Commit Graph
161 Commits
Author SHA1 Message Date
Chris CoutinhoandGitHub 8ac20a0bcd Merge pull request #899 from cbcoutinho/renovate/nextcloud-33-33.0.5
chore(deps): update nextcloud-33:33.0.5 docker digest to fe5166b
2026-06-18 18:01:38 +02:00
renovate-bot-cbcoutinho[bot]andGitHub fdf6c15c64 chore(deps): update nextcloud-33:33.0.5 docker digest to fe5166b 2026-06-18 04:27:00 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 5a583868a9 chore(deps): update nextcloud-32:32.0.11 docker digest to adf183b 2026-06-18 04:26:54 +00:00
Chris CoutinhoandClaude Opus 4.8 ec15cad234 ci: drop deprecated NC31 from matrix, enable NC33, stage NC34
Nextcloud 31 reached deprecation (02/2026), so remove it from the integration
matrix. Enable NC33 (previously disabled pending upstream app support) and add
NC34 as a commented, ready-to-enable entry.

- test.yml: nextcloud_version is now [32, 33]; 34 commented. Image pins updated
  to match (32.0.11, 33.0.5 active; 34.0.0 commented). The Renovate customManager
  regex already tracks commented entries, so 34 is digest-managed once present.
- renovate.json: drop the nextcloud-31 pin rule, add nextcloud-34 (/^34\./).

docker-compose.yml already defaults to 32.0.11 (Renovate-pinned to 32.x), so no
change there — the NC31 seen in local runs comes from a shell-exported
NEXTCLOUD_IMAGE override, not the compose default.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-18 01:23:52 +02:00
Chris CoutinhoandGitHub 86ed15f466 Merge pull request #668 from cbcoutinho/renovate/astral-sh-setup-uv-8.x
chore(deps): update astral-sh/setup-uv action to v8
2026-06-10 08:57:39 +02:00
Chris CoutinhoandGitHub 6454c6cc77 Merge pull request #605 from cbcoutinho/renovate/major-github-artifact-actions
chore(deps): update github artifact actions (major)
2026-06-09 08:11:01 +02:00
Chris CoutinhoandGitHub d903f233d2 Merge pull request #869 from cbcoutinho/renovate/nextcloud-33-33.0.5
chore(deps): update nextcloud-33:33.0.5 docker digest to 56bdc45
2026-06-09 06:56:33 +02:00
renovate-bot-cbcoutinho[bot]andGitHub e854840c77 chore(deps): update github artifact actions 2026-06-09 04:21:19 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 3aba38f1ef chore(deps): update astral-sh/setup-uv action to v8 2026-06-09 04:21:05 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 219ef89b93 chore(deps): update shivammathur/setup-php action to v2.37.2 2026-06-09 04:20:51 +00:00
Chris CoutinhoandClaude Opus 4.8 62274069de refactor(documents): fully decouple document stack from server startup; Windows-safe tests
Addresses round-1 review on #878:

- Move the eager `document_processors` imports out of the API startup graph:
  `app.py` (get_registry now imported inside initialize_document_processors,
  after the disabled early-return) and `vector/processor.py` (get_registry now
  imported at its single use site). Importing `app` + `cli` no longer loads
  `document_processors` / `_isolation` at all -- the #877 stack is fully out of
  startup (pymupdf still loads via search/pdf_highlighter, a Windows-compatible
  and separately-tracked concern).
- Make `tests/unit/test_pdf_parse_isolation.py` importable on Windows: guard the
  top-level `import resource` with try/except and skip the three rlimit
  computation tests via a `requires_resource` marker when the module is absent.
  The Windows no-op / import-guard tests don't use the real module and still run.
- Fix the `# pragma: no cover` comment on the win32 branch to be accurate.
- Add `enable-cache: true` to the package-smoke setup-uv step.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 15:11:18 +02:00
Chris CoutinhoandClaude Opus 4.8 fc8a4e4dfa fix(documents): guard Unix-only resource import for Windows (#877)
`document_processors/_isolation.py` did an unconditional module-level
`import resource`, a POSIX-only stdlib module absent on Windows. It was
pulled into the API startup path via
`server/webdav.py -> utils/document_parser -> document_processors`, so
the MCP server failed to start on Windows since 0.101.2 with
`ModuleNotFoundError: No module named 'resource'`.

- Guard the import behind `sys.platform`; bind `resource = None` on
  win32. `_apply_mem_limit()` degrades to a logged no-op when the module
  is unavailable (the RLIMIT_AS cap is a Linux-pod safety measure, not a
  correctness requirement).
- Make the document-parser import in `server/webdav.py` lazy so server
  startup never loads the ingest document stack
  (document_processors -> pymupdf -> _isolation) at all -- it is only
  needed when a file is actually read and parsed. This both fixes #877
  and decouples the API layer from ingest-only deps.
- Add unit regressions for the no-op path and the win32 import guard.
- Add a cross-platform `package-smoke` CI job (ubuntu + windows) that
  installs the package isolated and runs the CLI, exercising the
  cli -> server -> webdav import chain that crashed in #877.

Fixes #877

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 14:59:03 +02:00
renovate-bot-cbcoutinho[bot]andGitHub 8eaf46e7be chore(deps): update nextcloud-33:33.0.5 docker digest to 56bdc45 2026-06-07 04:14:18 +00:00
renovate-bot-cbcoutinho[bot]andGitHub faefd46b49 chore(deps): update nextcloud-33:33.0.5 docker digest to 96f8b6a 2026-06-06 04:23:20 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 157b1bb9d3 chore(deps): update hoverkraft-tech/compose-action action to v3 2026-06-05 00:36:32 +00:00
Chris CoutinhoandGitHub c3684f8558 Merge pull request #838 from cbcoutinho/renovate/actions-checkout-6.x
chore(deps): update actions/checkout action to v6.0.3
2026-06-05 01:55:07 +02:00
Chris CoutinhoandGitHub ec9c6b01f8 Merge pull request #846 from cbcoutinho/renovate/nextcloud-32-32.x
chore(deps): update nextcloud-32 docker tag to v32.0.11
2026-06-05 01:54:11 +02:00
renovate-bot-cbcoutinho[bot]andGitHub 085971f54a chore(deps): update nextcloud-33 docker tag to v33.0.5 2026-06-04 04:32:09 +00:00
renovate-bot-cbcoutinho[bot]andGitHub db0c7345a2 chore(deps): update nextcloud-32 docker tag to v32.0.11 2026-06-04 04:32:01 +00:00
renovate-bot-cbcoutinho[bot]andGitHub eed90bdb9b chore(deps): update actions/checkout action to v6.0.3 2026-06-03 04:20:33 +00:00
Chris CoutinhoandGitHub b91af923d2 Merge pull request #609 from cbcoutinho/renovate/actions-setup-node-6.x
chore(deps): update actions/setup-node action to v6
2026-06-03 02:30:36 +02:00
Chris CoutinhoandGitHub e7b1606631 Merge pull request #631 from cbcoutinho/renovate/shivammathur-setup-php-2.x
chore(deps): update shivammathur/setup-php action to v2.37.1
2026-06-03 02:27:47 +02:00
Chris CoutinhoandGitHub 7cf55ad903 Merge pull request #713 from cbcoutinho/renovate/hoverkraft-tech-compose-action-2.x
chore(deps): update hoverkraft-tech/compose-action action to v2.6.0
2026-06-03 02:26:36 +02:00
Chris CoutinhoandGitHub 580ff088e1 Merge pull request #816 from cbcoutinho/renovate/nextcloud-32-32.x
chore(deps): update nextcloud-32 docker tag to v32.0.10
2026-05-31 13:41:52 +02:00
renovate-bot-cbcoutinho[bot]andGitHub 076ec91981 chore(deps): update nextcloud-33 docker tag to v33.0.4 2026-05-30 04:29:01 +00:00
renovate-bot-cbcoutinho[bot]andGitHub f00b0b8e19 chore(deps): update nextcloud-32 docker tag to v32.0.10 2026-05-30 04:28:54 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 475d7bd568 chore(deps): update nextcloud-32:32.0.9 docker digest to a6faf7f 2026-05-24 04:32:27 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 246f3b734c chore(deps): update shivammathur/setup-php action to v2.37.1 2026-05-15 04:27:34 +00:00
Chris CoutinhoandGitHub 2d29b3801c Merge pull request #770 from cbcoutinho/renovate/nextcloud-32-32.0.9
chore(deps): update nextcloud-32:32.0.9 docker digest to 6052173
2026-05-10 17:56:59 +02:00
renovate-bot-cbcoutinho[bot]andGitHub 4b0a556750 chore(deps): update nextcloud-33:33.0.3 docker digest to 90a730e 2026-05-09 16:21:38 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 4774af1b69 chore(deps): update nextcloud-32:32.0.9 docker digest to 6052173 2026-05-09 16:21:32 +00:00
Chris CoutinhoandClaude Opus 4.7 4c84d82984 fix(auth): address PR #758 auto-review (id-token verify, nonce, CI key)
Blocking:
- AS proxy callback now calls verify_id_token before caching the proxy
  code so a tampered IdP response can't smuggle identity claims.

Important:
- Browser OAuth flow generates and verifies an OIDC nonce; new alembic
  migration 006 adds the nonce column to oauth_sessions.
- _origin_matches_self logs a warning when CSRF check is bypassed.
- oauth_tools.py uses get_shared_storage instead of fresh handles.

Nits:
- New token_utils.get_oidc_discovery shares the 5-minute cache with
  verify_id_token; oauth_login (integrated) and _revoke_refresh_token_at_idp
  now use it instead of issuing fresh discovery fetches.
- Drop typing.Optional from oauth_tools.py in favour of X | None.

CI:
- test.yml generates an ephemeral Fernet TOKEN_ENCRYPTION_KEY per run
  with openssl, removing the dependency on a missing repo secret.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-02 20:48:25 +02:00
Chris CoutinhoandClaude Opus 4.7 2ef4bfc4af fix(auth): fail closed on missing sub claim, delete Flow 2 callback session
Addresses the two remaining 🟡 findings from the PR #758 follow-up review:

  1. extract_user_id_from_token previously fell back to "default_user" when
     the verified access token had no sub claim. In a multi-tenant deployment
     a malformed IdP token could have bucketed every request under a single
     sentinel user, risking cross-tenant data exposure. The function now
     raises McpError on that branch; the BasicAuth no-token sentinel path is
     preserved.

  2. oauth_callback_nextcloud (Flow 2) read the PKCE code_verifier from
     oauth_sessions but never deleted the row, leaving the verifier valid for
     the full 10-minute TTL. The row is now deleted eagerly inside the same
     branch, mirroring oauth_login_callback in browser_oauth_routes.

Also wires TOKEN_ENCRYPTION_KEY through the docker-compose step in the CI
test workflow so the integration matrix can boot — every job had been
failing fast on the ${TOKEN_ENCRYPTION_KEY:?...} interpolation guard added
in PR #758 finding 5.

Tests pin both fixes (test_token_utils_user_id.py,
test_oauth_callback_session_cleanup.py).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-02 19:46:36 +02:00
Chris CoutinhoandGitHub 83f2e88d2c Merge pull request #755 from cbcoutinho/renovate/nextcloud-32-32.x
chore(deps): update nextcloud-32 docker tag to v32.0.9
2026-05-02 16:13:29 +02:00
renovate-bot-cbcoutinho[bot]andGitHub 774e6a119f chore(deps): update nextcloud-33 docker tag to v33.0.3 2026-05-02 04:23:08 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 9461bf2897 chore(deps): update nextcloud-32 docker tag to v32.0.9 2026-05-02 04:23:01 +00:00
renovate-bot-cbcoutinho[bot]andGitHub a3934535bf chore(deps): update nextcloud-32:32.0.8 docker digest to 334f45c 2026-04-27 04:21:29 +00:00
renovate-bot-cbcoutinho[bot]andGitHub d765067a27 chore(deps): update actions/setup-node action to v6 2026-04-20 04:16:51 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 310f0d1112 chore(deps): update hoverkraft-tech/compose-action action to v2.6.0 2026-04-17 04:18:35 +00:00
Chris CoutinhoandGitHub d7653535f0 Merge pull request #658 from cbcoutinho/renovate/nextcloud-31-31.0.14
chore(deps): update nextcloud-31:31.0.14 docker digest to 07ec73c
2026-04-07 17:10:32 +02:00
Chris CoutinhoandGitHub cc40f8f916 Merge pull request #661 from cbcoutinho/renovate/nextcloud-32-32.x
chore(deps): update nextcloud-32 docker tag to v32.0.8
2026-04-07 12:42:17 +02:00
renovate-bot-cbcoutinho[bot]andGitHub be4aeeb1d5 chore(deps): update nextcloud-33 docker tag to v33.0.2 2026-04-07 10:19:32 +00:00
renovate-bot-cbcoutinho[bot]andGitHub a82491de15 chore(deps): update nextcloud-32 docker tag to v32.0.8 2026-04-07 10:19:27 +00:00
Chris CoutinhoandClaude Opus 4.6 7d775d2a52 refactor: remove ALLOWED_MCP_CLOUD_CLIENTS and add keycloak CI profile
Remove the unused ALLOWED_MCP_CLOUD_CLIENTS env var — all clients are
defined via ALLOWED_MCP_CLIENTS or the static well-known defaults.
Add keycloak as an integration test profile in CI now that login-flow
replaces the old bearer token approach for external IdPs.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-05 15:06:56 +02:00
Chris CoutinhoandClaude Opus 4.6 aeddc28ca6 refactor: remove oauth profile, migrate MCP/OAuth tests to login-flow
Remove the oauth Docker Compose profile (mcp-oauth service, port 8001)
which used OAuth bearer tokens for direct NC API access, requiring
upstream OIDC patches. All NC access should use app passwords via
Login Flow v2 or BasicAuth.

Changes:
- Remove mcp-oauth service from docker-compose.yml
- Remove oauth mode from CI test matrix
- Delete oauth pass-through tests (core, permissions, token exchange)
- Delete oauth-specific tests (elicitation, NC PHP app, astrolabe)
- Migrate MCP/OAuth integration tests to login-flow profile:
  - DCR lifecycle, deletion, token type tests
  - Scope authorization (tool filtering) tests
  - Token introspection tests
- Fix flaky consent screen automation: replace JS btn.click() with
  Playwright native click + retry (handles Vue.js event binding race)
- Add scope-filtered OAuth client fixtures to login-flow conftest
- Keep keycloak profile for external IdP testing

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 16:05:14 +02:00
Chris CoutinhoandClaude Opus 4.6 fe8799a133 fix: resolve OAuth compatibility issues for login-flow deployment
- Drop OIDC fork: comment out third_party/oidc mount, use upstream
  v1.16.3 from app store (fixes consent redirect race, PR #631)
- Support client_secret_basic auth: add _extract_basic_auth() helper
  so TS MCP SDK can authenticate at token endpoint (RFC 6749 §2.3.1)
- Multi-issuer JWT validation: accept tokens with internal Docker
  issuer (http://app:80) or public URL (NEXTCLOUD_PUBLIC_ISSUER_URL)
  since AS proxy obtains tokens server-to-server
- Introspection fallback: try token introspection when JWT verification
  fails, supporting both JWT and opaque token types
- Register all tool scopes in DCR: add semantic:read, collectives:read,
  collectives:write to OIDC client allowed_scopes so tokens include
  them and semantic search tools are visible to authenticated clients
- Auto-create Astrolabe OAuth client: new app-hook creates OIDC client
  and stores credentials in config.php so the "Authorize via OAuth"
  button works without manual setup

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-29 15:05:26 +02:00
renovate-bot-cbcoutinho[bot]andGitHub 4354ee7270 chore(deps): update nextcloud-33 docker tag to v33.0.1 2026-03-28 11:20:49 +00:00
renovate-bot-cbcoutinho[bot]andGitHub 5d380f9819 chore(deps): update nextcloud-31:31.0.14 docker digest to 07ec73c 2026-03-28 10:13:40 +00:00
Chris CoutinhoandClaude Opus 4.6 1482d2d43d fix: pin Renovate Nextcloud updates to matching major version
The custom regex manager matched all nextcloud_image entries with the
same depName, causing Renovate to bump all matrix entries (NC 31, 32, 33)
to the latest version instead of only the targeted major.

Fix by capturing nextcloud_version to create version-specific dep names
(nextcloud-31, nextcloud-32, nextcloud-33) with allowedVersions rules
constraining each to its own major. Also pins docker-compose.yml to 32.x
and removes redundant inline # renovate: comments that could cause
duplicate matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-28 10:48:55 +01:00
Chris CoutinhoandClaude Opus 4.6 ad4ceaff30 fix: resolve OIDC consent flow 500 errors on NC 32
Root cause: ConsentController::grant() only passed client_id and scope
in the post-consent redirect, relying on PHP session fallback for state,
response_type, redirect_uri etc. On NC 32 (PHP 8.4), session values
were intermittently lost between session->close() and the subsequent GET
request, causing 500 errors from trim(null) / matchRedirectUri(null).

OIDC app fixes:
- Pass all OAuth params in consent redirect URL (eliminates session race)
- Add null safety guard in authorize endpoint (400 instead of 500)

Test infra fixes:
- Wait for OIDC redirect chain to settle before handling consent screen
  (fixes "Execution context was destroyed" Playwright errors)
- Capture nextcloud.log in CI failure artifacts for PHP error debugging

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-18 16:47:20 +01:00