Compare commits

..

1 Commits

Author SHA1 Message Date
Lunny Xiao 6744cab627 feat(gitea): support extra outbound HTTP headers via GITEA_EXTRA_HEADERS
Add a GITEA_EXTRA_HEADERS environment variable that accepts a JSON
object of header name/value pairs (e.g. Cloudflare Access
credentials) and applies them to every outbound request to Gitea,
both the raw pkg/gitea.DoJSON/DoBytes path and the SDK-backed
pkg/gitea.NewClient path, without overriding Authorization,
Content-Type, or Accept.

Co-Authored-By: Codet <codet@commitgo.dev> (GPT-5-Codex)
2026-08-23 23:33:36 -07:00
11 changed files with 198 additions and 352 deletions
+8
View File
@@ -20,6 +20,14 @@ make install
Pass the Gitea host and access token as command-line flags or environment variables, flags take precedence. Run `gitea-mcp --help` for the full list of flags and environment variables. Logs are written to `$HOME/.gitea-mcp/gitea-mcp.log`, add `-d` for debug logging.
Set `GITEA_EXTRA_HEADERS` to a JSON object of header name/value pairs to send with every outbound request to Gitea, for example when Gitea sits behind Cloudflare Access:
```bash
export GITEA_EXTRA_HEADERS='{"CF-Access-Client-Id":"id","CF-Access-Client-Secret":"secret"}'
```
These headers never override `Authorization`, `Content-Type`, or `Accept` set by `gitea-mcp` itself.
### MCP protocol and HTTP transport
The server supports MCP up to `2026-07-28` and negotiates down to the client's version, advertising only the `tools` capability. Tool and Gitea failures return a `tools/call` result with `result.isError: true`, while malformed requests and server faults stay JSON-RPC errors.
+15
View File
@@ -2,9 +2,11 @@ package cmd
import (
"context"
"encoding/json"
"flag"
"fmt"
"io"
"net/http"
"os"
"strconv"
"strings"
@@ -86,6 +88,7 @@ func initFlagSet(fs *flag.FlagSet, args []string, getenv func(string) string, re
fmt.Fprintf(w, " GITEA_ACCESS_TOKEN\tProvide access token\n")
fmt.Fprintf(w, " GITEA_ACCESS_TOKEN_FILE\tPath to a file containing the access token (e.g. a Docker secret)\n")
fmt.Fprintf(w, " GITEA_DEBUG\tSet to 'true' for debug mode\n")
fmt.Fprintf(w, " GITEA_EXTRA_HEADERS\tJSON object of extra HTTP headers to send with Gitea API requests\n")
fmt.Fprintf(w, " GITEA_HOST\tOverride Gitea host URL\n")
fmt.Fprintf(w, " GITEA_INSECURE\tSet to 'true' to ignore TLS errors\n")
fmt.Fprintf(w, " GITEA_MAX_INLINE_ATTACHMENT_BYTES\tOverride inline image attachment size limit in bytes\n")
@@ -164,6 +167,18 @@ func initFlagSet(fs *flag.FlagSet, args []string, getenv func(string) string, re
flagPkg.MaxInlineAttachmentBytes = parsed
}
}
if val := getenv("GITEA_EXTRA_HEADERS"); val != "" {
var headers map[string]string
if err := json.Unmarshal([]byte(val), &headers); err != nil {
fmt.Fprintf(stderr, "invalid GITEA_EXTRA_HEADERS: %v\n", err)
osExit(1)
}
extraHeaders := make(http.Header, len(headers))
for name, value := range headers {
extraHeaders.Set(name, value)
}
flagPkg.ExtraHeaders = extraHeaders
}
}
// normalizeScope trims whitespace, lowercases, and converts internal spaces
+52
View File
@@ -5,6 +5,7 @@ import (
"flag"
"maps"
"slices"
"strings"
"testing"
flagPkg "gitea.com/gitea/gitea-mcp/pkg/flag"
@@ -95,3 +96,54 @@ func TestInitFlagSetScopes(t *testing.T) {
})
}
}
func TestInitFlagSetExtraHeaders(t *testing.T) {
t.Cleanup(func() { flagPkg.ExtraHeaders = nil })
getenv := func(key string) string {
if key == "GITEA_EXTRA_HEADERS" {
return `{"CF-Access-Client-Id":"id","CF-Access-Client-Secret":"secret"}`
}
return ""
}
readFile := func(string) ([]byte, error) { return nil, nil }
fs := flag.NewFlagSet("test", flag.ContinueOnError)
var stderr bytes.Buffer
initFlagSet(fs, []string{}, getenv, readFile, &stderr)
if got := flagPkg.ExtraHeaders.Get("CF-Access-Client-Id"); got != "id" {
t.Errorf("ExtraHeaders[CF-Access-Client-Id] = %q, want %q", got, "id")
}
if got := flagPkg.ExtraHeaders.Get("CF-Access-Client-Secret"); got != "secret" {
t.Errorf("ExtraHeaders[CF-Access-Client-Secret] = %q, want %q", got, "secret")
}
}
func TestInitFlagSetExtraHeadersInvalidJSON(t *testing.T) {
t.Cleanup(func() { flagPkg.ExtraHeaders = nil })
origOsExit := osExit
var exitCode int
osExit = func(code int) { exitCode = code }
t.Cleanup(func() { osExit = origOsExit })
getenv := func(key string) string {
if key == "GITEA_EXTRA_HEADERS" {
return `not-json`
}
return ""
}
readFile := func(string) ([]byte, error) { return nil, nil }
fs := flag.NewFlagSet("test", flag.ContinueOnError)
var stderr bytes.Buffer
initFlagSet(fs, []string{}, getenv, readFile, &stderr)
if exitCode != 1 {
t.Errorf("exitCode = %d, want 1", exitCode)
}
if !strings.Contains(stderr.String(), "GITEA_EXTRA_HEADERS") {
t.Errorf("stderr = %q, want mention of GITEA_EXTRA_HEADERS", stderr.String())
}
}
+1 -6
View File
@@ -29,7 +29,7 @@ var (
ActionsRunReadToolName,
"Read Actions workflows, runs, jobs, logs, and artifacts.",
annotation.ReadOnly("Read Actions workflow, run, job, and artifact data"),
tool.String("method", tool.Required(), tool.Enum("list_workflows", "get_workflow", "list_runs", "get_run", "list_jobs", "list_run_jobs", "get_job", "get_job_log_preview", "download_job_log", "list_artifacts", "list_run_artifacts", "get_artifact", "download_artifact", "wait_for_pr_checks")),
tool.String("method", tool.Required(), tool.Enum("list_workflows", "get_workflow", "list_runs", "get_run", "list_jobs", "list_run_jobs", "get_job", "get_job_log_preview", "download_job_log", "list_artifacts", "list_run_artifacts", "get_artifact", "download_artifact")),
tool.String("owner", tool.Required(), tool.Description(params.OwnerDesc)),
tool.String("repo", tool.Required(), tool.Description(params.RepoDesc)),
tool.String("workflow_id", tool.Description("ID or filename (for 'get_workflow')")),
@@ -43,9 +43,6 @@ var (
tool.String("output_path", tool.Description("for 'download_job_log'/'download_artifact'")),
tool.Number("page", tool.Description(params.PageDesc), tool.Default(1), tool.Minimum(1)),
tool.Number("per_page", tool.Description(params.PaginationDesc), tool.Default(30), tool.Minimum(1)),
tool.Number("pull_number", tool.Description("PR number (for 'wait_for_pr_checks')")),
tool.Number("timeout_seconds", tool.Description("max time to wait (for 'wait_for_pr_checks')"), tool.Default(120), tool.Minimum(1)),
tool.Number("poll_interval_seconds", tool.Description("time between polls (for 'wait_for_pr_checks')"), tool.Default(5), tool.Minimum(1)),
)
ActionsRunWriteTool = tool.NewDefinition(
@@ -99,8 +96,6 @@ func runReadFn(ctx context.Context, args map[string]any) (*mcp.CallToolResult, e
return getRepoActionArtifactFn(ctx, args)
case "download_artifact":
return downloadRepoActionArtifactFn(ctx, args)
case "wait_for_pr_checks":
return waitForPRChecksFn(ctx, args)
default:
return to.ErrorResult(fmt.Errorf("unknown method: %s", method))
}
-174
View File
@@ -1,174 +0,0 @@
package actions
import (
"context"
"errors"
"fmt"
"net/url"
"strings"
"time"
"gitea.com/gitea/gitea-mcp/pkg/params"
"gitea.com/gitea/gitea-mcp/pkg/to"
"github.com/modelcontextprotocol/go-sdk/mcp"
)
const (
defaultWaitForPRChecksTimeoutSeconds = 120
defaultWaitForPRChecksPollIntervalSeconds = 5
)
// terminalRunStatuses lists Gitea Actions run statuses that never transition
// further, independent of whether a "conclusion" field is also present.
var terminalRunStatuses = map[string]bool{
"completed": true,
"success": true,
"failure": true,
"cancelled": true,
"skipped": true,
"failed": true,
"error": true,
}
func isRunTerminal(run map[string]any) bool {
if conclusion, ok := run["conclusion"].(string); ok && conclusion != "" {
return true
}
status, _ := run["status"].(string)
return terminalRunStatuses[strings.ToLower(status)]
}
func allRunsTerminal(runs []map[string]any) bool {
for _, run := range runs {
if !isRunTerminal(run) {
return false
}
}
return true
}
// waitForRunsUntilTerminal polls fetch until every run it returns is terminal
// or timeout elapses, sleeping pollInterval (capped to the remaining time)
// between polls so callers can inject a short pollInterval in tests.
func waitForRunsUntilTerminal(ctx context.Context, timeout, pollInterval time.Duration, fetch func(ctx context.Context) ([]map[string]any, error)) ([]map[string]any, bool, error) {
deadline := time.Now().Add(timeout)
for {
runs, err := fetch(ctx)
if err != nil {
return nil, false, err
}
if allRunsTerminal(runs) {
return runs, false, nil
}
remaining := time.Until(deadline)
if remaining <= 0 {
return runs, true, nil
}
wait := min(pollInterval, remaining)
select {
case <-ctx.Done():
return runs, false, ctx.Err()
case <-time.After(wait):
}
}
}
func fetchPullRequestHeadSHA(ctx context.Context, owner, repo string, pullNumber int64) (string, error) {
var result map[string]any
err := doJSONWithFallback(ctx, "GET",
[]string{
fmt.Sprintf("repos/%s/%s/pulls/%d", url.PathEscape(owner), url.PathEscape(repo), pullNumber),
},
nil, nil, &result,
)
if err != nil {
return "", err
}
head, ok := result["head"].(map[string]any)
if !ok {
return "", errors.New("pull request response missing head")
}
sha, ok := head["sha"].(string)
if !ok || sha == "" {
return "", errors.New("pull request response missing head.sha")
}
return sha, nil
}
func fetchActionRunsForSHA(ctx context.Context, owner, repo, sha string) ([]map[string]any, error) {
query := url.Values{}
query.Set("head_sha", sha)
var result map[string]any
err := doJSONWithFallback(ctx, "GET",
[]string{
fmt.Sprintf("repos/%s/%s/actions/runs", url.PathEscape(owner), url.PathEscape(repo)),
},
query, nil, &result,
)
if err != nil {
return nil, err
}
items, _ := result["workflow_runs"].([]any)
runs := make([]map[string]any, 0, len(items))
for _, item := range items {
if run, ok := item.(map[string]any); ok {
runs = append(runs, run)
}
}
return runs, nil
}
func waitForPRChecksFn(ctx context.Context, args map[string]any) (*mcp.CallToolResult, error) {
owner, err := params.GetString(args, "owner")
if err != nil {
return to.ErrorResult(err)
}
repo, err := params.GetString(args, "repo")
if err != nil {
return to.ErrorResult(err)
}
pullNumber, err := params.GetIndex(args, "pull_number")
if err != nil || pullNumber <= 0 {
return to.ErrorResult(errors.New("pull_number is required"))
}
timeoutSeconds := params.GetOptionalInt(args, "timeout_seconds", defaultWaitForPRChecksTimeoutSeconds)
if timeoutSeconds <= 0 {
timeoutSeconds = defaultWaitForPRChecksTimeoutSeconds
}
pollIntervalSeconds := params.GetOptionalInt(args, "poll_interval_seconds", defaultWaitForPRChecksPollIntervalSeconds)
if pollIntervalSeconds <= 0 {
pollIntervalSeconds = defaultWaitForPRChecksPollIntervalSeconds
}
sha, err := fetchPullRequestHeadSHA(ctx, owner, repo, pullNumber)
if err != nil {
return to.ErrorResult(fmt.Errorf("get pull request err: %v", err))
}
runs, timedOut, err := waitForRunsUntilTerminal(ctx,
time.Duration(timeoutSeconds)*time.Second,
time.Duration(pollIntervalSeconds)*time.Second,
func(ctx context.Context) ([]map[string]any, error) {
return fetchActionRunsForSHA(ctx, owner, repo, sha)
},
)
if err != nil {
return to.ErrorResult(fmt.Errorf("wait for pr checks err: %v", err))
}
slimmedRuns := make([]map[string]any, 0, len(runs))
for _, run := range runs {
slimmedRuns = append(slimmedRuns, slimRun(run))
}
return to.TextResult(map[string]any{
"head_sha": sha,
"timed_out": timedOut,
"runs": slimmedRuns,
})
}
-169
View File
@@ -1,169 +0,0 @@
package actions
import (
"context"
"errors"
"fmt"
"net/http"
"net/http/httptest"
"strings"
"sync"
"sync/atomic"
"testing"
"time"
"gitea.com/gitea/gitea-mcp/pkg/flag"
"github.com/modelcontextprotocol/go-sdk/mcp"
)
func TestAllRunsTerminal(t *testing.T) {
tests := []struct {
name string
runs []map[string]any
want bool
}{
{"no runs", nil, true},
{"single completed run with conclusion", []map[string]any{{"status": "completed", "conclusion": "success"}}, true},
{"single running run", []map[string]any{{"status": "running", "conclusion": ""}}, false},
{"single waiting run", []map[string]any{{"status": "waiting"}}, false},
{"mixed terminal and running", []map[string]any{
{"status": "completed", "conclusion": "success"},
{"status": "running"},
}, false},
{"all terminal", []map[string]any{
{"status": "completed", "conclusion": "failure"},
{"status": "completed", "conclusion": "cancelled"},
}, true},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
if got := allRunsTerminal(tt.runs); got != tt.want {
t.Errorf("allRunsTerminal() = %v, want %v", got, tt.want)
}
})
}
}
func TestWaitForRunsUntilTerminal_ReturnsOnceTerminal(t *testing.T) {
calls := 0
fetch := func(ctx context.Context) ([]map[string]any, error) {
calls++
if calls < 3 {
return []map[string]any{{"status": "running"}}, nil
}
return []map[string]any{{"status": "completed", "conclusion": "success"}}, nil
}
runs, timedOut, err := waitForRunsUntilTerminal(context.Background(), time.Second, time.Millisecond, fetch)
if err != nil {
t.Fatalf("waitForRunsUntilTerminal() error = %v", err)
}
if timedOut {
t.Fatalf("expected timedOut = false")
}
if calls != 3 {
t.Fatalf("expected 3 fetch calls, got %d", calls)
}
if len(runs) != 1 || runs[0]["conclusion"] != "success" {
t.Fatalf("unexpected runs: %v", runs)
}
}
func TestWaitForRunsUntilTerminal_TimesOut(t *testing.T) {
fetch := func(ctx context.Context) ([]map[string]any, error) {
return []map[string]any{{"status": "running"}}, nil
}
runs, timedOut, err := waitForRunsUntilTerminal(context.Background(), 20*time.Millisecond, time.Millisecond, fetch)
if err != nil {
t.Fatalf("waitForRunsUntilTerminal() error = %v", err)
}
if !timedOut {
t.Fatalf("expected timedOut = true")
}
if len(runs) != 1 {
t.Fatalf("expected last fetched runs to be returned, got %v", runs)
}
}
func TestWaitForRunsUntilTerminal_PropagatesFetchError(t *testing.T) {
wantErr := errors.New("boom")
fetch := func(ctx context.Context) ([]map[string]any, error) {
return nil, wantErr
}
_, _, err := waitForRunsUntilTerminal(context.Background(), time.Second, time.Millisecond, fetch)
if !errors.Is(err, wantErr) {
t.Fatalf("waitForRunsUntilTerminal() error = %v, want %v", err, wantErr)
}
}
func Test_waitForPRChecksFn(t *testing.T) {
const (
owner = "octo"
repo = "demo"
pullNumber = 42
headSHA = "abc123"
)
var runsRequests int32
handler := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
switch {
case r.URL.Path == fmt.Sprintf("/api/v1/repos/%s/%s/pulls/%d", owner, repo, pullNumber):
_, _ = fmt.Fprintf(w, `{"head":{"sha":%q}}`, headSHA)
case r.URL.Path == fmt.Sprintf("/api/v1/repos/%s/%s/actions/runs", owner, repo):
atomic.AddInt32(&runsRequests, 1)
if r.URL.Query().Get("head_sha") != headSHA {
t.Errorf("expected head_sha query param %q, got %q", headSHA, r.URL.Query().Get("head_sha"))
}
_, _ = fmt.Fprint(w, `{"workflow_runs":[{"id":1,"status":"completed","conclusion":"success"},{"id":2,"status":"completed","conclusion":"failure"}]}`)
default:
http.NotFound(w, r)
}
})
server := httptest.NewServer(handler)
defer server.Close()
var mu sync.Mutex
mu.Lock()
origHost, origToken := flag.Host, flag.Token
flag.Host, flag.Token = server.URL, ""
mu.Unlock()
defer func() {
mu.Lock()
flag.Host, flag.Token = origHost, origToken
mu.Unlock()
}()
args := map[string]any{
"owner": owner,
"repo": repo,
"pull_number": float64(pullNumber),
}
result, err := waitForPRChecksFn(context.Background(), args)
if err != nil {
t.Fatalf("waitForPRChecksFn() error = %v", err)
}
if atomic.LoadInt32(&runsRequests) != 1 {
t.Fatalf("expected exactly 1 runs request, got %d", runsRequests)
}
if len(result.Content) == 0 {
t.Fatalf("expected content in result")
}
textContent, ok := result.Content[0].(*mcp.TextContent)
if !ok {
t.Fatalf("expected text content, got %T", result.Content[0])
}
if !strings.Contains(textContent.Text, headSHA) {
t.Fatalf("expected result to mention head sha %q, got %s", headSHA, textContent.Text)
}
if !strings.Contains(textContent.Text, `"timed_out":false`) {
t.Fatalf("expected result to report timed_out=false, got %s", textContent.Text)
}
}
+3
View File
@@ -1,5 +1,7 @@
package flag
import "net/http"
var (
Host string
Bind string
@@ -15,4 +17,5 @@ var (
Debug bool
AllowedTools map[string]struct{}
AllowedScopes map[string]struct{}
ExtraHeaders http.Header
)
+27 -1
View File
@@ -30,6 +30,32 @@ func sharedTransport() *http.Transport {
return sharedTrans
}
// extraHeaderTransport injects flag.ExtraHeaders into every request, without
// overriding headers the caller already set (e.g. Authorization, Content-Type,
// Accept). It reads flag.ExtraHeaders on each round trip rather than caching
// it, so tests can change it between requests.
type extraHeaderTransport struct {
base http.RoundTripper
}
func (t *extraHeaderTransport) RoundTrip(req *http.Request) (*http.Response, error) {
headers := flag.ExtraHeaders
if len(headers) == 0 {
return t.base.RoundTrip(req)
}
cloned := req.Clone(req.Context())
for name, values := range headers {
if cloned.Header.Get(name) == "" {
cloned.Header[name] = values
}
}
return t.base.RoundTrip(cloned)
}
func giteaTransport() http.RoundTripper {
return &extraHeaderTransport{base: sharedTransport()}
}
// NewClient returns a cached *gitea.Client keyed by host+token. The SDK's per-client
// version cache and the shared transport let us reuse keep-alive connections
// and avoid the SDK's /api/v1/version preflight on every tool call.
@@ -40,7 +66,7 @@ func NewClient(token string) (*gitea.Client, error) {
}
httpClient := &http.Client{
Transport: sharedTransport(),
Transport: giteaTransport(),
CheckRedirect: checkRedirect,
}
opts := []gitea.ClientOption{
+49
View File
@@ -0,0 +1,49 @@
package gitea
import (
"context"
"net/http"
"net/http/httptest"
"testing"
"gitea.com/gitea/gitea-mcp/pkg/flag"
)
func TestNewClient_SendsExtraHeaders(t *testing.T) {
var gotClientID, gotAuthorization string
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
gotClientID = r.Header.Get("CF-Access-Client-Id")
gotAuthorization = r.Header.Get("Authorization")
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
_, _ = w.Write([]byte(`{"login":"octocat"}`))
}))
defer srv.Close()
origHost := flag.Host
origExtraHeaders := flag.ExtraHeaders
defer func() {
flag.Host = origHost
flag.ExtraHeaders = origExtraHeaders
}()
flag.Host = srv.URL
flag.ExtraHeaders = http.Header{
"Cf-Access-Client-Id": []string{"client-id"},
"Authorization": []string{"should-not-override"},
}
client, err := NewClient("the-token")
if err != nil {
t.Fatalf("NewClient returned error: %v", err)
}
if _, _, err := client.Users.GetMyUserInfo(context.Background()); err != nil {
t.Fatalf("GetMyUserInfo returned error: %v", err)
}
if gotClientID != "client-id" {
t.Fatalf("CF-Access-Client-Id header = %q, want %q", gotClientID, "client-id")
}
if gotAuthorization != "token the-token" {
t.Fatalf("Authorization header = %q, want %q", gotAuthorization, "token the-token")
}
}
+2 -2
View File
@@ -59,7 +59,7 @@ var (
func restHTTPClient() *http.Client {
restClientOnce.Do(func() {
restClient = &http.Client{
Transport: sharedTransport(),
Transport: giteaTransport(),
Timeout: httpClientTimeout,
CheckRedirect: checkRedirect,
}
@@ -180,7 +180,7 @@ func DoJSON(ctx context.Context, method, path string, query url.Values, body, re
func attachmentHTTPClient(origin *url.URL) *http.Client {
return &http.Client{
Transport: sharedTransport(),
Transport: giteaTransport(),
CheckRedirect: func(req *http.Request, via []*http.Request) error {
if err := checkRedirect(req, via); err != nil {
return err
+41
View File
@@ -62,3 +62,44 @@ func TestDoJSON_LimitsErrorResponseBody(t *testing.T) {
t.Fatalf("expected body length %d, got %d", errBodySnippetSize, len(httpErr.Body))
}
}
func TestDoJSON_SendsExtraHeaders(t *testing.T) {
var gotClientID, gotAuthorization string
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
gotClientID = r.Header.Get("CF-Access-Client-Id")
gotAuthorization = r.Header.Get("Authorization")
w.WriteHeader(http.StatusOK)
_, _ = io.WriteString(w, "{}")
}))
defer srv.Close()
origHost := flag.Host
origToken := flag.Token
origExtraHeaders := flag.ExtraHeaders
defer func() {
flag.Host = origHost
flag.Token = origToken
flag.ExtraHeaders = origExtraHeaders
}()
flag.Host = srv.URL
flag.Token = "the-token"
flag.ExtraHeaders = http.Header{
"Cf-Access-Client-Id": []string{"client-id"},
"Authorization": []string{"should-not-override"},
}
var out map[string]any
status, err := DoJSON(context.Background(), http.MethodGet, "repos/owner/repo", nil, nil, &out)
if err != nil {
t.Fatalf("DoJSON returned error: %v", err)
}
if status != http.StatusOK {
t.Fatalf("expected status %d, got %d", http.StatusOK, status)
}
if gotClientID != "client-id" {
t.Fatalf("CF-Access-Client-Id header = %q, want %q", gotClientID, "client-id")
}
if gotAuthorization != "token the-token" {
t.Fatalf("Authorization header = %q, want %q", gotAuthorization, "token the-token")
}
}