## Summary epic r04 - begin refactor ## Change Type - [x] Cowork feature - [ ] Bug fix - [ ] Core AI contribution - [ ] Test / hardening - [ ] Performance - [ ] Documentation ## Related Work Cowork Task: Core Repo: http://34.143.229.138/gitea-admin/fsg-ai-core-assets Core AI Issue: Core Task: Related PR: ## Scope What is intentionally included? What is intentionally NOT included? ## Validation - [ ] Unit tests - [ ] Integration tests - [ ] Manual verification - [ ] Regression check Commands / evidence: ## Security Impact Permission / credential / network / customer data impact: ## Compatibility - [ ] No breaking change - [ ] Breaking change documented ## Reviewer Notes Anything Cowork reviewers should pay attention to. --------- Co-authored-by: Anh Tran Nguyen Minh <anhtnm1@fpt.com> Co-authored-by: Huong Le Thi Thien <huongltt35@fpt.com> Co-authored-by: Nam Pham Dinh Thanh <nampdt@fpt.com> Co-authored-by: Vu Dam Tuan <vudt15@fpt.com> Co-authored-by: Hiep Ha Van <hiephv3@fpt.com> Co-authored-by: Lam Hoang Van <lamhv7@fpt.com> Reviewed-on: #7 Co-authored-by: Duy Le Huu <duylh19@fpt.com>
This commit was merged in pull request #7.
This commit is contained in:
@@ -31,6 +31,9 @@ class ProjectScopePolicy:
|
||||
"""Pilot policy: read scope and exact identity-bound project are both mandatory."""
|
||||
|
||||
def decide(self, identity: IdentityContext, tool_name: str, project_id: str) -> bool:
|
||||
"""Chỉ cho phép khi danh tính có phạm vi ``read`` VÀ project khớp đúng
|
||||
project gắn với danh tính đó — không cho đọc chéo project.
|
||||
"""
|
||||
return "read" in identity.granted_scopes and project_id == identity.project
|
||||
|
||||
|
||||
@@ -43,7 +46,11 @@ PROVIDER_FACTORIES: dict[str, Callable[[IdentityContext], Any]] = {
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class ProjectProviderResolver:
|
||||
"""Tra provider thật cho từng tool theo bảng ``PROVIDER_FACTORIES``."""
|
||||
def resolve(self, identity: IdentityContext, tool_name: str) -> Any:
|
||||
"""Dựng provider cho một tool; tool chưa đăng ký thì báo ``NOT_FOUND`` và
|
||||
không cho thử lại.
|
||||
"""
|
||||
factory = PROVIDER_FACTORIES.get(tool_name)
|
||||
if factory is None:
|
||||
raise ProviderError("NOT_FOUND", "The requested tool is not registered.", retryable=False)
|
||||
@@ -51,6 +58,11 @@ class ProjectProviderResolver:
|
||||
|
||||
|
||||
def _required_environment(name: str) -> str:
|
||||
"""Đọc một biến môi trường bắt buộc; thiếu thì dừng ngay lúc khởi động.
|
||||
|
||||
Thà không chạy còn hơn chạy với cấu hình khuyết rồi lỗi giữa chừng ở một
|
||||
lượt gọi tool nào đó.
|
||||
"""
|
||||
value = os.environ.get(name, "").strip()
|
||||
if not value:
|
||||
raise RuntimeError(f"Project Context MCP cannot start: required setting {name} is missing")
|
||||
|
||||
Reference in New Issue
Block a user