change that works. Nothing
|
||||
@@ -49,6 +57,22 @@ These rules apply to every task across every project, regardless of harness.
|
||||
PR flow only when a human reviewer outside the project is required. Document
|
||||
the reason in PROJECT.md.
|
||||
|
||||
6. **Close the loop — every substantive task ends with the same ritual.** Shipping
|
||||
the code is not the end of the task; capturing it is. Run this unprompted:
|
||||
- **Tag + bump SemVer** on the change (annotated tag; minor for a feature or
|
||||
new/changed ADR, patch for a fix; docs in the same commit). Check the repo's
|
||||
actual last tag — stated versions in docs drift stale.
|
||||
- **Push** main and the tag (CI is the gate).
|
||||
- **Persist generalizable learnings to the brain** (`brain_write`, wing/hall) —
|
||||
the reusable patterns and the footguns that would bite anyone again, never
|
||||
project status. See *Knowledge base — when to write* below.
|
||||
- **File discovered-but-deferred work as tracker issues** on the project's own
|
||||
repo — token-budget gaps, recorded ADR limitations, v2 follow-ups. Don't let
|
||||
"out of scope, recorded" rot in a commit message; make it a ticket with a
|
||||
source pointer.
|
||||
- Surface the brain entries and issue numbers in the closing summary so the
|
||||
trail is auditable.
|
||||
|
||||
## Default stack
|
||||
|
||||
| Layer | Default | Fallback | Last resort |
|
||||
@@ -78,6 +102,26 @@ Exploratory: Rust, Zig — I'll tell you when I want these.
|
||||
- **Security**: no secrets in code, govulncheck before adding deps, SOPS for encrypted config
|
||||
- **Dependencies**: prefer stdlib. testify, slog, templ, sqlc, google.golang.org/adk (agent projects only) are pre-approved; anything else needs justification in the commit message
|
||||
|
||||
## Secret handling (every harness, every command)
|
||||
|
||||
Tool output is persisted: terminal → `~/.claude/projects` transcripts →
|
||||
claudewatcher → brain/wiki → gitea history. A secret printed once is
|
||||
searchable forever, and clearing it means rotating the key. So:
|
||||
|
||||
1. **Never print, echo, log, or transform a secret to inspect it.** No
|
||||
`base64`/`xxd`/`cat` of a key, and never pipe a secret through a transform
|
||||
to defeat `op run`'s output masking (it masks raw values; base64 hides them
|
||||
from the mask — that exact trick leaked a key on 2026-06-11).
|
||||
2. **Secrets stay in the subprocess.** Reference them only as env vars consumed
|
||||
*inside* `op run --env-file ~/.op-env -- <cmd>`. Never place a literal secret
|
||||
in a command's argv (it lands in the tool call and the transcript).
|
||||
3. **Existence check without revealing the value:** `[ -n "$X" ] && echo set` —
|
||||
never `${X:-...}` (returns the value when set) and never echo a substring of it.
|
||||
4. **Cross-host secrets:** run the secret-consuming command on the host that has
|
||||
the secret; do not forward a raw key over ssh argv/stdout.
|
||||
5. If a secret does leak into output, say so immediately and flag it for rotation —
|
||||
don't bury it.
|
||||
|
||||
## Infrastructure
|
||||
|
||||
Three machines on Tailscale:
|
||||
@@ -157,7 +201,7 @@ entries that age well are about *why*, *how to avoid*, and *what to do when*.
|
||||
| **Claude Code, Claude Desktop** | `brain_query` (BM25), `brain_answer` (LLM-synth + sources) MCP tools | `brain_write` MCP tool |
|
||||
| **Crush, Pi, Antigravity, other MCP-capable** | same MCP server: `ingestion-brain` (via the `mcp__*_brain__*` namespace once authenticated) | same |
|
||||
| **Anything HTTP-only (curl, scripts)** | `POST https://brain-mcp.d-ma.be/query` with `{"query":"..."}` (auth via `BRAIN_MCP_TOKEN`) | `POST .../write` with `{"content":"...","filename":"..."}` |
|
||||
| **Browser / human inspection** | `https://gitea.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
| **Browser / human inspection** | `https://git.d-ma.be/mathias/hyperguild` → `knowledge/` and `wiki/` markdown files |
|
||||
|
||||
- **Scoping**: defaults to `public` collection; client projects filter to `{client}` + `public`.
|
||||
- **Routing**: brain_answer's LLM uses berget.ai as primary, iguana ollama as
|
||||
@@ -219,15 +263,17 @@ unconditionally on every host, every harness.
|
||||
|
||||
## Engineering Skills
|
||||
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load on demand via the index.
|
||||
Shared engineering skills are available in `~/dev/.skills/`. Load at task start — not "on demand" but on schedule, before writing code. See `~/dev/.skills/SKILLS_INDEX.md` for the full list.
|
||||
|
||||
See `~/dev/.skills/SKILLS_INDEX.md` for the full list with descriptions and "use when" triggers.
|
||||
**Skill trigger table — load before starting, not after getting stuck:**
|
||||
|
||||
Key skills:
|
||||
- **TDD**: always write tests first — load `tdd` skill
|
||||
- **Code Review**: load `code-review` skill before any review
|
||||
- **SOLID/Clean Code**: load `solid` or `clean-code` skill for design work
|
||||
- **Problem first**: load `problem-analysis` skill before coding non-trivial features
|
||||
| Task type | Load |
|
||||
|-----------|------|
|
||||
| Any feature or bug fix | `tdd` |
|
||||
| Refactor or design | `clean-code` or `solid` |
|
||||
| Debug | `problem-analysis` |
|
||||
| Review code or PRs | `code-review` |
|
||||
| Frame a problem before coding | `problem-analysis` |
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@ import (
|
||||
"os"
|
||||
"strings"
|
||||
|
||||
chassisauth "gitea.d-ma.be/mathias/mcp-chassis/auth"
|
||||
chassisauth "git.d-ma.be/mathias/mcp-chassis/auth"
|
||||
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/allowlist"
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/auth"
|
||||
|
||||
@@ -3,13 +3,12 @@ module gitea.d-ma.be/mathias/gitea-mcp
|
||||
go 1.26.2
|
||||
|
||||
require (
|
||||
git.d-ma.be/mathias/mcp-chassis v0.2.0
|
||||
github.com/hashicorp/golang-lru/v2 v2.0.7
|
||||
github.com/lestrrat-go/jwx/v2 v2.1.6
|
||||
github.com/stretchr/testify v1.11.1
|
||||
)
|
||||
|
||||
require (
|
||||
gitea.d-ma.be/mathias/mcp-chassis v0.1.0 // indirect
|
||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
|
||||
github.com/goccy/go-json v0.10.3 // indirect
|
||||
@@ -17,6 +16,7 @@ require (
|
||||
github.com/lestrrat-go/httpcc v1.0.1 // indirect
|
||||
github.com/lestrrat-go/httprc v1.0.6 // indirect
|
||||
github.com/lestrrat-go/iter v1.0.2 // indirect
|
||||
github.com/lestrrat-go/jwx/v2 v2.1.6 // indirect
|
||||
github.com/lestrrat-go/option v1.0.1 // indirect
|
||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||
github.com/segmentio/asm v1.2.0 // indirect
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
gitea.d-ma.be/mathias/mcp-chassis v0.1.0 h1:8RXO34+n7Vu8HnUMagars6fc4oemqRpMu7MVtjaj4qY=
|
||||
gitea.d-ma.be/mathias/mcp-chassis v0.1.0/go.mod h1:ajbLlwr2L7FAN3TBU39KucZkKJM02wTbKbDKDEW2YvE=
|
||||
git.d-ma.be/mathias/mcp-chassis v0.2.0 h1:6fLmb7xqRa2nNVWsHaUbbfbArgDXJw/gDhb09clBIjo=
|
||||
git.d-ma.be/mathias/mcp-chassis v0.2.0/go.mod h1:Ks7EK2UnGAN0H3rJjKUxUagX8/ZBdtLrOlcUbv0RwH8=
|
||||
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
|
||||
@@ -6,7 +6,6 @@ import (
|
||||
"fmt"
|
||||
"net/url"
|
||||
"strconv"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// DispatchWorkflowArgs is the request body for a workflow_dispatch trigger.
|
||||
@@ -15,42 +14,26 @@ type DispatchWorkflowArgs struct {
|
||||
Inputs map[string]any `json:"inputs,omitempty"`
|
||||
}
|
||||
|
||||
// WorkflowRunTrigger holds the run ID extracted from the Location header.
|
||||
type WorkflowRunTrigger struct {
|
||||
RunID int64
|
||||
}
|
||||
|
||||
// DispatchWorkflow triggers a workflow_dispatch event and returns the new run ID.
|
||||
func (c *Client) DispatchWorkflow(ctx context.Context, owner, repo, workflow string, args DispatchWorkflowArgs) (*WorkflowRunTrigger, error) {
|
||||
// DispatchWorkflow triggers a workflow_dispatch event. Gitea returns 204 No
|
||||
// Content with NO Location header, so the response carries no run ID — callers
|
||||
// resolve the new run separately via ListWorkflowRuns. Returns nil on success.
|
||||
func (c *Client) DispatchWorkflow(ctx context.Context, owner, repo, workflow string, args DispatchWorkflowArgs) error {
|
||||
p := fmt.Sprintf("/api/v1/repos/%s/%s/actions/workflows/%s/dispatches", owner, repo, workflow)
|
||||
payload, err := json.Marshal(args)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
return err
|
||||
}
|
||||
resp, err := c.doRaw(ctx, "POST", p, payload)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
return err
|
||||
}
|
||||
if resp.Status != 204 {
|
||||
if mapErr := MapStatus(resp.Status, resp.Body); mapErr != nil {
|
||||
return nil, mapErr
|
||||
return mapErr
|
||||
}
|
||||
return nil, fmt.Errorf("unexpected status %d", resp.Status)
|
||||
return fmt.Errorf("unexpected status %d", resp.Status)
|
||||
}
|
||||
location := resp.Headers.Get("Location")
|
||||
if location == "" {
|
||||
return nil, fmt.Errorf("missing Location header in dispatch response")
|
||||
}
|
||||
// Location is e.g. "/api/v1/repos/o/r/actions/runs/123" — take the last segment.
|
||||
parts := strings.Split(strings.TrimRight(location, "/"), "/")
|
||||
if len(parts) == 0 {
|
||||
return nil, fmt.Errorf("malformed Location: %s", location)
|
||||
}
|
||||
runID, err := strconv.ParseInt(parts[len(parts)-1], 10, 64)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("parse run id from %q: %w", location, err)
|
||||
}
|
||||
return &WorkflowRunTrigger{RunID: runID}, nil
|
||||
return nil
|
||||
}
|
||||
|
||||
// WorkflowRun represents a Gitea Actions run.
|
||||
|
||||
@@ -14,6 +14,9 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
// Gitea's dispatch endpoint returns 204 No Content with NO Location header.
|
||||
// Dispatch must succeed and forward ref+inputs in the body; the run ID is
|
||||
// resolved separately by the tool via ListWorkflowRuns.
|
||||
func TestDispatchWorkflow(t *testing.T) {
|
||||
var gotBody []byte
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
@@ -22,18 +25,17 @@ func TestDispatchWorkflow(t *testing.T) {
|
||||
var err error
|
||||
gotBody, err = io.ReadAll(r.Body)
|
||||
assert.NoError(t, err)
|
||||
w.Header().Set("Location", "/api/v1/repos/o/r/actions/runs/789")
|
||||
// No Location header — matches real Gitea.
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
c := gitea.NewClient(srv.URL, "tok")
|
||||
result, err := c.DispatchWorkflow(context.Background(), "o", "r", "ci.yml", gitea.DispatchWorkflowArgs{
|
||||
err := c.DispatchWorkflow(context.Background(), "o", "r", "ci.yml", gitea.DispatchWorkflowArgs{
|
||||
Ref: "main",
|
||||
Inputs: map[string]any{"env": "prod"},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, int64(789), result.RunID)
|
||||
|
||||
var body map[string]any
|
||||
require.NoError(t, json.Unmarshal(gotBody, &body))
|
||||
@@ -43,19 +45,6 @@ func TestDispatchWorkflow(t *testing.T) {
|
||||
assert.Equal(t, "prod", inputs["env"])
|
||||
}
|
||||
|
||||
func TestDispatchWorkflowMissingLocation(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
// 204 but no Location header
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
c := gitea.NewClient(srv.URL, "tok")
|
||||
_, err := c.DispatchWorkflow(context.Background(), "o", "r", "ci.yml", gitea.DispatchWorkflowArgs{Ref: "main"})
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), "Location")
|
||||
}
|
||||
|
||||
func TestDispatchWorkflowError404(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
@@ -63,7 +52,7 @@ func TestDispatchWorkflowError404(t *testing.T) {
|
||||
defer srv.Close()
|
||||
|
||||
c := gitea.NewClient(srv.URL, "tok")
|
||||
_, err := c.DispatchWorkflow(context.Background(), "o", "r", "ci.yml", gitea.DispatchWorkflowArgs{Ref: "main"})
|
||||
err := c.DispatchWorkflow(context.Background(), "o", "r", "ci.yml", gitea.DispatchWorkflowArgs{Ref: "main"})
|
||||
require.Error(t, err)
|
||||
assert.True(t, errors.Is(err, gitea.ErrNotFound))
|
||||
}
|
||||
|
||||
@@ -2,10 +2,13 @@ package tools
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"regexp"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/allowlist"
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/gitea"
|
||||
@@ -14,22 +17,22 @@ import (
|
||||
|
||||
var nameRe = regexp.MustCompile(`^[a-z][a-z0-9-]{1,38}[a-z0-9]$`)
|
||||
|
||||
var substitutionFiles = []string{
|
||||
"go.mod",
|
||||
"Taskfile.yml",
|
||||
"Dockerfile",
|
||||
".gitea/workflows/cd.yml",
|
||||
"README.md",
|
||||
".context/PROJECT.md",
|
||||
}
|
||||
|
||||
func substitutions(owner, name string) map[string]string {
|
||||
return map[string]string{
|
||||
"__PROJECT_NAME__": name,
|
||||
"__MODULE_PATH__": "gitea.d-ma.be/" + owner + "/" + name,
|
||||
// git.d-ma.be is the canonical module host (the gitea.d-ma.be → git.d-ma.be
|
||||
// rename; a stale host breaks `go mod download` for downstream consumers).
|
||||
"__MODULE_PATH__": "git.d-ma.be/" + owner + "/" + name,
|
||||
}
|
||||
}
|
||||
|
||||
func applyReplacements(s string, repls map[string]string) string {
|
||||
for k, v := range repls {
|
||||
s = strings.ReplaceAll(s, k, v)
|
||||
}
|
||||
return s
|
||||
}
|
||||
|
||||
// CreateProjectFromTemplate is the exported type so tests can reference it.
|
||||
type CreateProjectFromTemplate struct {
|
||||
c *gitea.Client
|
||||
@@ -45,7 +48,7 @@ func NewCreateProjectFromTemplate(c *gitea.Client, a *allowlist.Allowlist, tmplO
|
||||
func (t *CreateProjectFromTemplate) Descriptor() registry.ToolDescriptor {
|
||||
return registry.ToolDescriptor{
|
||||
Name: "create_project_from_template",
|
||||
Description: "Create a new project repo from a template, applying placeholder substitutions to known files. Defaults to the server-configured template; pass template_name to override (e.g. template-go-agent).",
|
||||
Description: "Create a new project repo from a template. Best-effort substitution of placeholders (__PROJECT_NAME__, __MODULE_PATH__) in every file's content AND path (e.g. renaming cmd/__PROJECT_NAME__/): it completes only if the generated branch is promptly writable. If gitea's async generate is slow (infra#179) the repo is still created and partial_failure explains how to finalize locally (`hyperguild new-project`). Check files_substituted and partial_failure. Defaults to the server-configured template; pass template_name to override (e.g. template-go-agent). Pass dispatch_allow=true to also inject a .dispatch-allow file so the project is immediately dispatch-eligible (dispatch#3).",
|
||||
InputSchema: json.RawMessage(`{
|
||||
"type":"object",
|
||||
"properties":{
|
||||
@@ -53,7 +56,8 @@ func (t *CreateProjectFromTemplate) Descriptor() registry.ToolDescriptor {
|
||||
"name":{"type":"string","pattern":"^[a-z][a-z0-9-]{1,38}[a-z0-9]$"},
|
||||
"description":{"type":"string"},
|
||||
"private":{"type":"boolean"},
|
||||
"template_name":{"type":"string","description":"Template repo name to generate from. Defaults to the server-configured template."}
|
||||
"template_name":{"type":"string","description":"Template repo name to generate from. Defaults to the server-configured template."},
|
||||
"dispatch_allow":{"type":"boolean","description":"When true, inject a .dispatch-allow file so the new project is immediately opt-in for headless dispatch (dispatch#3). Default false."}
|
||||
},
|
||||
"required":["owner","name"]
|
||||
}`),
|
||||
@@ -61,13 +65,20 @@ func (t *CreateProjectFromTemplate) Descriptor() registry.ToolDescriptor {
|
||||
}
|
||||
|
||||
type createProjectArgs struct {
|
||||
Owner string `json:"owner"`
|
||||
Name string `json:"name"`
|
||||
Description string `json:"description"`
|
||||
Private bool `json:"private"`
|
||||
TemplateName string `json:"template_name"`
|
||||
Owner string `json:"owner"`
|
||||
Name string `json:"name"`
|
||||
Description string `json:"description"`
|
||||
Private bool `json:"private"`
|
||||
TemplateName string `json:"template_name"`
|
||||
DispatchAllow bool `json:"dispatch_allow"`
|
||||
}
|
||||
|
||||
// dispatchAllowContent is the body injected when dispatch_allow=true. Mirrors the
|
||||
// sandbox convention: presence of the file (not its content) marks the repo
|
||||
// dispatch-eligible; the comment exists only to explain that to a human reader.
|
||||
const dispatchAllowContent = "# Presence of this file marks this repo as opt-in for headless dispatch.\n" +
|
||||
"# See dispatch#3.\n"
|
||||
|
||||
type createProjectResult struct {
|
||||
FullName string `json:"full_name"`
|
||||
HTMLURL string `json:"html_url"`
|
||||
@@ -135,21 +146,167 @@ func (t *CreateProjectFromTemplate) Call(ctx context.Context, raw json.RawMessag
|
||||
DefaultBranch: newRepo.DefaultBranch,
|
||||
}
|
||||
|
||||
// Substitute placeholders in known files (best-effort).
|
||||
repls := substitutions(args.Owner, args.Name)
|
||||
// The /generate response often omits default_branch — resolve it explicitly,
|
||||
// otherwise every file read below hits an empty ref and nothing substitutes
|
||||
// (the silent-null bug: gitea-mcp#42).
|
||||
branch := newRepo.DefaultBranch
|
||||
for _, path := range substitutionFiles {
|
||||
if err := t.c.SubstituteFile(ctx, args.Owner, args.Name, branch, path, repls); err != nil {
|
||||
// Files that don't exist in this template are silently skipped.
|
||||
if errors.Is(err, gitea.ErrNotFound) {
|
||||
continue
|
||||
}
|
||||
// Any other error halts the substitution pass with partial_failure recorded.
|
||||
result.PartialFailure = fmt.Sprintf("%s: %v", path, err)
|
||||
if branch == "" {
|
||||
if r, gerr := t.c.GetRepo(ctx, args.Owner, args.Name); gerr == nil && r.DefaultBranch != "" {
|
||||
branch = r.DefaultBranch
|
||||
} else {
|
||||
branch = "main"
|
||||
}
|
||||
}
|
||||
result.DefaultBranch = branch
|
||||
|
||||
// Substitute across the WHOLE tree: content in every blob, plus a path rename
|
||||
// for any file whose path carries a placeholder (e.g. cmd/__PROJECT_NAME__/main.go).
|
||||
// A fixed known-files list can't rename directories or cover every templated
|
||||
// file, which is why the old scaffold didn't build.
|
||||
repls := substitutions(args.Owner, args.Name)
|
||||
tree, err := t.c.GetTree(ctx, args.Owner, args.Name, branch, true)
|
||||
if err != nil {
|
||||
result.PartialFailure = fmt.Sprintf("tree walk (%s@%s): %v", args.Name, branch, err)
|
||||
return textOK(result)
|
||||
}
|
||||
|
||||
for _, e := range tree.Tree {
|
||||
if e.Type != "blob" {
|
||||
continue
|
||||
}
|
||||
substituted, fail := t.substituteEntry(ctx, args.Owner, args.Name, branch, e.Path, repls)
|
||||
if fail != "" {
|
||||
result.PartialFailure = fail
|
||||
break
|
||||
}
|
||||
result.FilesSubstituted = append(result.FilesSubstituted, path)
|
||||
if substituted != "" {
|
||||
result.FilesSubstituted = append(result.FilesSubstituted, substituted)
|
||||
}
|
||||
}
|
||||
|
||||
// Opt the new project into headless dispatch if asked: presence of a
|
||||
// .dispatch-allow file on the default branch marks it dispatch-eligible
|
||||
// (dispatch#3). Ride the same upsertRetry path as substitution so it inherits
|
||||
// the infra#179 branch-readiness / partial-failure handling below. Skip if the
|
||||
// loop already stalled — a failed injection then degrades identically.
|
||||
if args.DispatchAllow && result.PartialFailure == "" {
|
||||
const dispatchAllowPath = ".dispatch-allow"
|
||||
if err := t.upsertRetry(ctx, args.Owner, args.Name, dispatchAllowPath, gitea.UpsertFileArgs{
|
||||
Branch: branch,
|
||||
Content: base64.StdEncoding.EncodeToString([]byte(dispatchAllowContent)),
|
||||
Message: "dispatch: mark project dispatch-eligible (dispatch#3)",
|
||||
}); err != nil {
|
||||
result.PartialFailure = fmt.Sprintf("write %s: %v", dispatchAllowPath, err)
|
||||
} else {
|
||||
result.FilesSubstituted = append(result.FilesSubstituted, dispatchAllowPath)
|
||||
}
|
||||
}
|
||||
|
||||
// If substitution stalled because the generated branch wasn't writable in time,
|
||||
// the repo IS created — say so clearly and point to the local finalize step,
|
||||
// rather than leaking the raw "branch does not exist" (infra#179: gitea's
|
||||
// template-generate is slow-async on this instance, so tool-side substitution
|
||||
// is best-effort).
|
||||
if strings.Contains(result.PartialFailure, "branch does not exist") ||
|
||||
strings.Contains(result.PartialFailure, "not found") {
|
||||
result.PartialFailure = fmt.Sprintf(
|
||||
"repo created, but its branch (%s) was not writable within %ds — gitea's "+
|
||||
"template-generate is slow-async on this instance (infra#179), so substitution "+
|
||||
"is incomplete (%d file(s) done). Finalize locally with `hyperguild new-project` "+
|
||||
"(clone + substitute, no API race). Underlying: %s",
|
||||
branch, substitutionBudget, len(result.FilesSubstituted), result.PartialFailure)
|
||||
}
|
||||
|
||||
// Fail loud: a scaffold that still holds placeholders does not build. Nothing
|
||||
// substituted (with no explicit failure) means the walk found no placeholders —
|
||||
// suspicious for a real template. Surface it instead of returning silent success.
|
||||
if result.PartialFailure == "" && len(result.FilesSubstituted) == 0 {
|
||||
result.PartialFailure = fmt.Sprintf("no placeholders substituted in %s@%s — verify the scaffold is not left templated", args.Name, branch)
|
||||
}
|
||||
|
||||
return textOK(result)
|
||||
}
|
||||
|
||||
// substitutionBudget bounds how long we retry the first write while the freshly
|
||||
// generated branch becomes writable. gitea's /generate returns (and serves reads)
|
||||
// before the branch ref is committed, so writes 404 "branch does not exist" for a
|
||||
// window. We keep the budget SHORT so the MCP call stays responsive: a healthy
|
||||
// gitea commits in ~1s and this catches it; a slow one (infra#179, observed >40s)
|
||||
// fails fast and we defer substitution with clear guidance rather than hang.
|
||||
const substitutionBudget = 5
|
||||
|
||||
// upsertRetry retries UpsertFile on the transient post-generate "branch does not
|
||||
// exist" not-found, up to substitutionBudget. The write itself is the readiness
|
||||
// probe — BranchExists reports the branch present before writes succeed.
|
||||
func (t *CreateProjectFromTemplate) upsertRetry(ctx context.Context, owner, name, path string, args gitea.UpsertFileArgs) error {
|
||||
var err error
|
||||
for i := 0; i < substitutionBudget; i++ {
|
||||
if _, err = t.c.UpsertFile(ctx, owner, name, path, args); err == nil {
|
||||
return nil
|
||||
}
|
||||
if !errors.Is(err, gitea.ErrNotFound) {
|
||||
return err
|
||||
}
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return err
|
||||
case <-time.After(time.Second):
|
||||
}
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
// substituteEntry substitutes placeholders in one blob. If the path carries a
|
||||
// placeholder it renames the file (write new + delete old); otherwise it rewrites
|
||||
// content in place when changed. Returns a human-readable description of what was
|
||||
// substituted ("" if nothing), and a non-empty partial-failure string on error.
|
||||
func (t *CreateProjectFromTemplate) substituteEntry(ctx context.Context, owner, name, branch, path string, repls map[string]string) (substituted, failure string) {
|
||||
newPath := applyReplacements(path, repls)
|
||||
|
||||
fc, err := t.c.GetFileContents(ctx, owner, name, path, branch)
|
||||
if err != nil {
|
||||
if errors.Is(err, gitea.ErrNotFound) {
|
||||
return "", "" // vanished between tree walk and read; skip
|
||||
}
|
||||
return "", fmt.Sprintf("read %s: %v", path, err)
|
||||
}
|
||||
decoded, err := base64.StdEncoding.DecodeString(fc.Content)
|
||||
if err != nil {
|
||||
return "", fmt.Sprintf("decode %s: %v", path, err)
|
||||
}
|
||||
newContent := applyReplacements(string(decoded), repls)
|
||||
renamed := newPath != path
|
||||
changed := newContent != string(decoded)
|
||||
if !renamed && !changed {
|
||||
return "", "" // nothing to do
|
||||
}
|
||||
enc := base64.StdEncoding.EncodeToString([]byte(newContent))
|
||||
|
||||
if renamed {
|
||||
if err := t.upsertRetry(ctx, owner, name, newPath, gitea.UpsertFileArgs{
|
||||
Branch: branch,
|
||||
Content: enc,
|
||||
Message: fmt.Sprintf("template: substitute + rename %s -> %s", path, newPath),
|
||||
}); err != nil {
|
||||
return "", fmt.Sprintf("write %s: %v", newPath, err)
|
||||
}
|
||||
if _, err := t.c.DeleteFile(ctx, owner, name, path, gitea.DeleteFileArgs{
|
||||
Branch: branch,
|
||||
Sha: fc.Sha,
|
||||
Message: fmt.Sprintf("template: drop placeholder path %s", path),
|
||||
}); err != nil {
|
||||
return "", fmt.Sprintf("delete %s: %v", path, err)
|
||||
}
|
||||
return path + " -> " + newPath, ""
|
||||
}
|
||||
|
||||
if err := t.upsertRetry(ctx, owner, name, path, gitea.UpsertFileArgs{
|
||||
Branch: branch,
|
||||
Content: enc,
|
||||
Message: "template: substitute placeholders",
|
||||
Sha: fc.Sha,
|
||||
}); err != nil {
|
||||
return "", fmt.Sprintf("write %s: %v", path, err)
|
||||
}
|
||||
return path, ""
|
||||
}
|
||||
|
||||
@@ -5,9 +5,11 @@ import (
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"sync"
|
||||
"testing"
|
||||
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/allowlist"
|
||||
@@ -17,306 +19,294 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
// substitutionFileList matches the tool's internal list — used to drive fake server routing.
|
||||
var substitutionFileList = []string{
|
||||
"go.mod",
|
||||
"Taskfile.yml",
|
||||
"Dockerfile",
|
||||
".gitea/workflows/cd.yml",
|
||||
"README.md",
|
||||
".context/PROJECT.md",
|
||||
}
|
||||
func encb64(s string) string { return base64.StdEncoding.EncodeToString([]byte(s)) }
|
||||
|
||||
// contentWithPlaceholder is a template file body that contains the placeholder.
|
||||
const contentWithPlaceholder = "# __PROJECT_NAME__\nmodule __MODULE_PATH__\n"
|
||||
|
||||
func encodedContent(s string) string {
|
||||
return base64.StdEncoding.EncodeToString([]byte(s))
|
||||
}
|
||||
|
||||
// fileContentsJSON returns a JSON FileContents object for the given path.
|
||||
func fileContentsJSON(path string) string {
|
||||
enc := encodedContent(contentWithPlaceholder)
|
||||
return fmt.Sprintf(`{"path":%q,"sha":"sha-%s","size":40,"content":%q,"encoding":"base64"}`,
|
||||
path, strings.ReplaceAll(path, "/", "-"), enc)
|
||||
}
|
||||
|
||||
// fileWriteResultJSON returns a minimal FileWriteResult JSON.
|
||||
func fileWriteResultJSON(path string) string {
|
||||
return fmt.Sprintf(`{"content":{"path":%q,"sha":"newsha","html_url":""},"commit":{"sha":"c","html_url":""}}`, path)
|
||||
}
|
||||
|
||||
// newTemplateRepoJSON returns a JSON Repo marked as template.
|
||||
func newTemplateRepoJSON(name string, isTemplate bool) string {
|
||||
return fmt.Sprintf(`{"name":%q,"full_name":"mathias/%s","default_branch":"main","description":"","private":false,"clone_url":"http://gitea.example.com/mathias/%s.git","html_url":"http://gitea.example.com/mathias/%s","template":%v}`,
|
||||
func templateRepoJSON(name string, isTemplate bool) string {
|
||||
return fmt.Sprintf(`{"name":%q,"full_name":"mathias/%s","default_branch":"main","clone_url":"http://gitea.example.com/mathias/%s.git","html_url":"http://gitea.example.com/mathias/%s","template":%v}`,
|
||||
name, name, name, name, isTemplate)
|
||||
}
|
||||
|
||||
// newGeneratedRepoJSON returns the JSON for the newly generated repo.
|
||||
func newGeneratedRepoJSON(name string) string {
|
||||
return fmt.Sprintf(`{"name":%q,"full_name":"mathias/%s","default_branch":"main","description":"","private":false,"clone_url":"http://gitea.example.com/mathias/%s.git","html_url":"http://gitea.example.com/mathias/%s","template":false}`,
|
||||
name, name, name, name)
|
||||
// fakeTemplateServer serves the whole create-from-template flow off an in-memory
|
||||
// file map, driving the tool's tree-walk. Records writes/deletes/put-bodies.
|
||||
type fakeTemplateServer struct {
|
||||
mu sync.Mutex
|
||||
files map[string]string // path -> raw (un-substituted) content
|
||||
genBranch string // default_branch returned by /generate ("" to force fallback)
|
||||
generated bool
|
||||
puts []string
|
||||
deletes []string
|
||||
putBodies map[string]string // path -> decoded written content
|
||||
repoGetsPost int // GET dest after generate (branch fallback)
|
||||
}
|
||||
|
||||
func newCreateProjectTool(srvURL string) *tools.CreateProjectFromTemplate {
|
||||
c := gitea.NewClient(srvURL, "tok")
|
||||
a := allowlist.New([]string{"mathias"})
|
||||
return tools.NewCreateProjectFromTemplate(c, a, "mathias", "template-go-web")
|
||||
func newFakeTemplateServer(files map[string]string, genBranch string) *fakeTemplateServer {
|
||||
return &fakeTemplateServer{files: files, genBranch: genBranch, putBodies: map[string]string{}}
|
||||
}
|
||||
|
||||
// TestCreateProjectHappyPath: all 6 files served and substituted.
|
||||
func TestCreateProjectHappyPath(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
func (f *fakeTemplateServer) handler(t *testing.T, tmpl, dest string) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
p := r.URL.Path
|
||||
|
||||
switch {
|
||||
// Template repo lookup
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/template-go-web":
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("template-go-web", true)))
|
||||
case r.Method == http.MethodGet && p == "/api/v1/repos/mathias/"+tmpl:
|
||||
_, _ = w.Write([]byte(templateRepoJSON(tmpl, true)))
|
||||
|
||||
// Destination repo lookup — 404 means it doesn't exist yet
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/new-svc":
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
_, _ = w.Write([]byte(`{"message":"not found"}`))
|
||||
case r.Method == http.MethodGet && p == "/api/v1/repos/mathias/"+dest:
|
||||
if !f.generated {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
_, _ = w.Write([]byte(`{"message":"not found"}`))
|
||||
return
|
||||
}
|
||||
f.repoGetsPost++
|
||||
_, _ = fmt.Fprintf(w, `{"name":%q,"full_name":"mathias/%s","default_branch":"main","clone_url":"c","html_url":"h","template":false}`, dest, dest)
|
||||
|
||||
// Generate
|
||||
case r.Method == http.MethodPost && r.URL.Path == "/api/v1/repos/mathias/template-go-web/generate":
|
||||
case r.Method == http.MethodPost && p == "/api/v1/repos/mathias/"+tmpl+"/generate":
|
||||
f.generated = true
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
_, _ = w.Write([]byte(newGeneratedRepoJSON("new-svc")))
|
||||
_, _ = fmt.Fprintf(w, `{"name":%q,"full_name":"mathias/%s","default_branch":%q,"clone_url":"http://gitea.example.com/mathias/%s.git","html_url":"http://gitea.example.com/mathias/%s","template":false}`,
|
||||
dest, dest, f.genBranch, dest, dest)
|
||||
|
||||
// File contents GET — handle all 6 substitution files
|
||||
case r.Method == http.MethodGet && strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/"):
|
||||
filePath := strings.TrimPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/")
|
||||
_, _ = w.Write([]byte(fileContentsJSON(filePath)))
|
||||
case r.Method == http.MethodGet && strings.HasPrefix(p, "/api/v1/repos/mathias/"+dest+"/git/trees/"):
|
||||
var entries []string
|
||||
for path := range f.files {
|
||||
entries = append(entries, fmt.Sprintf(`{"path":%q,"type":"blob","sha":"sha-%s"}`, path, strings.ReplaceAll(path, "/", "-")))
|
||||
}
|
||||
// include a tree (directory) entry to exercise the blob filter
|
||||
entries = append(entries, `{"path":"cmd","type":"tree","sha":"treesha"}`)
|
||||
_, _ = fmt.Fprintf(w, `{"sha":"root","tree":[%s],"truncated":false}`, strings.Join(entries, ","))
|
||||
|
||||
// File contents PUT — handle all 6 substitution files
|
||||
case r.Method == http.MethodPut && strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/"):
|
||||
filePath := strings.TrimPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/")
|
||||
case r.Method == http.MethodGet && strings.HasPrefix(p, "/api/v1/repos/mathias/"+dest+"/contents/"):
|
||||
path := strings.TrimPrefix(p, "/api/v1/repos/mathias/"+dest+"/contents/")
|
||||
body, ok := f.files[path]
|
||||
if !ok {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
_, _ = w.Write([]byte(`{"message":"not found"}`))
|
||||
return
|
||||
}
|
||||
_, _ = fmt.Fprintf(w, `{"path":%q,"sha":"sha-%s","size":1,"content":%q,"encoding":"base64"}`,
|
||||
path, strings.ReplaceAll(path, "/", "-"), encb64(body))
|
||||
|
||||
// POST = create (new/renamed file, no sha), PUT = update (existing, with sha).
|
||||
case (r.Method == http.MethodPost || r.Method == http.MethodPut) && strings.HasPrefix(p, "/api/v1/repos/mathias/"+dest+"/contents/"):
|
||||
path := strings.TrimPrefix(p, "/api/v1/repos/mathias/"+dest+"/contents/")
|
||||
raw, _ := io.ReadAll(r.Body)
|
||||
var args struct {
|
||||
Content string `json:"content"`
|
||||
}
|
||||
_ = json.Unmarshal(raw, &args)
|
||||
dec, _ := base64.StdEncoding.DecodeString(args.Content)
|
||||
f.puts = append(f.puts, path)
|
||||
f.putBodies[path] = string(dec)
|
||||
if r.Method == http.MethodPost {
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
} else {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
}
|
||||
_, _ = w.Write([]byte(`{"content":{"path":"x","sha":"n"},"commit":{"sha":"c"}}`))
|
||||
|
||||
case r.Method == http.MethodDelete && strings.HasPrefix(p, "/api/v1/repos/mathias/"+dest+"/contents/"):
|
||||
path := strings.TrimPrefix(p, "/api/v1/repos/mathias/"+dest+"/contents/")
|
||||
f.deletes = append(f.deletes, path)
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = w.Write([]byte(fileWriteResultJSON(filePath)))
|
||||
_, _ = w.Write([]byte(`{"content":null,"commit":{"sha":"c"}}`))
|
||||
|
||||
default:
|
||||
t.Errorf("unexpected request: %s %s", r.Method, r.URL.Path)
|
||||
t.Errorf("unexpected request: %s %s", r.Method, p)
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}))
|
||||
}
|
||||
}
|
||||
|
||||
func newTool(srvURL, tmpl string) *tools.CreateProjectFromTemplate {
|
||||
return tools.NewCreateProjectFromTemplate(
|
||||
gitea.NewClient(srvURL, "tok"), allowlist.New([]string{"mathias"}), "mathias", tmpl)
|
||||
}
|
||||
|
||||
func callTool(t *testing.T, srvURL, tmpl, argsJSON string) createOut {
|
||||
t.Helper()
|
||||
res, err := newTool(srvURL, tmpl).Call(context.Background(), json.RawMessage(argsJSON))
|
||||
require.NoError(t, err)
|
||||
var out createOut
|
||||
require.NoError(t, json.Unmarshal(res, &out))
|
||||
return out
|
||||
}
|
||||
|
||||
type createOut struct {
|
||||
FullName string `json:"full_name"`
|
||||
DefaultBranch string `json:"default_branch"`
|
||||
FilesSubstituted []string `json:"files_substituted"`
|
||||
PartialFailure string `json:"partial_failure,omitempty"`
|
||||
}
|
||||
|
||||
// Happy path: whole-tree substitution, content + path rename, correct module host.
|
||||
func TestCreateProject_TreeWalk_SubstitutesAndRenames(t *testing.T) {
|
||||
files := map[string]string{
|
||||
"go.mod": "module __MODULE_PATH__\n\ngo 1.26\n",
|
||||
"README.md": "# __PROJECT_NAME__\n",
|
||||
"cmd/__PROJECT_NAME__/main.go": "package main\nimport \"__MODULE_PATH__/pkg/litellm\"\nconst n = \"__PROJECT_NAME__\"\n",
|
||||
"pkg/litellm/x.go": "package litellm\n", // no placeholder → untouched
|
||||
}
|
||||
f := newFakeTemplateServer(files, "main")
|
||||
srv := httptest.NewServer(f.handler(t, "template-go-agent", "new-svc"))
|
||||
defer srv.Close()
|
||||
|
||||
tool := newCreateProjectTool(srv.URL)
|
||||
result, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"new-svc","description":"A new service"}`))
|
||||
require.NoError(t, err)
|
||||
out := callTool(t, srv.URL, "template-go-agent", `{"owner":"mathias","name":"new-svc"}`)
|
||||
|
||||
var out struct {
|
||||
FullName string `json:"full_name"`
|
||||
HTMLURL string `json:"html_url"`
|
||||
CloneURL string `json:"clone_url"`
|
||||
DefaultBranch string `json:"default_branch"`
|
||||
FilesSubstituted []string `json:"files_substituted"`
|
||||
PartialFailure string `json:"partial_failure,omitempty"`
|
||||
}
|
||||
require.NoError(t, json.Unmarshal(result, &out))
|
||||
|
||||
assert.Equal(t, "mathias/new-svc", out.FullName)
|
||||
assert.Equal(t, "http://gitea.example.com/mathias/new-svc", out.HTMLURL)
|
||||
assert.Equal(t, "main", out.DefaultBranch)
|
||||
assert.ElementsMatch(t, substitutionFileList, out.FilesSubstituted)
|
||||
assert.Empty(t, out.PartialFailure)
|
||||
|
||||
// content-substituted files present; untouched file absent
|
||||
assert.Contains(t, out.FilesSubstituted, "go.mod")
|
||||
assert.Contains(t, out.FilesSubstituted, "README.md")
|
||||
assert.NotContains(t, out.FilesSubstituted, "pkg/litellm/x.go")
|
||||
// path rename recorded as "old -> new"
|
||||
assert.Contains(t, out.FilesSubstituted, "cmd/__PROJECT_NAME__/main.go -> cmd/new-svc/main.go")
|
||||
|
||||
// module host substituted correctly (git.d-ma.be, not gitea.d-ma.be)
|
||||
assert.Equal(t, "module git.d-ma.be/mathias/new-svc\n\ngo 1.26\n", f.putBodies["go.mod"])
|
||||
// rename: new path written, old path deleted
|
||||
assert.Contains(t, f.puts, "cmd/new-svc/main.go")
|
||||
assert.Contains(t, f.deletes, "cmd/__PROJECT_NAME__/main.go")
|
||||
assert.Equal(t, "package main\nimport \"git.d-ma.be/mathias/new-svc/pkg/litellm\"\nconst n = \"new-svc\"\n",
|
||||
f.putBodies["cmd/new-svc/main.go"])
|
||||
// the untouched file was never written
|
||||
assert.NotContains(t, f.puts, "pkg/litellm/x.go")
|
||||
}
|
||||
|
||||
// The /generate response omits default_branch (the live gitea behavior the old
|
||||
// mock hid) → tool must re-fetch the repo and still substitute.
|
||||
func TestCreateProject_EmptyGenerateBranch_FallsBack(t *testing.T) {
|
||||
files := map[string]string{"go.mod": "module __MODULE_PATH__\n"}
|
||||
f := newFakeTemplateServer(files, "") // generate returns default_branch:""
|
||||
srv := httptest.NewServer(f.handler(t, "template-go-agent", "new-svc"))
|
||||
defer srv.Close()
|
||||
|
||||
out := callTool(t, srv.URL, "template-go-agent", `{"owner":"mathias","name":"new-svc"}`)
|
||||
|
||||
assert.Equal(t, "main", out.DefaultBranch, "must resolve branch via GetRepo fallback")
|
||||
assert.GreaterOrEqual(t, f.repoGetsPost, 1, "must re-fetch repo to resolve empty default_branch")
|
||||
assert.Contains(t, out.FilesSubstituted, "go.mod")
|
||||
assert.Equal(t, "module git.d-ma.be/mathias/new-svc\n", f.putBodies["go.mod"])
|
||||
assert.Empty(t, out.PartialFailure)
|
||||
}
|
||||
|
||||
// TestCreateProjectTemplateNameOverride (issue #24): per-call template_name overrides the
|
||||
// server-configured default, so the same binary can generate from template-go-web or
|
||||
// template-go-agent without restart.
|
||||
func TestCreateProjectTemplateNameOverride(t *testing.T) {
|
||||
var templateLookups, generateCalls []string
|
||||
// Fail loud: a template whose files carry no placeholders yields nothing
|
||||
// substituted — surface it rather than returning silent success.
|
||||
func TestCreateProject_NothingSubstituted_IsLoud(t *testing.T) {
|
||||
files := map[string]string{"README.md": "# static, no placeholders\n"}
|
||||
f := newFakeTemplateServer(files, "main")
|
||||
srv := httptest.NewServer(f.handler(t, "template-go-agent", "new-svc"))
|
||||
defer srv.Close()
|
||||
|
||||
out := callTool(t, srv.URL, "template-go-agent", `{"owner":"mathias","name":"new-svc"}`)
|
||||
assert.Empty(t, out.FilesSubstituted)
|
||||
assert.NotEmpty(t, out.PartialFailure, "nothing substituted must not be silent success")
|
||||
}
|
||||
|
||||
// Write failure mid-pass → partial_failure populated, no Go error.
|
||||
func TestCreateProject_WriteFailure_PartialFailure(t *testing.T) {
|
||||
files := map[string]string{"go.mod": "module __MODULE_PATH__\n"}
|
||||
f := newFakeTemplateServer(files, "main")
|
||||
base := f.handler(t, "template-go-agent", "new-svc")
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
switch {
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/template-go-agent":
|
||||
templateLookups = append(templateLookups, "template-go-agent")
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("template-go-agent", true)))
|
||||
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/template-go-web":
|
||||
templateLookups = append(templateLookups, "template-go-web")
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("template-go-web", true)))
|
||||
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/new-agent":
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
_, _ = w.Write([]byte(`{"message":"not found"}`))
|
||||
|
||||
case r.Method == http.MethodPost && strings.HasSuffix(r.URL.Path, "/generate"):
|
||||
generateCalls = append(generateCalls, r.URL.Path)
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
_, _ = w.Write([]byte(newGeneratedRepoJSON("new-agent")))
|
||||
|
||||
case r.Method == http.MethodGet && strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/new-agent/contents/"):
|
||||
filePath := strings.TrimPrefix(r.URL.Path, "/api/v1/repos/mathias/new-agent/contents/")
|
||||
_, _ = w.Write([]byte(fileContentsJSON(filePath)))
|
||||
|
||||
case r.Method == http.MethodPut && strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/new-agent/contents/"):
|
||||
filePath := strings.TrimPrefix(r.URL.Path, "/api/v1/repos/mathias/new-agent/contents/")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = w.Write([]byte(fileWriteResultJSON(filePath)))
|
||||
|
||||
default:
|
||||
t.Errorf("unexpected request: %s %s", r.Method, r.URL.Path)
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
if r.Method == http.MethodPut && strings.Contains(r.URL.Path, "/contents/go.mod") {
|
||||
w.WriteHeader(http.StatusInternalServerError)
|
||||
_, _ = w.Write([]byte(`{"message":"boom"}`))
|
||||
return
|
||||
}
|
||||
base(w, r)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
// Server is configured with template-go-web as the default; call overrides to template-go-agent.
|
||||
tool := newCreateProjectTool(srv.URL)
|
||||
_, err := tool.Call(context.Background(), json.RawMessage(
|
||||
`{"owner":"mathias","name":"new-agent","template_name":"template-go-agent"}`,
|
||||
))
|
||||
require.NoError(t, err)
|
||||
|
||||
assert.Equal(t, []string{"template-go-agent"}, templateLookups,
|
||||
"override must direct the template lookup, not the server default")
|
||||
require.Len(t, generateCalls, 1)
|
||||
assert.Equal(t, "/api/v1/repos/mathias/template-go-agent/generate", generateCalls[0],
|
||||
"override must direct the /generate call too")
|
||||
out := callTool(t, srv.URL, "template-go-agent", `{"owner":"mathias","name":"new-svc"}`)
|
||||
assert.NotEmpty(t, out.PartialFailure)
|
||||
assert.Contains(t, out.PartialFailure, "go.mod")
|
||||
}
|
||||
|
||||
// TestCreateProjectNameRegexFailure: invalid name returns ErrValidation without hitting network.
|
||||
func TestCreateProjectNameRegexFailure(t *testing.T) {
|
||||
tool := tools.NewCreateProjectFromTemplate(
|
||||
gitea.NewClient("http://unused", ""),
|
||||
allowlist.New([]string{"mathias"}),
|
||||
"mathias", "template-go-web",
|
||||
)
|
||||
_, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"INVALID_NAME"}`))
|
||||
// dispatch_allow injects a .dispatch-allow file (dispatch#3) only when true.
|
||||
func TestCreateProject_DispatchAllow(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
argsJSON string
|
||||
wantFile bool
|
||||
}{
|
||||
{"true injects .dispatch-allow", `{"owner":"mathias","name":"new-svc","dispatch_allow":true}`, true},
|
||||
{"false does not inject", `{"owner":"mathias","name":"new-svc","dispatch_allow":false}`, false},
|
||||
{"omitted does not inject", `{"owner":"mathias","name":"new-svc"}`, false},
|
||||
}
|
||||
for _, tc := range tests {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
files := map[string]string{"go.mod": "module __MODULE_PATH__\n"}
|
||||
f := newFakeTemplateServer(files, "main")
|
||||
srv := httptest.NewServer(f.handler(t, "template-go-agent", "new-svc"))
|
||||
defer srv.Close()
|
||||
|
||||
out := callTool(t, srv.URL, "template-go-agent", tc.argsJSON)
|
||||
require.Empty(t, out.PartialFailure)
|
||||
if tc.wantFile {
|
||||
assert.Contains(t, out.FilesSubstituted, ".dispatch-allow")
|
||||
assert.Contains(t, f.puts, ".dispatch-allow")
|
||||
assert.Contains(t, f.putBodies[".dispatch-allow"], "dispatch#3")
|
||||
} else {
|
||||
assert.NotContains(t, out.FilesSubstituted, ".dispatch-allow")
|
||||
assert.NotContains(t, f.puts, ".dispatch-allow")
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// ── guardrails unchanged by the rewrite ──────────────────────────────────────
|
||||
|
||||
func TestCreateProject_NameRegexFailure(t *testing.T) {
|
||||
_, err := tools.NewCreateProjectFromTemplate(
|
||||
gitea.NewClient("http://unused", ""), allowlist.New([]string{"mathias"}), "mathias", "template-go-agent",
|
||||
).Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"INVALID_NAME"}`))
|
||||
require.Error(t, err)
|
||||
assert.ErrorIs(t, err, gitea.ErrValidation)
|
||||
}
|
||||
|
||||
// TestCreateProjectAllowlistRejects: owner not in allowlist returns error.
|
||||
func TestCreateProjectAllowlistRejects(t *testing.T) {
|
||||
tool := tools.NewCreateProjectFromTemplate(
|
||||
gitea.NewClient("http://unused", ""),
|
||||
allowlist.New([]string{"mathias"}),
|
||||
"mathias", "template-go-web",
|
||||
)
|
||||
_, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"evil","name":"new-svc"}`))
|
||||
func TestCreateProject_AllowlistRejects(t *testing.T) {
|
||||
_, err := tools.NewCreateProjectFromTemplate(
|
||||
gitea.NewClient("http://unused", ""), allowlist.New([]string{"mathias"}), "mathias", "template-go-agent",
|
||||
).Call(context.Background(), json.RawMessage(`{"owner":"evil","name":"new-svc"}`))
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), "allowlist")
|
||||
}
|
||||
|
||||
// TestCreateProjectTemplateNotTemplate: template repo exists but is not marked as template.
|
||||
func TestCreateProjectTemplateNotTemplate(t *testing.T) {
|
||||
func TestCreateProject_NotTemplate(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
// Template lookup returns a non-template repo.
|
||||
if r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/template-go-web" {
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("template-go-web", false)))
|
||||
if r.URL.Path == "/api/v1/repos/mathias/template-go-agent" {
|
||||
_, _ = w.Write([]byte(templateRepoJSON("template-go-agent", false)))
|
||||
return
|
||||
}
|
||||
t.Errorf("unexpected request: %s %s", r.Method, r.URL.Path)
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
tool := newCreateProjectTool(srv.URL)
|
||||
_, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"new-svc"}`))
|
||||
_, err := newTool(srv.URL, "template-go-agent").Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"new-svc"}`))
|
||||
require.Error(t, err)
|
||||
assert.ErrorIs(t, err, gitea.ErrValidation)
|
||||
}
|
||||
|
||||
// TestCreateProjectDestinationExists: destination repo already exists.
|
||||
func TestCreateProjectDestinationExists(t *testing.T) {
|
||||
func TestCreateProject_DestinationExists(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
switch {
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/template-go-web":
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("template-go-web", true)))
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/new-svc":
|
||||
// Destination exists — return 200.
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("new-svc", false)))
|
||||
switch r.URL.Path {
|
||||
case "/api/v1/repos/mathias/template-go-agent":
|
||||
_, _ = w.Write([]byte(templateRepoJSON("template-go-agent", true)))
|
||||
case "/api/v1/repos/mathias/new-svc":
|
||||
_, _ = w.Write([]byte(templateRepoJSON("new-svc", false)))
|
||||
default:
|
||||
t.Errorf("unexpected request: %s %s", r.Method, r.URL.Path)
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
tool := newCreateProjectTool(srv.URL)
|
||||
_, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"new-svc"}`))
|
||||
_, err := newTool(srv.URL, "template-go-agent").Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"new-svc"}`))
|
||||
require.Error(t, err)
|
||||
assert.ErrorIs(t, err, gitea.ErrConflict)
|
||||
}
|
||||
|
||||
// TestCreateProjectMidPassSubstitutionFailure: the 4th file (.gitea/workflows/cd.yml) PUT fails;
|
||||
// the first 3 are substituted, partial_failure is populated, no Go error is returned.
|
||||
func TestCreateProjectMidPassSubstitutionFailure(t *testing.T) {
|
||||
// Files that should succeed (index 0-2 in substitutionFileList).
|
||||
successFiles := map[string]bool{
|
||||
"go.mod": true,
|
||||
"Taskfile.yml": true,
|
||||
"Dockerfile": true,
|
||||
}
|
||||
// The 4th file (index 3) is .gitea/workflows/cd.yml — its PUT returns 500.
|
||||
failFile := ".gitea/workflows/cd.yml"
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
switch {
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/template-go-web":
|
||||
_, _ = w.Write([]byte(newTemplateRepoJSON("template-go-web", true)))
|
||||
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/v1/repos/mathias/new-svc":
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
_, _ = w.Write([]byte(`{"message":"not found"}`))
|
||||
|
||||
case r.Method == http.MethodPost && r.URL.Path == "/api/v1/repos/mathias/template-go-web/generate":
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
_, _ = w.Write([]byte(newGeneratedRepoJSON("new-svc")))
|
||||
|
||||
case r.Method == http.MethodGet && strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/"):
|
||||
filePath := strings.TrimPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/")
|
||||
_, _ = w.Write([]byte(fileContentsJSON(filePath)))
|
||||
|
||||
case r.Method == http.MethodPut && strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/"):
|
||||
filePath := strings.TrimPrefix(r.URL.Path, "/api/v1/repos/mathias/new-svc/contents/")
|
||||
if filePath == failFile {
|
||||
// Simulate upstream 500.
|
||||
w.WriteHeader(http.StatusInternalServerError)
|
||||
_, _ = w.Write([]byte(`{"message":"internal server error"}`))
|
||||
return
|
||||
}
|
||||
if !successFiles[filePath] {
|
||||
t.Errorf("unexpected PUT for file: %s", filePath)
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = w.Write([]byte(fileWriteResultJSON(filePath)))
|
||||
|
||||
default:
|
||||
t.Errorf("unexpected request: %s %s", r.Method, r.URL.Path)
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
tool := newCreateProjectTool(srv.URL)
|
||||
result, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"new-svc"}`))
|
||||
// Best-effort: no Go error returned, partial state in result.
|
||||
require.NoError(t, err)
|
||||
|
||||
var out struct {
|
||||
FullName string `json:"full_name"`
|
||||
FilesSubstituted []string `json:"files_substituted"`
|
||||
PartialFailure string `json:"partial_failure,omitempty"`
|
||||
}
|
||||
require.NoError(t, json.Unmarshal(result, &out))
|
||||
|
||||
// First 3 files should be in FilesSubstituted.
|
||||
assert.Len(t, out.FilesSubstituted, 3)
|
||||
assert.Contains(t, out.FilesSubstituted, "go.mod")
|
||||
assert.Contains(t, out.FilesSubstituted, "Taskfile.yml")
|
||||
assert.Contains(t, out.FilesSubstituted, "Dockerfile")
|
||||
assert.NotContains(t, out.FilesSubstituted, failFile)
|
||||
|
||||
// partial_failure should be non-empty.
|
||||
assert.NotEmpty(t, out.PartialFailure, "partial_failure should be populated on mid-pass failure")
|
||||
}
|
||||
|
||||
@@ -4,12 +4,22 @@ import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/allowlist"
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/gitea"
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/registry"
|
||||
)
|
||||
|
||||
// dispatchResolveBudget bounds how many times we poll for the dispatched run to
|
||||
// appear, and dispatchResolvePoll is the gap between polls. Gitea returns 204
|
||||
// with no run ID, so we list workflow_dispatch runs and take the newest above
|
||||
// the pre-dispatch baseline; it may register a beat after the 204.
|
||||
const (
|
||||
dispatchResolveBudget = 5
|
||||
dispatchResolvePoll = time.Second
|
||||
)
|
||||
|
||||
// WorkflowRunTrigger triggers a Gitea Actions workflow_dispatch run.
|
||||
type WorkflowRunTrigger struct {
|
||||
c *gitea.Client
|
||||
@@ -68,17 +78,82 @@ func (t *WorkflowRunTrigger) Call(ctx context.Context, raw json.RawMessage) (jso
|
||||
}
|
||||
}
|
||||
|
||||
result, err := t.c.DispatchWorkflow(ctx, args.Owner, args.Name, args.Workflow, gitea.DispatchWorkflowArgs{
|
||||
// Snapshot the newest existing workflow_dispatch run BEFORE dispatching, so we
|
||||
// can tell our fresh run apart from a prior one (Gitea's 204 carries no run ID).
|
||||
baseline := t.newestDispatchRunID(ctx, args.Owner, args.Name, args.Workflow, ref)
|
||||
|
||||
if err := t.c.DispatchWorkflow(ctx, args.Owner, args.Name, args.Workflow, gitea.DispatchWorkflowArgs{
|
||||
Ref: ref,
|
||||
Inputs: args.Inputs,
|
||||
})
|
||||
if err != nil {
|
||||
}); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
htmlURL := fmt.Sprintf("%s/%s/%s/actions/runs/%d", t.baseURL, args.Owner, args.Name, result.RunID)
|
||||
// Resolve the new run by listing workflow_dispatch runs and taking the newest
|
||||
// one whose ID exceeds the baseline. Poll briefly: the run can register a beat
|
||||
// after the 204.
|
||||
var run *gitea.WorkflowRun
|
||||
for i := 0; i < dispatchResolveBudget; i++ {
|
||||
if i > 0 {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return nil, ctx.Err()
|
||||
case <-time.After(dispatchResolvePoll):
|
||||
}
|
||||
}
|
||||
if r := t.newestDispatchRun(ctx, args.Owner, args.Name, args.Workflow, ref); r != nil && r.ID > baseline {
|
||||
run = r
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
// Dispatch succeeded (204). If the run has not surfaced yet, say so honestly
|
||||
// rather than failing — the workflow IS firing; the caller can list runs.
|
||||
if run == nil {
|
||||
return textOK(map[string]any{
|
||||
"dispatched": true,
|
||||
"note": "dispatch accepted but the run did not register within the resolve window; " +
|
||||
"list recent workflow_dispatch runs to find it",
|
||||
})
|
||||
}
|
||||
|
||||
htmlURL := run.HTMLURL
|
||||
if htmlURL == "" {
|
||||
htmlURL = fmt.Sprintf("%s/%s/%s/actions/runs/%d", t.baseURL, args.Owner, args.Name, run.ID)
|
||||
}
|
||||
return textOK(map[string]any{
|
||||
"run_id": result.RunID,
|
||||
"html_url": htmlURL,
|
||||
"dispatched": true,
|
||||
"run_id": run.ID,
|
||||
"html_url": htmlURL,
|
||||
})
|
||||
}
|
||||
|
||||
// newestDispatchRun returns the most recent workflow_dispatch run for the given
|
||||
// workflow and ref, or nil if none / on listing error (best-effort resolution).
|
||||
func (t *WorkflowRunTrigger) newestDispatchRun(ctx context.Context, owner, name, workflow, ref string) *gitea.WorkflowRun {
|
||||
resp, err := t.c.ListWorkflowRuns(ctx, owner, name, gitea.ListWorkflowRunsArgs{
|
||||
Event: "workflow_dispatch",
|
||||
Workflow: workflow,
|
||||
Branch: ref,
|
||||
Limit: 20,
|
||||
})
|
||||
if err != nil || resp == nil {
|
||||
return nil
|
||||
}
|
||||
var newest *gitea.WorkflowRun
|
||||
for i := range resp.WorkflowRuns {
|
||||
r := &resp.WorkflowRuns[i]
|
||||
if newest == nil || r.ID > newest.ID {
|
||||
newest = r
|
||||
}
|
||||
}
|
||||
return newest
|
||||
}
|
||||
|
||||
// newestDispatchRunID is newestDispatchRun's ID, or 0 if none.
|
||||
func (t *WorkflowRunTrigger) newestDispatchRunID(ctx context.Context, owner, name, workflow, ref string) int64 {
|
||||
if r := t.newestDispatchRun(ctx, owner, name, workflow, ref); r != nil {
|
||||
return r.ID
|
||||
}
|
||||
return 0
|
||||
}
|
||||
|
||||
@@ -3,8 +3,10 @@ package tools_test
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"gitea.d-ma.be/mathias/gitea-mcp/internal/allowlist"
|
||||
@@ -14,10 +16,67 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
func TestWorkflowRunTriggerSuccess(t *testing.T) {
|
||||
// Fake server handles both the repo endpoint (default_branch) and the dispatch endpoint.
|
||||
// runsListJSON is a workflow_runs listing body with a single run of the given id.
|
||||
func runsListJSON(id int) string {
|
||||
return `{"total_count":1,"workflow_runs":[{"id":` +
|
||||
fmtInt(id) +
|
||||
`,"status":"queued","event":"workflow_dispatch","html_url":"http://gitea.example/mathias/myrepo/actions/runs/` +
|
||||
fmtInt(id) + `"}]}`
|
||||
}
|
||||
|
||||
func fmtInt(i int) string { b, _ := json.Marshal(i); return string(b) }
|
||||
|
||||
// The dispatch endpoint returns 204 with NO Location header (real Gitea). The
|
||||
// tool must treat that as success, forward inputs, and resolve the new run by
|
||||
// listing workflow_dispatch runs and picking the newest one above the
|
||||
// pre-dispatch baseline.
|
||||
func TestWorkflowRunTriggerResolvesRunViaListing(t *testing.T) {
|
||||
dispatched := false
|
||||
var gotBody []byte
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
switch {
|
||||
case r.URL.Path == "/api/v1/repos/mathias/myrepo/actions/workflows/ci.yml/dispatches" && r.Method == http.MethodPost:
|
||||
gotBody, _ = io.ReadAll(r.Body)
|
||||
dispatched = true
|
||||
w.WriteHeader(http.StatusNoContent) // no Location header
|
||||
case strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/myrepo/actions/runs"):
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
if !dispatched {
|
||||
_, _ = w.Write([]byte(`{"total_count":0,"workflow_runs":[]}`)) // baseline: none yet
|
||||
return
|
||||
}
|
||||
_, _ = w.Write([]byte(runsListJSON(100)))
|
||||
default:
|
||||
http.NotFound(w, r)
|
||||
}
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
tool := tools.NewWorkflowRunTrigger(gitea.NewClient(srv.URL, "tok"), allowlist.New([]string{"mathias"}), srv.URL)
|
||||
out, err := tool.Call(context.Background(), json.RawMessage(
|
||||
`{"owner":"mathias","name":"myrepo","workflow":"ci.yml","ref":"main","inputs":{"issue_number":"36","harness":"agentsquad"}}`))
|
||||
require.NoError(t, err)
|
||||
assert.True(t, dispatched, "expected POST dispatch")
|
||||
|
||||
// inputs forwarded to the dispatch body
|
||||
var body map[string]any
|
||||
require.NoError(t, json.Unmarshal(gotBody, &body))
|
||||
assert.Equal(t, "main", body["ref"])
|
||||
inputs, ok := body["inputs"].(map[string]any)
|
||||
require.True(t, ok, "inputs must be present in dispatch body")
|
||||
assert.Equal(t, "36", inputs["issue_number"])
|
||||
assert.Equal(t, "agentsquad", inputs["harness"])
|
||||
|
||||
// run id resolved via listing (not a Location header)
|
||||
var result map[string]any
|
||||
require.NoError(t, json.Unmarshal(out, &result))
|
||||
assert.Equal(t, float64(100), result["run_id"])
|
||||
assert.Contains(t, result["html_url"], "/actions/runs/100")
|
||||
}
|
||||
|
||||
func TestWorkflowRunTriggerDefaultBranch(t *testing.T) {
|
||||
repoHit := false
|
||||
dispatchHit := false
|
||||
dispatched := false
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
switch {
|
||||
case r.URL.Path == "/api/v1/repos/mathias/myrepo" && r.Method == http.MethodGet:
|
||||
@@ -25,9 +84,15 @@ func TestWorkflowRunTriggerSuccess(t *testing.T) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = w.Write([]byte(`{"name":"myrepo","full_name":"mathias/myrepo","default_branch":"main"}`))
|
||||
case r.URL.Path == "/api/v1/repos/mathias/myrepo/actions/workflows/ci.yml/dispatches" && r.Method == http.MethodPost:
|
||||
dispatchHit = true
|
||||
w.Header().Set("Location", "/api/v1/repos/mathias/myrepo/actions/runs/42")
|
||||
dispatched = true
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
case strings.HasPrefix(r.URL.Path, "/api/v1/repos/mathias/myrepo/actions/runs"):
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
if !dispatched {
|
||||
_, _ = w.Write([]byte(`{"total_count":0,"workflow_runs":[]}`))
|
||||
return
|
||||
}
|
||||
_, _ = w.Write([]byte(runsListJSON(55)))
|
||||
default:
|
||||
http.NotFound(w, r)
|
||||
}
|
||||
@@ -38,37 +103,10 @@ func TestWorkflowRunTriggerSuccess(t *testing.T) {
|
||||
out, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"myrepo","workflow":"ci.yml"}`))
|
||||
require.NoError(t, err)
|
||||
assert.True(t, repoHit, "expected GET /repo for default branch")
|
||||
assert.True(t, dispatchHit, "expected POST dispatch")
|
||||
|
||||
var result map[string]any
|
||||
require.NoError(t, json.Unmarshal(out, &result))
|
||||
assert.Equal(t, float64(42), result["run_id"])
|
||||
assert.Contains(t, result["html_url"], "/mathias/myrepo/actions/runs/42")
|
||||
}
|
||||
|
||||
func TestWorkflowRunTriggerExplicitRef(t *testing.T) {
|
||||
repoHit := false
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if r.URL.Path == "/api/v1/repos/mathias/myrepo" {
|
||||
repoHit = true
|
||||
}
|
||||
if r.URL.Path == "/api/v1/repos/mathias/myrepo/actions/workflows/ci.yml/dispatches" {
|
||||
w.Header().Set("Location", "/api/v1/repos/mathias/myrepo/actions/runs/99")
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
return
|
||||
}
|
||||
http.NotFound(w, r)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
tool := tools.NewWorkflowRunTrigger(gitea.NewClient(srv.URL, "tok"), allowlist.New([]string{"mathias"}), srv.URL)
|
||||
out, err := tool.Call(context.Background(), json.RawMessage(`{"owner":"mathias","name":"myrepo","workflow":"ci.yml","ref":"develop"}`))
|
||||
require.NoError(t, err)
|
||||
assert.False(t, repoHit, "should not call GET /repo when ref is provided")
|
||||
|
||||
var result map[string]any
|
||||
require.NoError(t, json.Unmarshal(out, &result))
|
||||
assert.Equal(t, float64(99), result["run_id"])
|
||||
assert.Equal(t, float64(55), result["run_id"])
|
||||
}
|
||||
|
||||
func TestWorkflowRunTriggerAllowlistRejects(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user