Fills a gap the blueprint names: the admin had to hand-author every
`mcp_catalog` entry. A remote feed of vetted connectors now proposes them
and the admin installs — the feed is *consultative*, so §14's risk axis is
untouched and the trust anchor stays on the box.
Marketplace client (`src/frontend/api/marketplace.rs`):
- Fetches the feed server-side (it sends no CORS headers) and caches it;
icons are proxied for the same reason.
- Verifies every declared SHA-256 before writing, fail-closed and
all-or-nothing. Feed-supplied paths are refused if they escape
`./scripts/<id>/`. Importing an `mcp_local` entry still demands the
admin-only `mcp.register_local_script`.
- Translates the feed's vocabulary into Skald's: `user`→`per_user`,
`mcp_local`→`local_script`. Scope is read, never inferred from transport
(a remote connector can be per-user — that is what `mcp.register_remote`
is for), and an unreadable `type` fails closed to the answer needing more
authority. The feed's `llm_short_description` maps to `description`, the
column `render_mcp_list` puts in front of the LLM for `activate_tools()`.
- Feed URL is config (`marketplace.url`), not a constant: an on-premise
product must not hard-require reaching one vendor's host.
Two silent failures found while wiring it:
- `transport_of` maps anything unknown to Stdio, so the feed's
`streamable-http` would have tried to spawn a command. Normalised on import.
- Some servers want their key as a query param, not a bearer header, and say
so with a `{key}` placeholder. Substituted at connect time in
`global_row_spec`/`user_row_spec` — never at rest, so the key stays in its
own column and the stored URL stays a template.
Pages, split by the question each answers:
- Connectors — what runs (`UserMcpView` = global ∪ per-user) and what I can
add. Same page for everyone; the admin just has more verbs. One Available
list with the verb per row: `per_user`→Activate, `global`→Enable globally.
Enabling a global is the admin's counterpart to activating a per-user one,
so the catalog picker dropdown is gone — the entry comes from the row.
- Connector Catalog (admin) — what this box offers. One `Add connector`
with two sources: marketplace first (vetted, hashed), manual second
(unvetted by nature) — the order mirrors the trust model.
- Marketplace (admin) — reached from the catalog, not the sidebar: it is a
destination of an action, not a place.
`available()` no longer returns `McpGlobalServerRow`: that row carries
`api_key` and this view now reaches every logged-in user. A slim `GlobalView`
crosses instead, and an admin sees every global (with `can_use` marking their
own) so one enabled for someone else stays manageable.
Also fixes `connectors-page` having no CSS rule at all — every sibling page
has one, so it never got `flex: 1` and left an empty column beside it.
102 lines
4.8 KiB
TOML
102 lines
4.8 KiB
TOML
[workspace]
|
|
members = [
|
|
".",
|
|
"crates/skald-core",
|
|
"crates/skald-setup",
|
|
"crates/honcho-client",
|
|
"crates/llm-client",
|
|
"crates/core-api",
|
|
"crates/mcp-client",
|
|
"crates/plugin-tailscale-remote",
|
|
"crates/plugin-telegram-bot",
|
|
"crates/plugin-mobile-connector",
|
|
"crates/plugin-transcribe-whisper-local",
|
|
"crates/plugin-comfyui",
|
|
"crates/plugin-tts-orpheus-3b",
|
|
"crates/plugin-tts-kokoro",
|
|
"crates/plugin-elevenlabs",
|
|
"crates/skald-relay-common",
|
|
"crates/skald-relay-server",
|
|
"crates/skald-relay-client",
|
|
]
|
|
resolver = "2"
|
|
|
|
[package]
|
|
name = "skald"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
|
|
[features]
|
|
default = ["whisper-local"]
|
|
whisper-local = ["dep:plugin-transcribe-whisper-local"]
|
|
# Desktop bundle mode: wraps the headless server in a Tauri webview with a
|
|
# system-tray icon (menu-bar on macOS, notification area on Windows, AppIndicator
|
|
# on Linux). When enabled, `main.rs` enters the Tauri event loop instead of the
|
|
# plain tokio blocking path; the backend runs as a task on Tauri's shared runtime.
|
|
# Build a distributable bundle with: cargo tauri build --features desktop
|
|
desktop = ["dep:tauri", "dep:dirs", "dep:tauri-build"]
|
|
# Embedded (pure-Rust) Tailscale provider. Off by default: the `tailscale` crate
|
|
# forces the `aws-lc-rs` crypto backend (a cmake/NASM C build) back into the
|
|
# tree, defeating the ring-only crypto path. The recommended `tailscale_sys`
|
|
# provider (system tailscaled) stays available without it. Enable only for a
|
|
# self-contained embedded mesh (re-introduces the aws-lc-rs C build).
|
|
embedded-tailscale = ["plugin-tailscale-remote/remote-tailscale"]
|
|
|
|
[build-dependencies]
|
|
tauri-build = { version = "2", optional = true , features = [] }
|
|
|
|
[dependencies]
|
|
skald-core = { path = "crates/skald-core" }
|
|
|
|
axum = { version = "0.8", features = ["ws", "multipart"] }
|
|
tokio = { version = "1.52.3", features = ["full"] }
|
|
tokio-util = { version = "0.7", features = ["rt"] }
|
|
futures = "0.3"
|
|
tower-http = { version = "0.7.0", features = ["fs", "compression-gzip", "compression-br", "set-header"] }
|
|
tower = "0.5"
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_yaml = "0.9"
|
|
anyhow = "1"
|
|
# Verifies the SHA-256 digests the connector marketplace declares for each file
|
|
# it serves (src/frontend/api/marketplace.rs).
|
|
sha2 = "0.10"
|
|
sqlx = { version = "0.9.0", features = ["runtime-tokio", "sqlite"] }
|
|
reqwest = { version = "0.13.4", default-features = false, features = ["rustls-no-provider", "charset", "http2", "system-proxy", "json", "multipart"] }
|
|
# rustls is pinned as a direct dependency solely to select the crypto provider:
|
|
# `ring` instead of the default `aws-lc-rs`, avoiding aws-lc's cmake/NASM build.
|
|
# Every reqwest client uses `rustls-no-provider`, so exactly one process-wide
|
|
# provider is installed in main() before any TLS handshake.
|
|
#
|
|
# TLS therefore never touches OpenSSL. libcrypto is nonetheless in the tree now,
|
|
# vendored and statically linked for SQLCipher (see `libsqlite3-sys` in
|
|
# crates/skald-core) — so the binary stays self-contained, but "no OpenSSL
|
|
# anywhere" is no longer true.
|
|
rustls = { version = "0.23", default-features = false, features = ["ring", "std", "tls12", "logging"] }
|
|
async-trait = "0.1"
|
|
serde_json = "1"
|
|
indexmap = { version = "2", features = ["serde"] }
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
tracing-appender = "0.2"
|
|
chrono = { version = "0.4", default-features = false, features = ["clock", "std"] }
|
|
libc = "0.2"
|
|
notify = "8"
|
|
honcho-client = { path = "crates/honcho-client" }
|
|
llm-client = { path = "crates/llm-client" }
|
|
core-api = { path = "crates/core-api" }
|
|
mcp-client = { path = "crates/mcp-client" }
|
|
plugin-tailscale-remote = { path = "crates/plugin-tailscale-remote" }
|
|
plugin-telegram-bot = { path = "crates/plugin-telegram-bot" }
|
|
plugin-mobile-connector = { path = "crates/plugin-mobile-connector" }
|
|
plugin-transcribe-whisper-local = { path = "crates/plugin-transcribe-whisper-local", optional = true }
|
|
plugin-comfyui = { path = "crates/plugin-comfyui" }
|
|
plugin-tts-orpheus-3b = { path = "crates/plugin-tts-orpheus-3b" }
|
|
plugin-tts-kokoro = { path = "crates/plugin-tts-kokoro" }
|
|
plugin-elevenlabs = { path = "crates/plugin-elevenlabs" }
|
|
|
|
# ── Desktop bundle (Tauri) ───────────────────────────────────────────────────
|
|
# Optional, activated by the `desktop` feature. Wraps the headless server in a
|
|
# Tauri webview with a system-tray icon. See src/desktop/ and docs/desktop.md.
|
|
tauri = { version = "2", optional = true, features = ["tray-icon"] }
|
|
dirs = { version = "5", optional = true }
|