Fills a gap the blueprint names: the admin had to hand-author every
`mcp_catalog` entry. A remote feed of vetted connectors now proposes them
and the admin installs — the feed is *consultative*, so §14's risk axis is
untouched and the trust anchor stays on the box.
Marketplace client (`src/frontend/api/marketplace.rs`):
- Fetches the feed server-side (it sends no CORS headers) and caches it;
icons are proxied for the same reason.
- Verifies every declared SHA-256 before writing, fail-closed and
all-or-nothing. Feed-supplied paths are refused if they escape
`./scripts/<id>/`. Importing an `mcp_local` entry still demands the
admin-only `mcp.register_local_script`.
- Translates the feed's vocabulary into Skald's: `user`→`per_user`,
`mcp_local`→`local_script`. Scope is read, never inferred from transport
(a remote connector can be per-user — that is what `mcp.register_remote`
is for), and an unreadable `type` fails closed to the answer needing more
authority. The feed's `llm_short_description` maps to `description`, the
column `render_mcp_list` puts in front of the LLM for `activate_tools()`.
- Feed URL is config (`marketplace.url`), not a constant: an on-premise
product must not hard-require reaching one vendor's host.
Two silent failures found while wiring it:
- `transport_of` maps anything unknown to Stdio, so the feed's
`streamable-http` would have tried to spawn a command. Normalised on import.
- Some servers want their key as a query param, not a bearer header, and say
so with a `{key}` placeholder. Substituted at connect time in
`global_row_spec`/`user_row_spec` — never at rest, so the key stays in its
own column and the stored URL stays a template.
Pages, split by the question each answers:
- Connectors — what runs (`UserMcpView` = global ∪ per-user) and what I can
add. Same page for everyone; the admin just has more verbs. One Available
list with the verb per row: `per_user`→Activate, `global`→Enable globally.
Enabling a global is the admin's counterpart to activating a per-user one,
so the catalog picker dropdown is gone — the entry comes from the row.
- Connector Catalog (admin) — what this box offers. One `Add connector`
with two sources: marketplace first (vetted, hashed), manual second
(unvetted by nature) — the order mirrors the trust model.
- Marketplace (admin) — reached from the catalog, not the sidebar: it is a
destination of an action, not a place.
`available()` no longer returns `McpGlobalServerRow`: that row carries
`api_key` and this view now reaches every logged-in user. A slim `GlobalView`
crosses instead, and an admin sees every global (with `can_use` marking their
own) so one enabled for someone else stays manageable.
Also fixes `connectors-page` having no CSS rule at all — every sibling page
has one, so it never got `flex: 1` and left an empty column beside it.
67 lines
2.7 KiB
Plaintext
67 lines
2.7 KiB
Plaintext
# ── Runtime config & secrets ──────────────────────────────────────────────────
|
|
# Copy of default.config.yaml with real API keys — never commit
|
|
/config.yml
|
|
/config/
|
|
# OAuth tokens, credentials, WhatsApp session data
|
|
/secrets/
|
|
!/secrets/.gitkeep
|
|
config.yml.bak
|
|
blueprint/
|
|
/.understand-anything
|
|
# ── Database & runtime data ───────────────────────────────────────────────────
|
|
/database/
|
|
# SQLite WAL-mode sidecar files (journal_mode=WAL)
|
|
*.db-wal
|
|
*.db-shm
|
|
*.db-journal
|
|
/data/
|
|
/logs/
|
|
/tmp/
|
|
/scripts/
|
|
|
|
# ── Rust build artifacts ──────────────────────────────────────────────────────
|
|
/target/
|
|
/deploy/
|
|
# Binary installed by ./build.sh, executed by ./run.sh
|
|
/bin/
|
|
|
|
# ── Python environment ────────────────────────────────────────────────────────
|
|
/.venv/
|
|
__pycache__/
|
|
*.pyc
|
|
*.pyo
|
|
|
|
# ── Node / WhatsApp bridge ────────────────────────────────────────────────────
|
|
node_modules/
|
|
# whatsapp-web.js local auth & cache
|
|
.wwebjs_auth/
|
|
.wwebjs_cache/
|
|
|
|
# ── LLM models (large binary files) ──────────────────────────────────────────
|
|
/models/
|
|
|
|
# ── Uploads ───────────────────────────────────────────────────────────────────
|
|
/uploads/
|
|
|
|
# ── macOS ─────────────────────────────────────────────────────────────────────
|
|
.DS_Store
|
|
|
|
# ── Private skills ────────────────────────────────────────────────────────────
|
|
skills/.gitignore
|
|
scripts/.gitignore
|
|
|
|
# ── Editors & IDEs ────────────────────────────────────────────────────────────
|
|
.claude/
|
|
.idea/
|
|
.vscode/
|
|
*.swp
|
|
*.swo
|
|
run-log.sh
|
|
/backup.sh
|
|
debug/
|
|
|
|
# Honcho Docker secrets
|
|
honcho/.env
|
|
# Istanza personale — non nel repo
|
|
honcho-local/
|