mirror of
https://gitea.com/gitea/gitea-mcp.git
synced 2026-08-28 02:57:44 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a5d3910a89 |
@@ -20,14 +20,6 @@ make install
|
||||
|
||||
Pass the Gitea host and access token as command-line flags or environment variables, flags take precedence. Run `gitea-mcp --help` for the full list of flags and environment variables. Logs are written to `$HOME/.gitea-mcp/gitea-mcp.log`, add `-d` for debug logging.
|
||||
|
||||
Set `GITEA_EXTRA_HEADERS` to a JSON object of header name/value pairs to send with every outbound request to Gitea, for example when Gitea sits behind Cloudflare Access:
|
||||
|
||||
```bash
|
||||
export GITEA_EXTRA_HEADERS='{"CF-Access-Client-Id":"id","CF-Access-Client-Secret":"secret"}'
|
||||
```
|
||||
|
||||
These headers never override `Authorization`, `Content-Type`, or `Accept` set by `gitea-mcp` itself.
|
||||
|
||||
### MCP protocol and HTTP transport
|
||||
|
||||
The server supports MCP up to `2026-07-28` and negotiates down to the client's version, advertising only the `tools` capability. Tool and Gitea failures return a `tools/call` result with `result.isError: true`, while malformed requests and server faults stay JSON-RPC errors.
|
||||
|
||||
-15
@@ -2,11 +2,9 @@ package cmd
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"flag"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"os"
|
||||
"strconv"
|
||||
"strings"
|
||||
@@ -88,7 +86,6 @@ func initFlagSet(fs *flag.FlagSet, args []string, getenv func(string) string, re
|
||||
fmt.Fprintf(w, " GITEA_ACCESS_TOKEN\tProvide access token\n")
|
||||
fmt.Fprintf(w, " GITEA_ACCESS_TOKEN_FILE\tPath to a file containing the access token (e.g. a Docker secret)\n")
|
||||
fmt.Fprintf(w, " GITEA_DEBUG\tSet to 'true' for debug mode\n")
|
||||
fmt.Fprintf(w, " GITEA_EXTRA_HEADERS\tJSON object of extra HTTP headers to send with Gitea API requests\n")
|
||||
fmt.Fprintf(w, " GITEA_HOST\tOverride Gitea host URL\n")
|
||||
fmt.Fprintf(w, " GITEA_INSECURE\tSet to 'true' to ignore TLS errors\n")
|
||||
fmt.Fprintf(w, " GITEA_MAX_INLINE_ATTACHMENT_BYTES\tOverride inline image attachment size limit in bytes\n")
|
||||
@@ -167,18 +164,6 @@ func initFlagSet(fs *flag.FlagSet, args []string, getenv func(string) string, re
|
||||
flagPkg.MaxInlineAttachmentBytes = parsed
|
||||
}
|
||||
}
|
||||
if val := getenv("GITEA_EXTRA_HEADERS"); val != "" {
|
||||
var headers map[string]string
|
||||
if err := json.Unmarshal([]byte(val), &headers); err != nil {
|
||||
fmt.Fprintf(stderr, "invalid GITEA_EXTRA_HEADERS: %v\n", err)
|
||||
osExit(1)
|
||||
}
|
||||
extraHeaders := make(http.Header, len(headers))
|
||||
for name, value := range headers {
|
||||
extraHeaders.Set(name, value)
|
||||
}
|
||||
flagPkg.ExtraHeaders = extraHeaders
|
||||
}
|
||||
}
|
||||
|
||||
// normalizeScope trims whitespace, lowercases, and converts internal spaces
|
||||
|
||||
@@ -5,7 +5,6 @@ import (
|
||||
"flag"
|
||||
"maps"
|
||||
"slices"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
flagPkg "gitea.com/gitea/gitea-mcp/pkg/flag"
|
||||
@@ -96,54 +95,3 @@ func TestInitFlagSetScopes(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestInitFlagSetExtraHeaders(t *testing.T) {
|
||||
t.Cleanup(func() { flagPkg.ExtraHeaders = nil })
|
||||
|
||||
getenv := func(key string) string {
|
||||
if key == "GITEA_EXTRA_HEADERS" {
|
||||
return `{"CF-Access-Client-Id":"id","CF-Access-Client-Secret":"secret"}`
|
||||
}
|
||||
return ""
|
||||
}
|
||||
readFile := func(string) ([]byte, error) { return nil, nil }
|
||||
fs := flag.NewFlagSet("test", flag.ContinueOnError)
|
||||
var stderr bytes.Buffer
|
||||
|
||||
initFlagSet(fs, []string{}, getenv, readFile, &stderr)
|
||||
|
||||
if got := flagPkg.ExtraHeaders.Get("CF-Access-Client-Id"); got != "id" {
|
||||
t.Errorf("ExtraHeaders[CF-Access-Client-Id] = %q, want %q", got, "id")
|
||||
}
|
||||
if got := flagPkg.ExtraHeaders.Get("CF-Access-Client-Secret"); got != "secret" {
|
||||
t.Errorf("ExtraHeaders[CF-Access-Client-Secret] = %q, want %q", got, "secret")
|
||||
}
|
||||
}
|
||||
|
||||
func TestInitFlagSetExtraHeadersInvalidJSON(t *testing.T) {
|
||||
t.Cleanup(func() { flagPkg.ExtraHeaders = nil })
|
||||
|
||||
origOsExit := osExit
|
||||
var exitCode int
|
||||
osExit = func(code int) { exitCode = code }
|
||||
t.Cleanup(func() { osExit = origOsExit })
|
||||
|
||||
getenv := func(key string) string {
|
||||
if key == "GITEA_EXTRA_HEADERS" {
|
||||
return `not-json`
|
||||
}
|
||||
return ""
|
||||
}
|
||||
readFile := func(string) ([]byte, error) { return nil, nil }
|
||||
fs := flag.NewFlagSet("test", flag.ContinueOnError)
|
||||
var stderr bytes.Buffer
|
||||
|
||||
initFlagSet(fs, []string{}, getenv, readFile, &stderr)
|
||||
|
||||
if exitCode != 1 {
|
||||
t.Errorf("exitCode = %d, want 1", exitCode)
|
||||
}
|
||||
if !strings.Contains(stderr.String(), "GITEA_EXTRA_HEADERS") {
|
||||
t.Errorf("stderr = %q, want mention of GITEA_EXTRA_HEADERS", stderr.String())
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,98 @@
|
||||
package actions
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"testing"
|
||||
|
||||
"gitea.com/gitea/gitea-mcp/pkg/flag"
|
||||
|
||||
"github.com/modelcontextprotocol/go-sdk/mcp"
|
||||
)
|
||||
|
||||
func Test_listPullRequestActionRunsFn(t *testing.T) {
|
||||
const (
|
||||
owner = "octo"
|
||||
repo = "demo"
|
||||
pullNumber = 42
|
||||
headSHA = "abc123"
|
||||
)
|
||||
|
||||
var gotRunsQuery string
|
||||
|
||||
handler := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
switch r.URL.Path {
|
||||
case fmt.Sprintf("/api/v1/repos/%s/%s/pulls/%d", owner, repo, pullNumber):
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = w.Write(fmt.Appendf(nil, `{"number":%d,"head":{"sha":"%s"}}`, pullNumber, headSHA))
|
||||
case fmt.Sprintf("/api/v1/repos/%s/%s/actions/runs", owner, repo):
|
||||
gotRunsQuery = r.URL.RawQuery
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = w.Write([]byte(`{"total_count":1,"workflow_runs":[{"id":9,"name":"CI","status":"success"}]}`))
|
||||
default:
|
||||
http.NotFound(w, r)
|
||||
}
|
||||
})
|
||||
|
||||
server := httptest.NewServer(handler)
|
||||
defer server.Close()
|
||||
|
||||
origHost := flag.Host
|
||||
origToken := flag.Token
|
||||
flag.Host = server.URL
|
||||
flag.Token = ""
|
||||
defer func() {
|
||||
flag.Host = origHost
|
||||
flag.Token = origToken
|
||||
}()
|
||||
|
||||
args := map[string]any{
|
||||
"owner": owner,
|
||||
"repo": repo,
|
||||
"pull_number": float64(pullNumber),
|
||||
}
|
||||
|
||||
result, err := listPullRequestActionRunsFn(context.Background(), args)
|
||||
if err != nil {
|
||||
t.Fatalf("listPullRequestActionRunsFn() error = %v", err)
|
||||
}
|
||||
if result.IsError {
|
||||
t.Fatalf("listPullRequestActionRunsFn() returned error result: %+v", result)
|
||||
}
|
||||
|
||||
if gotRunsQuery == "" {
|
||||
t.Fatalf("expected actions/runs to be called")
|
||||
}
|
||||
values, err := url.ParseQuery(gotRunsQuery)
|
||||
if err != nil {
|
||||
t.Fatalf("parse actions/runs query: %v", err)
|
||||
}
|
||||
if got := values.Get("head_sha"); got != headSHA {
|
||||
t.Fatalf("actions/runs head_sha = %q, want %q", got, headSHA)
|
||||
}
|
||||
|
||||
if len(result.Content) == 0 {
|
||||
t.Fatalf("expected content in result")
|
||||
}
|
||||
textContent, ok := result.Content[0].(*mcp.TextContent)
|
||||
if !ok {
|
||||
t.Fatalf("expected text content, got %T", result.Content[0])
|
||||
}
|
||||
|
||||
var parsed struct {
|
||||
WorkflowRuns []map[string]any `json:"workflow_runs"`
|
||||
}
|
||||
if err := json.Unmarshal([]byte(textContent.Text), &parsed); err != nil {
|
||||
t.Fatalf("unmarshal result text: %v", err)
|
||||
}
|
||||
if len(parsed.WorkflowRuns) != 1 {
|
||||
t.Fatalf("expected 1 run, got %d", len(parsed.WorkflowRuns))
|
||||
}
|
||||
if got := parsed.WorkflowRuns[0]["name"]; got != "CI" {
|
||||
t.Fatalf("run name = %v, want %q", got, "CI")
|
||||
}
|
||||
}
|
||||
@@ -29,15 +29,16 @@ var (
|
||||
ActionsRunReadToolName,
|
||||
"Read Actions workflows, runs, jobs, logs, and artifacts.",
|
||||
annotation.ReadOnly("Read Actions workflow, run, job, and artifact data"),
|
||||
tool.String("method", tool.Required(), tool.Enum("list_workflows", "get_workflow", "list_runs", "get_run", "list_jobs", "list_run_jobs", "get_job", "get_job_log_preview", "download_job_log", "list_artifacts", "list_run_artifacts", "get_artifact", "download_artifact")),
|
||||
tool.String("method", tool.Required(), tool.Enum("list_workflows", "get_workflow", "list_runs", "get_run", "list_pr_runs", "list_jobs", "list_run_jobs", "get_job", "get_job_log_preview", "download_job_log", "list_artifacts", "list_run_artifacts", "get_artifact", "download_artifact")),
|
||||
tool.String("owner", tool.Required(), tool.Description(params.OwnerDesc)),
|
||||
tool.String("repo", tool.Required(), tool.Description(params.RepoDesc)),
|
||||
tool.String("workflow_id", tool.Description("ID or filename (for 'get_workflow')")),
|
||||
tool.Number("run_id", tool.Description("for 'get_run'/'list_run_jobs'/'list_run_artifacts'")),
|
||||
tool.Number("pull_number", tool.Description("pull request number (for 'list_pr_runs')")),
|
||||
tool.Number("job_id", tool.Description("for 'get_job'/log methods")),
|
||||
tool.Number("artifact_id", tool.Description("for 'get_artifact'/'download_artifact'")),
|
||||
tool.String("artifact_name", tool.Description("name filter for 'list_artifacts'/'list_run_artifacts'")),
|
||||
tool.String("status", tool.Description("filter for 'list_runs'/'list_jobs'")),
|
||||
tool.String("status", tool.Description("filter for 'list_runs'/'list_pr_runs'/'list_jobs'")),
|
||||
tool.Number("tail_lines", tool.Description("log tail lines"), tool.Default(200), tool.Minimum(1)),
|
||||
tool.Number("max_bytes", tool.Description("max log bytes"), tool.Default(65536), tool.Minimum(1024)),
|
||||
tool.String("output_path", tool.Description("for 'download_job_log'/'download_artifact'")),
|
||||
@@ -78,6 +79,8 @@ func runReadFn(ctx context.Context, args map[string]any) (*mcp.CallToolResult, e
|
||||
return listRepoActionRunsFn(ctx, args)
|
||||
case "get_run":
|
||||
return getRepoActionRunFn(ctx, args)
|
||||
case "list_pr_runs":
|
||||
return listPullRequestActionRunsFn(ctx, args)
|
||||
case "list_jobs":
|
||||
return listRepoActionJobsFn(ctx, args)
|
||||
case "list_run_jobs":
|
||||
@@ -297,6 +300,61 @@ func getRepoActionRunFn(ctx context.Context, args map[string]any) (*mcp.CallTool
|
||||
return to.TextResult(slimActionRun(result))
|
||||
}
|
||||
|
||||
func listPullRequestActionRunsFn(ctx context.Context, args map[string]any) (*mcp.CallToolResult, error) {
|
||||
owner, err := params.GetString(args, "owner")
|
||||
if err != nil {
|
||||
return to.ErrorResult(err)
|
||||
}
|
||||
repo, err := params.GetString(args, "repo")
|
||||
if err != nil {
|
||||
return to.ErrorResult(err)
|
||||
}
|
||||
pullNumber, err := params.GetIndex(args, "pull_number")
|
||||
if err != nil || pullNumber <= 0 {
|
||||
return to.ErrorResult(errors.New("pull_number is required"))
|
||||
}
|
||||
page, pageSize := params.GetPagination(args, 30)
|
||||
statusFilter, _ := args["status"].(string)
|
||||
|
||||
var pull struct {
|
||||
Head struct {
|
||||
SHA string `json:"sha"`
|
||||
} `json:"head"`
|
||||
}
|
||||
err = doJSONWithFallback(ctx, "GET",
|
||||
[]string{
|
||||
fmt.Sprintf("repos/%s/%s/pulls/%d", url.PathEscape(owner), url.PathEscape(repo), pullNumber),
|
||||
},
|
||||
nil, nil, &pull,
|
||||
)
|
||||
if err != nil {
|
||||
return to.ErrorResult(fmt.Errorf("get pull request err: %v", err))
|
||||
}
|
||||
if pull.Head.SHA == "" {
|
||||
return to.ErrorResult(fmt.Errorf("pull request %d has no head sha", pullNumber))
|
||||
}
|
||||
|
||||
query := url.Values{}
|
||||
query.Set("head_sha", pull.Head.SHA)
|
||||
query.Set("page", strconv.Itoa(page))
|
||||
query.Set("limit", strconv.Itoa(pageSize))
|
||||
if statusFilter != "" {
|
||||
query.Set("status", statusFilter)
|
||||
}
|
||||
|
||||
var result any
|
||||
err = doJSONWithFallback(ctx, "GET",
|
||||
[]string{
|
||||
fmt.Sprintf("repos/%s/%s/actions/runs", url.PathEscape(owner), url.PathEscape(repo)),
|
||||
},
|
||||
query, nil, &result,
|
||||
)
|
||||
if err != nil {
|
||||
return to.ErrorResult(fmt.Errorf("list pull request action runs err: %v", err))
|
||||
}
|
||||
return to.TextResult(slimActionRuns(result))
|
||||
}
|
||||
|
||||
func cancelRepoActionRunFn(ctx context.Context, args map[string]any) (*mcp.CallToolResult, error) {
|
||||
owner, err := params.GetString(args, "owner")
|
||||
if err != nil {
|
||||
|
||||
@@ -1,7 +1,5 @@
|
||||
package flag
|
||||
|
||||
import "net/http"
|
||||
|
||||
var (
|
||||
Host string
|
||||
Bind string
|
||||
@@ -17,5 +15,4 @@ var (
|
||||
Debug bool
|
||||
AllowedTools map[string]struct{}
|
||||
AllowedScopes map[string]struct{}
|
||||
ExtraHeaders http.Header
|
||||
)
|
||||
|
||||
+1
-27
@@ -30,32 +30,6 @@ func sharedTransport() *http.Transport {
|
||||
return sharedTrans
|
||||
}
|
||||
|
||||
// extraHeaderTransport injects flag.ExtraHeaders into every request, without
|
||||
// overriding headers the caller already set (e.g. Authorization, Content-Type,
|
||||
// Accept). It reads flag.ExtraHeaders on each round trip rather than caching
|
||||
// it, so tests can change it between requests.
|
||||
type extraHeaderTransport struct {
|
||||
base http.RoundTripper
|
||||
}
|
||||
|
||||
func (t *extraHeaderTransport) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||
headers := flag.ExtraHeaders
|
||||
if len(headers) == 0 {
|
||||
return t.base.RoundTrip(req)
|
||||
}
|
||||
cloned := req.Clone(req.Context())
|
||||
for name, values := range headers {
|
||||
if cloned.Header.Get(name) == "" {
|
||||
cloned.Header[name] = values
|
||||
}
|
||||
}
|
||||
return t.base.RoundTrip(cloned)
|
||||
}
|
||||
|
||||
func giteaTransport() http.RoundTripper {
|
||||
return &extraHeaderTransport{base: sharedTransport()}
|
||||
}
|
||||
|
||||
// NewClient returns a cached *gitea.Client keyed by host+token. The SDK's per-client
|
||||
// version cache and the shared transport let us reuse keep-alive connections
|
||||
// and avoid the SDK's /api/v1/version preflight on every tool call.
|
||||
@@ -66,7 +40,7 @@ func NewClient(token string) (*gitea.Client, error) {
|
||||
}
|
||||
|
||||
httpClient := &http.Client{
|
||||
Transport: giteaTransport(),
|
||||
Transport: sharedTransport(),
|
||||
CheckRedirect: checkRedirect,
|
||||
}
|
||||
opts := []gitea.ClientOption{
|
||||
|
||||
@@ -1,49 +0,0 @@
|
||||
package gitea
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"gitea.com/gitea/gitea-mcp/pkg/flag"
|
||||
)
|
||||
|
||||
func TestNewClient_SendsExtraHeaders(t *testing.T) {
|
||||
var gotClientID, gotAuthorization string
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
gotClientID = r.Header.Get("CF-Access-Client-Id")
|
||||
gotAuthorization = r.Header.Get("Authorization")
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = w.Write([]byte(`{"login":"octocat"}`))
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
origHost := flag.Host
|
||||
origExtraHeaders := flag.ExtraHeaders
|
||||
defer func() {
|
||||
flag.Host = origHost
|
||||
flag.ExtraHeaders = origExtraHeaders
|
||||
}()
|
||||
flag.Host = srv.URL
|
||||
flag.ExtraHeaders = http.Header{
|
||||
"Cf-Access-Client-Id": []string{"client-id"},
|
||||
"Authorization": []string{"should-not-override"},
|
||||
}
|
||||
|
||||
client, err := NewClient("the-token")
|
||||
if err != nil {
|
||||
t.Fatalf("NewClient returned error: %v", err)
|
||||
}
|
||||
if _, _, err := client.Users.GetMyUserInfo(context.Background()); err != nil {
|
||||
t.Fatalf("GetMyUserInfo returned error: %v", err)
|
||||
}
|
||||
|
||||
if gotClientID != "client-id" {
|
||||
t.Fatalf("CF-Access-Client-Id header = %q, want %q", gotClientID, "client-id")
|
||||
}
|
||||
if gotAuthorization != "token the-token" {
|
||||
t.Fatalf("Authorization header = %q, want %q", gotAuthorization, "token the-token")
|
||||
}
|
||||
}
|
||||
+2
-2
@@ -59,7 +59,7 @@ var (
|
||||
func restHTTPClient() *http.Client {
|
||||
restClientOnce.Do(func() {
|
||||
restClient = &http.Client{
|
||||
Transport: giteaTransport(),
|
||||
Transport: sharedTransport(),
|
||||
Timeout: httpClientTimeout,
|
||||
CheckRedirect: checkRedirect,
|
||||
}
|
||||
@@ -180,7 +180,7 @@ func DoJSON(ctx context.Context, method, path string, query url.Values, body, re
|
||||
|
||||
func attachmentHTTPClient(origin *url.URL) *http.Client {
|
||||
return &http.Client{
|
||||
Transport: giteaTransport(),
|
||||
Transport: sharedTransport(),
|
||||
CheckRedirect: func(req *http.Request, via []*http.Request) error {
|
||||
if err := checkRedirect(req, via); err != nil {
|
||||
return err
|
||||
|
||||
@@ -62,44 +62,3 @@ func TestDoJSON_LimitsErrorResponseBody(t *testing.T) {
|
||||
t.Fatalf("expected body length %d, got %d", errBodySnippetSize, len(httpErr.Body))
|
||||
}
|
||||
}
|
||||
|
||||
func TestDoJSON_SendsExtraHeaders(t *testing.T) {
|
||||
var gotClientID, gotAuthorization string
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
gotClientID = r.Header.Get("CF-Access-Client-Id")
|
||||
gotAuthorization = r.Header.Get("Authorization")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = io.WriteString(w, "{}")
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
origHost := flag.Host
|
||||
origToken := flag.Token
|
||||
origExtraHeaders := flag.ExtraHeaders
|
||||
defer func() {
|
||||
flag.Host = origHost
|
||||
flag.Token = origToken
|
||||
flag.ExtraHeaders = origExtraHeaders
|
||||
}()
|
||||
flag.Host = srv.URL
|
||||
flag.Token = "the-token"
|
||||
flag.ExtraHeaders = http.Header{
|
||||
"Cf-Access-Client-Id": []string{"client-id"},
|
||||
"Authorization": []string{"should-not-override"},
|
||||
}
|
||||
|
||||
var out map[string]any
|
||||
status, err := DoJSON(context.Background(), http.MethodGet, "repos/owner/repo", nil, nil, &out)
|
||||
if err != nil {
|
||||
t.Fatalf("DoJSON returned error: %v", err)
|
||||
}
|
||||
if status != http.StatusOK {
|
||||
t.Fatalf("expected status %d, got %d", http.StatusOK, status)
|
||||
}
|
||||
if gotClientID != "client-id" {
|
||||
t.Fatalf("CF-Access-Client-Id header = %q, want %q", gotClientID, "client-id")
|
||||
}
|
||||
if gotAuthorization != "token the-token" {
|
||||
t.Fatalf("Authorization header = %q, want %q", gotAuthorization, "token the-token")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user