feat: serve workspace MCP over the web app HTTP endpoint

This commit is contained in:
2026-10-07 20:46:08 +09:00
parent e917cafd88
commit f41d0c1964
18 changed files with 1004 additions and 145 deletions
+17 -1
View File
@@ -7,6 +7,22 @@ const health = createMiddleware().server(({ request, next }) => {
return next();
});
// Private MCP clients do not carry a browser session or Tailscale identity.
// Keep this exact endpoint ahead of browser-only access checks.
const mcp = createMiddleware().server(async ({ request, next }) => {
const path = new URL(request.url).pathname;
// Explicitly report that this private endpoint does not advertise OAuth.
if (
["/.well-known/oauth-protected-resource", "/.well-known/oauth-protected-resource/mcp"].includes(
path,
)
)
return new Response(null, { status: 404 });
if (path !== "/mcp") return next();
const { handleMcpRequest } = await import("./features/mcp/http.server");
return handleMcpRequest(request);
});
const ownerAccess = createMiddleware().server(async ({ request, next }) => {
const { checkAccess, readAccessConfig } = await import("./features/access/policy.server");
return checkAccess(request, readAccessConfig()) ?? next();
@@ -30,5 +46,5 @@ const storage = createMiddleware().server(async ({ next }) => {
});
export const startInstance = createStart(() => ({
requestMiddleware: [health, ownerAccess, csrf, storage, appSession],
requestMiddleware: [health, mcp, ownerAccess, csrf, storage, appSession],
}));