feat(mcp): connector marketplace + split the Connectors surface (§7/§14/§15)

Fills a gap the blueprint names: the admin had to hand-author every
`mcp_catalog` entry. A remote feed of vetted connectors now proposes them
and the admin installs — the feed is *consultative*, so §14's risk axis is
untouched and the trust anchor stays on the box.

Marketplace client (`src/frontend/api/marketplace.rs`):
- Fetches the feed server-side (it sends no CORS headers) and caches it;
  icons are proxied for the same reason.
- Verifies every declared SHA-256 before writing, fail-closed and
  all-or-nothing. Feed-supplied paths are refused if they escape
  `./scripts/<id>/`. Importing an `mcp_local` entry still demands the
  admin-only `mcp.register_local_script`.
- Translates the feed's vocabulary into Skald's: `user`→`per_user`,
  `mcp_local`→`local_script`. Scope is read, never inferred from transport
  (a remote connector can be per-user — that is what `mcp.register_remote`
  is for), and an unreadable `type` fails closed to the answer needing more
  authority. The feed's `llm_short_description` maps to `description`, the
  column `render_mcp_list` puts in front of the LLM for `activate_tools()`.
- Feed URL is config (`marketplace.url`), not a constant: an on-premise
  product must not hard-require reaching one vendor's host.

Two silent failures found while wiring it:
- `transport_of` maps anything unknown to Stdio, so the feed's
  `streamable-http` would have tried to spawn a command. Normalised on import.
- Some servers want their key as a query param, not a bearer header, and say
  so with a `{key}` placeholder. Substituted at connect time in
  `global_row_spec`/`user_row_spec` — never at rest, so the key stays in its
  own column and the stored URL stays a template.

Pages, split by the question each answers:
- Connectors — what runs (`UserMcpView` = global ∪ per-user) and what I can
  add. Same page for everyone; the admin just has more verbs. One Available
  list with the verb per row: `per_user`→Activate, `global`→Enable globally.
  Enabling a global is the admin's counterpart to activating a per-user one,
  so the catalog picker dropdown is gone — the entry comes from the row.
- Connector Catalog (admin) — what this box offers. One `Add connector`
  with two sources: marketplace first (vetted, hashed), manual second
  (unvetted by nature) — the order mirrors the trust model.
- Marketplace (admin) — reached from the catalog, not the sidebar: it is a
  destination of an action, not a place.

`available()` no longer returns `McpGlobalServerRow`: that row carries
`api_key` and this view now reaches every logged-in user. A slim `GlobalView`
crosses instead, and an admin sees every global (with `can_use` marking their
own) so one enabled for someone else stays manageable.

Also fixes `connectors-page` having no CSS rule at all — every sibling page
has one, so it never got `flex: 1` and left an empty column beside it.
This commit is contained in:
2026-07-16 18:52:59 +01:00
parent 6d299472e3
commit bcd8f7b5c0
19 changed files with 2119 additions and 235 deletions
+26 -4
View File
@@ -393,9 +393,30 @@ fn transport_of(s: &str) -> McpTransport {
}
}
/// Some remote MCP servers take their key as a **query parameter** rather than the
/// `Authorization: Bearer` header this client sends by default (Tavily wants
/// `?tavilyApiKey=…`). Those declare a `{key}` placeholder in their URL, which is
/// substituted here — at connect time, in memory.
///
/// Doing it here rather than at write time keeps the key in its own column (where
/// it is redacted and, for a per-user connector, encrypted with the rest of
/// `{userid}.db`) instead of baking a live secret into a stored URL. Once
/// substituted, the key is cleared so it is not also sent as a bearer header the
/// server never asked for.
fn apply_key_placeholder(
url: Option<String>,
api_key: Option<String>,
) -> (Option<String>, Option<String>) {
match (url, api_key) {
(Some(u), Some(k)) if u.contains("{key}") => (Some(u.replace("{key}", &k)), None),
(u, k) => (u, k),
}
}
/// Builds a spec for a globally-active connector — host transport (`launch_in`
/// = None), so it runs in the Skald process, not in any container (§7).
pub fn global_row_spec(row: &crate::db::mcp_global_servers::McpGlobalServerRow) -> McpServerSpec {
let (url, api_key) = apply_key_placeholder(row.url.clone(), row.api_key.clone());
McpServerSpec {
config: McpServerConfig {
name: row.name.clone(),
@@ -403,8 +424,8 @@ pub fn global_row_spec(row: &crate::db::mcp_global_servers::McpGlobalServerRow)
command: row.command.clone(),
args: Some(row.args()).filter(|v| !v.is_empty()),
env: Some(row.env()).filter(|m| !m.is_empty()),
url: row.url.clone(),
api_key: row.api_key.clone(),
url,
api_key,
launch_in: None,
},
description: row.description.clone(),
@@ -421,6 +442,7 @@ pub fn user_row_spec(
) -> McpServerSpec {
let transport = transport_of(&row.transport);
let launch_in = matches!(transport, McpTransport::Stdio).then(|| container.to_string());
let (url, api_key) = apply_key_placeholder(row.url.clone(), row.api_key.clone());
McpServerSpec {
config: McpServerConfig {
name: row.name.clone(),
@@ -428,8 +450,8 @@ pub fn user_row_spec(
command: row.command.clone(),
args: Some(row.args()).filter(|v| !v.is_empty()),
env: Some(row.env()).filter(|m| !m.is_empty()),
url: row.url.clone(),
api_key: row.api_key.clone(),
url,
api_key,
launch_in,
},
// A per-user connector's description falls back to its catalog name; the