Allowlist.Check now takes ctx: when the caller authenticated with their own Gitea PAT (pass-through, v0.12.0), it skips the static GITEA_MCP_ALLOWED_OWNERS check entirely — Gitea's own permission model already gates that caller's access more precisely than a coarse owner-name list can. The static list still applies unchanged for the shared static-token/JWT path, where it's the only defense against the service token's blast radius. Mechanical: every tool call site already had ctx in scope, so this is a signature-only change at 41 call sites, no other tool behavior changes. Closes the "Deferred" item from #59. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
108 lines
2.9 KiB
Go
108 lines
2.9 KiB
Go
package tools
|
|
|
|
import (
|
|
"context"
|
|
"encoding/base64"
|
|
"encoding/json"
|
|
"fmt"
|
|
|
|
"git.d-ma.be/mathias/gitea-mcp/internal/allowlist"
|
|
"git.d-ma.be/mathias/gitea-mcp/internal/gitea"
|
|
"git.d-ma.be/mathias/gitea-mcp/internal/registry"
|
|
)
|
|
|
|
type FileWriteBranch struct {
|
|
c *gitea.Client
|
|
a *allowlist.Allowlist
|
|
}
|
|
|
|
func NewFileWriteBranch(c *gitea.Client, a *allowlist.Allowlist) *FileWriteBranch {
|
|
return &FileWriteBranch{c: c, a: a}
|
|
}
|
|
|
|
func (t *FileWriteBranch) Descriptor() registry.ToolDescriptor {
|
|
return registry.ToolDescriptor{
|
|
Name: "file_write_branch",
|
|
Description: "Create or update a file on the given branch. Pass an existing branch — e.g. the default branch `main` — to commit directly to it (trunk-based); a branch that doesn't exist yet is created from `base` first (PR flow). Pair with pr_create/pr_merge for the branch→PR→merge path.",
|
|
InputSchema: json.RawMessage(`{
|
|
"type":"object",
|
|
"properties":{
|
|
"owner":{"type":"string"},
|
|
"repo":{"type":"string"},
|
|
"path":{"type":"string"},
|
|
"content":{"type":"string"},
|
|
"branch":{"type":"string"},
|
|
"base":{"type":"string"},
|
|
"message":{"type":"string"},
|
|
"sha":{"type":"string"}
|
|
},
|
|
"required":["owner","repo","path","content","branch","message"]
|
|
}`),
|
|
}
|
|
}
|
|
|
|
type fileWriteBranchArgs struct {
|
|
Owner string `json:"owner"`
|
|
Repo string `json:"repo"`
|
|
Path string `json:"path"`
|
|
Content string `json:"content"`
|
|
Branch string `json:"branch"`
|
|
Base string `json:"base"`
|
|
Message string `json:"message"`
|
|
Sha string `json:"sha"`
|
|
}
|
|
|
|
func (t *FileWriteBranch) Call(ctx context.Context, raw json.RawMessage) (json.RawMessage, error) {
|
|
var args fileWriteBranchArgs
|
|
if err := parseArgs(raw, &args); err != nil {
|
|
return nil, err
|
|
}
|
|
if err := t.a.Check(ctx, args.Owner); err != nil {
|
|
return nil, err
|
|
}
|
|
if args.Branch == "" {
|
|
return nil, fmt.Errorf("branch is required: %w", gitea.ErrValidation)
|
|
}
|
|
if args.Message == "" {
|
|
return nil, fmt.Errorf("message is required: %w", gitea.ErrValidation)
|
|
}
|
|
|
|
// Resolve base default if branch needs to be created
|
|
exists, err := t.c.BranchExists(ctx, args.Owner, args.Repo, args.Branch)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
if !exists {
|
|
base := args.Base
|
|
if base == "" {
|
|
var err error
|
|
base, err = t.c.DefaultBranch(ctx, args.Owner, args.Repo)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
}
|
|
if err := t.c.CreateBranch(ctx, args.Owner, args.Repo, args.Branch, base); err != nil {
|
|
return nil, err
|
|
}
|
|
}
|
|
|
|
encoded := base64.StdEncoding.EncodeToString([]byte(args.Content))
|
|
result, err := t.c.UpsertFile(ctx, args.Owner, args.Repo, args.Path, gitea.UpsertFileArgs{
|
|
Branch: args.Branch,
|
|
Content: encoded,
|
|
Message: args.Message,
|
|
Sha: args.Sha,
|
|
})
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
return textOK(map[string]any{
|
|
"path": result.Content.Path,
|
|
"sha": result.Content.Sha,
|
|
"branch": args.Branch,
|
|
"commit_sha": result.Commit.Sha,
|
|
"html_url": result.Content.HTMLURL,
|
|
})
|
|
}
|