-
Notifications
You must be signed in to change notification settings - Fork 357
137 metadata timestamps #776
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Signed-off-by: Mihai Criveti <[email protected]>
Signed-off-by: Mihai Criveti <[email protected]>
Signed-off-by: Mihai Criveti <[email protected]>
Signed-off-by: Mihai Criveti <[email protected]>
Signed-off-by: Madhav Kandukuri <[email protected]>
Signed-off-by: Madhav Kandukuri <[email protected]>
@crivetimihai Need to add similar functionality for main.py update endpoints. But, that can be a separate PR since it won't need any db schema changes. |
rakdutta
pushed a commit
to rakdutta/mcp-context-forge
that referenced
this pull request
Aug 19, 2025
* Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]>
madhav165
added a commit
that referenced
this pull request
Aug 20, 2025
* Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]>
crivetimihai
added a commit
that referenced
this pull request
Aug 20, 2025
…g Implementation (#786) * db.py update Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * revert alembic with main version Signed-off-by: RAKHI DUTTA <[email protected]> * 138 view realtime logs in UI and export logs (CSV, JSON) (#747) * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI readme Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Fix test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 749 reverse proxy (#750) * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * doctest improvements Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * (fix) Added missing prompts/get (#748) Signed-off-by: Ian Molloy <[email protected]> * Adds RPC endpoints and updates RPC response and error handling (#746) * Fix rpc endpoints Signed-off-by: Madhav Kandukuri <[email protected]> * Remove commented code Signed-off-by: Madhav Kandukuri <[email protected]> * remove duplicate code in session registry Signed-off-by: Madhav Kandukuri <[email protected]> * Linting fixes Signed-off-by: Madhav Kandukuri <[email protected]> * Fix tests Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Madhav Kandukuri <[email protected]> * 753 fix tool invocation invalid method (#754) * Fix tool invocation 'Invalid method' error with backward compatibility (#753) - Add backward compatibility for direct tool invocation (pre-PR #746 format) - Support both old format (method=tool_name) and new format (method=tools/call) - Add comprehensive test coverage for RPC tool invocation scenarios - Ensure graceful fallback to gateway forwarding when method is not a tool The RPC endpoint now handles tool invocations in both formats: 1. New format: method='tools/call' with name and arguments in params 2. Old format: method='tool_name' with params as arguments (backward compat) This maintains compatibility with existing clients while supporting the new standardized RPC method structure introduced in PR #746. Signed-off-by: Mihai Criveti <[email protected]> * Fix flake8 E722: Replace bare except with Exception Signed-off-by: Mihai Criveti <[email protected]> * lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: suppress bandit security warnings with appropriate nosec comments (#755) - Added nosec B105 for ENV_TOKEN as it's an environment variable name, not a hardcoded secret - Added nosec B110 for intentional exception swallowing in cleanup/error handling paths - Both cases are legitimate uses where errors should be silently ignored to prevent cascading failures Signed-off-by: Mihai Criveti <[email protected]> * Add agents file Signed-off-by: Mihai Criveti <[email protected]> * pylint (#759) Signed-off-by: Mihai Criveti <[email protected]> * Remove redundant title in readme. (#757) Signed-off-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> * Update documentation with fixed image tag Signed-off-by: Mihai Criveti <[email protected]> * 256 fuzz testing (#760) * Implement comprehensive fuzz testing automation (#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * feat: Bulk Import Tools modal wiring #737 (#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs #737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * Implemented configuration export (#764) Signed-off-by: Mihai Criveti <[email protected]> * 185 186 import export (#769) * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: local network address translation in discovery module (#767) Signed-off-by: Frederico Araujo <[email protected]> * Well known (#770) Signed-off-by: Mihai Criveti <[email protected]> * Update docs with jsonrpc tutorial (#772) Signed-off-by: Mihai Criveti <[email protected]> * 137 metadata timestamps (#776) * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> * feat #262: MCP Langchain Agent (#781) * feat: Add bulk import UI modal for tools Signed-off-by: Vicky <[email protected]> * feat: Add Langchain agent with OpenAI & A2A endpoints (refs #262) Signed-off-by: Vicky <[email protected]> * lint: prettier fix at ~L8090 (insert newline) Signed-off-by: Vicky <[email protected]> --------- Signed-off-by: Vicky <[email protected]> Co-authored-by: Vicky <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Issue 587/rest tool error (#778) * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * Rebase and lint / test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * edit column header (#777) Signed-off-by: Shoumi <[email protected]> * Test case update (#775) * session_registry test case updates Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update for routers/reverse_proxy Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update to mcpgateway/reverse_proxy.py Signed-off-by: Mohan Lakshmaiah <[email protected]> * Fix formatting issues from pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: add plugins cli, external plugin support, plugin template (#722) * feat: add support for external plugins Signed-off-by: Teryl Taylor <[email protected]> * feat(plugins): add external mcp server and associated test cases. Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed yamllint issues Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed flake8 issue. Signed-off-by: Teryl Taylor <[email protected]> * feat: define plugins cli and implement bootstrap command Signed-off-by: Frederico Araujo <[email protected]> * fix: implement install and package CLI commands Signed-off-by: Frederico Araujo <[email protected]> * fix: remote avoid insecure shell=True in subprocess invocation Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: move copier config to repository root Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier template Signed-off-by: Frederico Araujo <[email protected]> * feat: get default author from git config Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier settings Signed-off-by: Frederico Araujo <[email protected]> * fix: copier config syntax Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template modules Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: make template Signed-off-by: Frederico Araujo <[email protected]> * feat: fix template issue Signed-off-by: Frederico Araujo <[email protected]> * fix: toml template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin mcp server initialization Signed-off-by: Frederico Araujo <[email protected]> * feat: init module for plugin framework Signed-off-by: Frederico Araujo <[email protected]> * feat: add chuck runtime and container wrapping Signed-off-by: Frederico Araujo <[email protected]> * fix: makefile template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins config path Signed-off-by: Frederico Araujo <[email protected]> * feat: add .env.template Signed-off-by: Frederico Araujo <[email protected]> * feat: add tools and resources support Signed-off-by: Frederico Araujo <[email protected]> * fix: lint yaml Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanups Signed-off-by: Frederico Araujo <[email protected]> * feat: update manifest.in Signed-off-by: Frederico Araujo <[email protected]> * chore: linting Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin config variable Signed-off-by: Frederico Araujo <[email protected]> * fix(tests): fixed doctests for plugins. Signed-off-by: Teryl Taylor <[email protected]> * refactor: external plugin server and plugin external API Signed-off-by: Frederico Araujo <[email protected]> * docs(plugins): removed subpackages from examples Signed-off-by: Teryl Taylor <[email protected]> * docs: update plugin docs to use public framework API Signed-off-by: Frederico Araujo <[email protected]> * fix(plugin): added resource payloads to base plugin. Signed-off-by: Teryl Taylor <[email protected]> * feat: udpate test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update tempalte makefile Signed-off-by: Frederico Araujo <[email protected]> * feat: add template for native plugin Signed-off-by: Frederico Araujo <[email protected]> * feat: add readme for native template Signed-off-by: Frederico Araujo <[email protected]> * feat: force boostrap to be a subcommnand Signed-off-by: Frederico Araujo <[email protected]> * tests(plugin): added http streamable and error tests. Signed-off-by: Teryl Taylor <[email protected]> * tests: add tests for plugins CLI Signed-off-by: Frederico Araujo <[email protected]> * fix: deprecation warning Signed-off-by: Frederico Araujo <[email protected]> * tests: add CLI tests Signed-off-by: Frederico Araujo <[email protected]> * tests: update plugin cli Signed-off-by: Frederico Araujo <[email protected]> * tests(plugins): added client hook tests for external plugins. Signed-off-by: Teryl Taylor <[email protected]> * chore: update template readmes Signed-off-by: Frederico Araujo <[email protected]> * fix: lint docstrings in cli Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors in docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors Signed-off-by: Frederico Araujo <[email protected]> * tests: add external plugin server tests Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanup Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * tests: fix cli dryrun test Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint issues Signed-off-by: Frederico Araujo <[email protected]> * tests: fix teardown of client http tests Signed-off-by: Frederico Araujo <[email protected]> * tests: skipping flaky tests Signed-off-by: Frederico Araujo <[email protected]> * docs: plugin lifecycle tools Signed-off-by: Frederico Araujo <[email protected]> * docs: add missing plugin lifecycle doc Signed-off-by: Frederico Araujo <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: Experimental Oauth 2.0 support in gateway (#768) * Oauth 2.1 design Signed-off-by: Shamsul Arefin <[email protected]> * oauth 2.0 design Signed-off-by: Shamsul Arefin <[email protected]> * Support for oauth auth type in gateway Signed-off-by: Shamsul Arefin <[email protected]> * Decrypt client secret Signed-off-by: Shamsul Arefin <[email protected]> * authorization code flow, token storage, tool fetching, tool calling with Oauth2.0 Signed-off-by: Shamsul Arefin <[email protected]> * test fixes Signed-off-by: Shamsul Arefin <[email protected]> * 256 fuzz testing (#760) * Implement comprehensive fuzz testing automation (#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * feat: Bulk Import Tools modal wiring #737 (#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs #737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * Implemented configuration export (#764) Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * fixes Signed-off-by: Shamsul Arefin <[email protected]> * ruff fixes Signed-off-by: Shamsul Arefin <[email protected]> * fix flake8 errors Signed-off-by: Shamsul Arefin <[email protected]> * fix eslint errors Signed-off-by: Shamsul Arefin <[email protected]> * aiohttp added in the main dependencies section of pyproject.toml Signed-off-by: Shamsul Arefin <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic multiple heads issue Create merge migration to resolve parallel migration chains: - Main branch migrations (34492f99a0c4) - OAuth branch migrations (add_oauth_tokens_table) This resolves CI/CD test failures caused by Alembic not knowing which migration head to follow during 'alembic upgrade head'. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic migration chain - remove merge migration hack - Remove unnecessary merge migration file (813b45a70b53) - Fix OAuth config migration to follow proper chain (f8c9d3e2a1b4 → 34492f99a0c4) - OAuth tokens migration already correctly follows (add_oauth_tokens_table → f8c9d3e2a1b4) - Now single migration head without parallel branches This eliminates the 'Multiple heads are present' error in CI/CD tests by ensuring migrations follow a linear chain instead of creating parallel migration branches that need artificial merge migrations. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Shamsul Arefin <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Claude <[email protected]> * Fix pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> * 744 annotations (#784) * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: plugins template (#783) * feat: update context forge target in template's project dependencies Signed-off-by: Frederico Araujo <[email protected]> * fix: exclude jinja files from reformatting tabs Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins cli defaults Signed-off-by: Frederico Araujo <[email protected]> * fix: revert formatted Makefile template Signed-off-by: Frederico Araujo <[email protected]> * feat: add optional packages Signed-off-by: Frederico Araujo <[email protected]> * docs: update plugin template docs Signed-off-by: Frederico Araujo <[email protected]> * docs: update template readme Signed-off-by: Frederico Araujo <[email protected]> --------- Signed-off-by: Frederico Araujo <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * web lint Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * pytest fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * flake fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * alembic change Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * remove addtional line Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * Rebase and fix Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: RAKHI DUTTA <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Ian Molloy <[email protected]> Signed-off-by: Madhav Kandukuri <[email protected]> Signed-off-by: Vinod Muthusamy <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Vicky <[email protected]> Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Shoumi <[email protected]> Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> Co-authored-by: RAKHI DUTTA <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: Ian Molloy <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Frederico Araujo <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vicky <[email protected]> Co-authored-by: Veeresh K <[email protected]> Co-authored-by: Shoumi M <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Claude <[email protected]>
vk-playground
pushed a commit
to vk-playground/mcp-context-forge
that referenced
this pull request
Sep 14, 2025
* Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]>
vk-playground
added a commit
to vk-playground/mcp-context-forge
that referenced
this pull request
Sep 14, 2025
…g Implementation (IBM#786) * db.py update Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * revert alembic with main version Signed-off-by: RAKHI DUTTA <[email protected]> * 138 view realtime logs in UI and export logs (CSV, JSON) (IBM#747) * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI readme Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Fix test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 749 reverse proxy (IBM#750) * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * doctest improvements Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * (fix) Added missing prompts/get (IBM#748) Signed-off-by: Ian Molloy <[email protected]> * Adds RPC endpoints and updates RPC response and error handling (IBM#746) * Fix rpc endpoints Signed-off-by: Madhav Kandukuri <[email protected]> * Remove commented code Signed-off-by: Madhav Kandukuri <[email protected]> * remove duplicate code in session registry Signed-off-by: Madhav Kandukuri <[email protected]> * Linting fixes Signed-off-by: Madhav Kandukuri <[email protected]> * Fix tests Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Madhav Kandukuri <[email protected]> * 753 fix tool invocation invalid method (IBM#754) * Fix tool invocation 'Invalid method' error with backward compatibility (IBM#753) - Add backward compatibility for direct tool invocation (pre-PR IBM#746 format) - Support both old format (method=tool_name) and new format (method=tools/call) - Add comprehensive test coverage for RPC tool invocation scenarios - Ensure graceful fallback to gateway forwarding when method is not a tool The RPC endpoint now handles tool invocations in both formats: 1. New format: method='tools/call' with name and arguments in params 2. Old format: method='tool_name' with params as arguments (backward compat) This maintains compatibility with existing clients while supporting the new standardized RPC method structure introduced in PR IBM#746. Signed-off-by: Mihai Criveti <[email protected]> * Fix flake8 E722: Replace bare except with Exception Signed-off-by: Mihai Criveti <[email protected]> * lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: suppress bandit security warnings with appropriate nosec comments (IBM#755) - Added nosec B105 for ENV_TOKEN as it's an environment variable name, not a hardcoded secret - Added nosec B110 for intentional exception swallowing in cleanup/error handling paths - Both cases are legitimate uses where errors should be silently ignored to prevent cascading failures Signed-off-by: Mihai Criveti <[email protected]> * Add agents file Signed-off-by: Mihai Criveti <[email protected]> * pylint (IBM#759) Signed-off-by: Mihai Criveti <[email protected]> * Remove redundant title in readme. (IBM#757) Signed-off-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> * Update documentation with fixed image tag Signed-off-by: Mihai Criveti <[email protected]> * 256 fuzz testing (IBM#760) * Implement comprehensive fuzz testing automation (IBM#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (IBM#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * feat: Bulk Import Tools modal wiring IBM#737 (IBM#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs IBM#737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * Implemented configuration export (IBM#764) Signed-off-by: Mihai Criveti <[email protected]> * 185 186 import export (IBM#769) * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: local network address translation in discovery module (IBM#767) Signed-off-by: Frederico Araujo <[email protected]> * Well known (IBM#770) Signed-off-by: Mihai Criveti <[email protected]> * Update docs with jsonrpc tutorial (IBM#772) Signed-off-by: Mihai Criveti <[email protected]> * 137 metadata timestamps (IBM#776) * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> * feat IBM#262: MCP Langchain Agent (IBM#781) * feat: Add bulk import UI modal for tools Signed-off-by: Vicky <[email protected]> * feat: Add Langchain agent with OpenAI & A2A endpoints (refs IBM#262) Signed-off-by: Vicky <[email protected]> * lint: prettier fix at ~L8090 (insert newline) Signed-off-by: Vicky <[email protected]> --------- Signed-off-by: Vicky <[email protected]> Co-authored-by: Vicky <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Issue 587/rest tool error (IBM#778) * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * Rebase and lint / test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * edit column header (IBM#777) Signed-off-by: Shoumi <[email protected]> * Test case update (IBM#775) * session_registry test case updates Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update for routers/reverse_proxy Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update to mcpgateway/reverse_proxy.py Signed-off-by: Mohan Lakshmaiah <[email protected]> * Fix formatting issues from pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: add plugins cli, external plugin support, plugin template (IBM#722) * feat: add support for external plugins Signed-off-by: Teryl Taylor <[email protected]> * feat(plugins): add external mcp server and associated test cases. Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed yamllint issues Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed flake8 issue. Signed-off-by: Teryl Taylor <[email protected]> * feat: define plugins cli and implement bootstrap command Signed-off-by: Frederico Araujo <[email protected]> * fix: implement install and package CLI commands Signed-off-by: Frederico Araujo <[email protected]> * fix: remote avoid insecure shell=True in subprocess invocation Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: move copier config to repository root Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier template Signed-off-by: Frederico Araujo <[email protected]> * feat: get default author from git config Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier settings Signed-off-by: Frederico Araujo <[email protected]> * fix: copier config syntax Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template modules Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: make template Signed-off-by: Frederico Araujo <[email protected]> * feat: fix template issue Signed-off-by: Frederico Araujo <[email protected]> * fix: toml template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin mcp server initialization Signed-off-by: Frederico Araujo <[email protected]> * feat: init module for plugin framework Signed-off-by: Frederico Araujo <[email protected]> * feat: add chuck runtime and container wrapping Signed-off-by: Frederico Araujo <[email protected]> * fix: makefile template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins config path Signed-off-by: Frederico Araujo <[email protected]> * feat: add .env.template Signed-off-by: Frederico Araujo <[email protected]> * feat: add tools and resources support Signed-off-by: Frederico Araujo <[email protected]> * fix: lint yaml Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanups Signed-off-by: Frederico Araujo <[email protected]> * feat: update manifest.in Signed-off-by: Frederico Araujo <[email protected]> * chore: linting Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin config variable Signed-off-by: Frederico Araujo <[email protected]> * fix(tests): fixed doctests for plugins. Signed-off-by: Teryl Taylor <[email protected]> * refactor: external plugin server and plugin external API Signed-off-by: Frederico Araujo <[email protected]> * docs(plugins): removed subpackages from examples Signed-off-by: Teryl Taylor <[email protected]> * docs: update plugin docs to use public framework API Signed-off-by: Frederico Araujo <[email protected]> * fix(plugin): added resource payloads to base plugin. Signed-off-by: Teryl Taylor <[email protected]> * feat: udpate test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update tempalte makefile Signed-off-by: Frederico Araujo <[email protected]> * feat: add template for native plugin Signed-off-by: Frederico Araujo <[email protected]> * feat: add readme for native template Signed-off-by: Frederico Araujo <[email protected]> * feat: force boostrap to be a subcommnand Signed-off-by: Frederico Araujo <[email protected]> * tests(plugin): added http streamable and error tests. Signed-off-by: Teryl Taylor <[email protected]> * tests: add tests for plugins CLI Signed-off-by: Frederico Araujo <[email protected]> * fix: deprecation warning Signed-off-by: Frederico Araujo <[email protected]> * tests: add CLI tests Signed-off-by: Frederico Araujo <[email protected]> * tests: update plugin cli Signed-off-by: Frederico Araujo <[email protected]> * tests(plugins): added client hook tests for external plugins. Signed-off-by: Teryl Taylor <[email protected]> * chore: update template readmes Signed-off-by: Frederico Araujo <[email protected]> * fix: lint docstrings in cli Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors in docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors Signed-off-by: Frederico Araujo <[email protected]> * tests: add external plugin server tests Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanup Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * tests: fix cli dryrun test Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint issues Signed-off-by: Frederico Araujo <[email protected]> * tests: fix teardown of client http tests Signed-off-by: Frederico Araujo <[email protected]> * tests: skipping flaky tests Signed-off-by: Frederico Araujo <[email protected]> * docs: plugin lifecycle tools Signed-off-by: Frederico Araujo <[email protected]> * docs: add missing plugin lifecycle doc Signed-off-by: Frederico Araujo <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: Experimental Oauth 2.0 support in gateway (IBM#768) * Oauth 2.1 design Signed-off-by: Shamsul Arefin <[email protected]> * oauth 2.0 design Signed-off-by: Shamsul Arefin <[email protected]> * Support for oauth auth type in gateway Signed-off-by: Shamsul Arefin <[email protected]> * Decrypt client secret Signed-off-by: Shamsul Arefin <[email protected]> * authorization code flow, token storage, tool fetching, tool calling with Oauth2.0 Signed-off-by: Shamsul Arefin <[email protected]> * test fixes Signed-off-by: Shamsul Arefin <[email protected]> * 256 fuzz testing (IBM#760) * Implement comprehensive fuzz testing automation (IBM#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (IBM#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * feat: Bulk Import Tools modal wiring IBM#737 (IBM#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs IBM#737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * Implemented configuration export (IBM#764) Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * fixes Signed-off-by: Shamsul Arefin <[email protected]> * ruff fixes Signed-off-by: Shamsul Arefin <[email protected]> * fix flake8 errors Signed-off-by: Shamsul Arefin <[email protected]> * fix eslint errors Signed-off-by: Shamsul Arefin <[email protected]> * aiohttp added in the main dependencies section of pyproject.toml Signed-off-by: Shamsul Arefin <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic multiple heads issue Create merge migration to resolve parallel migration chains: - Main branch migrations (34492f99a0c4) - OAuth branch migrations (add_oauth_tokens_table) This resolves CI/CD test failures caused by Alembic not knowing which migration head to follow during 'alembic upgrade head'. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic migration chain - remove merge migration hack - Remove unnecessary merge migration file (813b45a70b53) - Fix OAuth config migration to follow proper chain (f8c9d3e2a1b4 → 34492f99a0c4) - OAuth tokens migration already correctly follows (add_oauth_tokens_table → f8c9d3e2a1b4) - Now single migration head without parallel branches This eliminates the 'Multiple heads are present' error in CI/CD tests by ensuring migrations follow a linear chain instead of creating parallel migration branches that need artificial merge migrations. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Shamsul Arefin <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Claude <[email protected]> * Fix pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> * 744 annotations (IBM#784) * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: plugins template (IBM#783) * feat: update context forge target in template's project dependencies Signed-off-by: Frederico Araujo <[email protected]> * fix: exclude jinja files from reformatting tabs Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins cli defaults Signed-off-by: Frederico Araujo <[email protected]> * fix: revert formatted Makefile template Signed-off-by: Frederico Araujo <[email protected]> * feat: add optional packages Signed-off-by: Frederico Araujo <[email protected]> * docs: update plugin template docs Signed-off-by: Frederico Araujo <[email protected]> * docs: update template readme Signed-off-by: Frederico Araujo <[email protected]> --------- Signed-off-by: Frederico Araujo <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * web lint Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * pytest fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * flake fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * alembic change Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * remove addtional line Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * Rebase and fix Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: RAKHI DUTTA <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Ian Molloy <[email protected]> Signed-off-by: Madhav Kandukuri <[email protected]> Signed-off-by: Vinod Muthusamy <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Vicky <[email protected]> Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Shoumi <[email protected]> Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> Co-authored-by: RAKHI DUTTA <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: Ian Molloy <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Frederico Araujo <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vicky <[email protected]> Co-authored-by: Veeresh K <[email protected]> Co-authored-by: Shoumi M <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Claude <[email protected]>
vk-playground
pushed a commit
to vk-playground/mcp-context-forge
that referenced
this pull request
Sep 14, 2025
* Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]>
vk-playground
added a commit
to vk-playground/mcp-context-forge
that referenced
this pull request
Sep 14, 2025
…g Implementation (IBM#786) * db.py update Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * revert alembic with main version Signed-off-by: RAKHI DUTTA <[email protected]> * 138 view realtime logs in UI and export logs (CSV, JSON) (IBM#747) * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI readme Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Fix test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 749 reverse proxy (IBM#750) * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * doctest improvements Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * (fix) Added missing prompts/get (IBM#748) Signed-off-by: Ian Molloy <[email protected]> * Adds RPC endpoints and updates RPC response and error handling (IBM#746) * Fix rpc endpoints Signed-off-by: Madhav Kandukuri <[email protected]> * Remove commented code Signed-off-by: Madhav Kandukuri <[email protected]> * remove duplicate code in session registry Signed-off-by: Madhav Kandukuri <[email protected]> * Linting fixes Signed-off-by: Madhav Kandukuri <[email protected]> * Fix tests Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Madhav Kandukuri <[email protected]> * 753 fix tool invocation invalid method (IBM#754) * Fix tool invocation 'Invalid method' error with backward compatibility (IBM#753) - Add backward compatibility for direct tool invocation (pre-PR IBM#746 format) - Support both old format (method=tool_name) and new format (method=tools/call) - Add comprehensive test coverage for RPC tool invocation scenarios - Ensure graceful fallback to gateway forwarding when method is not a tool The RPC endpoint now handles tool invocations in both formats: 1. New format: method='tools/call' with name and arguments in params 2. Old format: method='tool_name' with params as arguments (backward compat) This maintains compatibility with existing clients while supporting the new standardized RPC method structure introduced in PR IBM#746. Signed-off-by: Mihai Criveti <[email protected]> * Fix flake8 E722: Replace bare except with Exception Signed-off-by: Mihai Criveti <[email protected]> * lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: suppress bandit security warnings with appropriate nosec comments (IBM#755) - Added nosec B105 for ENV_TOKEN as it's an environment variable name, not a hardcoded secret - Added nosec B110 for intentional exception swallowing in cleanup/error handling paths - Both cases are legitimate uses where errors should be silently ignored to prevent cascading failures Signed-off-by: Mihai Criveti <[email protected]> * Add agents file Signed-off-by: Mihai Criveti <[email protected]> * pylint (IBM#759) Signed-off-by: Mihai Criveti <[email protected]> * Remove redundant title in readme. (IBM#757) Signed-off-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> * Update documentation with fixed image tag Signed-off-by: Mihai Criveti <[email protected]> * 256 fuzz testing (IBM#760) * Implement comprehensive fuzz testing automation (IBM#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (IBM#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * feat: Bulk Import Tools modal wiring IBM#737 (IBM#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs IBM#737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * Implemented configuration export (IBM#764) Signed-off-by: Mihai Criveti <[email protected]> * 185 186 import export (IBM#769) * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: local network address translation in discovery module (IBM#767) Signed-off-by: Frederico Araujo <[email protected]> * Well known (IBM#770) Signed-off-by: Mihai Criveti <[email protected]> * Update docs with jsonrpc tutorial (IBM#772) Signed-off-by: Mihai Criveti <[email protected]> * 137 metadata timestamps (IBM#776) * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> * feat IBM#262: MCP Langchain Agent (IBM#781) * feat: Add bulk import UI modal for tools Signed-off-by: Vicky <[email protected]> * feat: Add Langchain agent with OpenAI & A2A endpoints (refs IBM#262) Signed-off-by: Vicky <[email protected]> * lint: prettier fix at ~L8090 (insert newline) Signed-off-by: Vicky <[email protected]> --------- Signed-off-by: Vicky <[email protected]> Co-authored-by: Vicky <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Issue 587/rest tool error (IBM#778) * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * Rebase and lint / test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * edit column header (IBM#777) Signed-off-by: Shoumi <[email protected]> * Test case update (IBM#775) * session_registry test case updates Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update for routers/reverse_proxy Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update to mcpgateway/reverse_proxy.py Signed-off-by: Mohan Lakshmaiah <[email protected]> * Fix formatting issues from pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: add plugins cli, external plugin support, plugin template (IBM#722) * feat: add support for external plugins Signed-off-by: Teryl Taylor <[email protected]> * feat(plugins): add external mcp server and associated test cases. Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed yamllint issues Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed flake8 issue. Signed-off-by: Teryl Taylor <[email protected]> * feat: define plugins cli and implement bootstrap command Signed-off-by: Frederico Araujo <[email protected]> * fix: implement install and package CLI commands Signed-off-by: Frederico Araujo <[email protected]> * fix: remote avoid insecure shell=True in subprocess invocation Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: move copier config to repository root Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier template Signed-off-by: Frederico Araujo <[email protected]> * feat: get default author from git config Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier settings Signed-off-by: Frederico Araujo <[email protected]> * fix: copier config syntax Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template modules Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: make template Signed-off-by: Frederico Araujo <[email protected]> * feat: fix template issue Signed-off-by: Frederico Araujo <[email protected]> * fix: toml template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin mcp server initialization Signed-off-by: Frederico Araujo <[email protected]> * feat: init module for plugin framework Signed-off-by: Frederico Araujo <[email protected]> * feat: add chuck runtime and container wrapping Signed-off-by: Frederico Araujo <[email protected]> * fix: makefile template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins config path Signed-off-by: Frederico Araujo <[email protected]> * feat: add .env.template Signed-off-by: Frederico Araujo <[email protected]> * feat: add tools and resources support Signed-off-by: Frederico Araujo <[email protected]> * fix: lint yaml Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanups Signed-off-by: Frederico Araujo <[email protected]> * feat: update manifest.in Signed-off-by: Frederico Araujo <[email protected]> * chore: linting Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin config variable Signed-off-by: Frederico Araujo <[email protected]> * fix(tests): fixed doctests for plugins. Signed-off-by: Teryl Taylor <[email protected]> * refactor: external plugin server and plugin external API Signed-off-by: Frederico Araujo <[email protected]> * docs(plugins): removed subpackages from examples Signed-off-by: Teryl Taylor <[email protected]> * docs: update plugin docs to use public framework API Signed-off-by: Frederico Araujo <[email protected]> * fix(plugin): added resource payloads to base plugin. Signed-off-by: Teryl Taylor <[email protected]> * feat: udpate test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update tempalte makefile Signed-off-by: Frederico Araujo <[email protected]> * feat: add template for native plugin Signed-off-by: Frederico Araujo <[email protected]> * feat: add readme for native template Signed-off-by: Frederico Araujo <[email protected]> * feat: force boostrap to be a subcommnand Signed-off-by: Frederico Araujo <[email protected]> * tests(plugin): added http streamable and error tests. Signed-off-by: Teryl Taylor <[email protected]> * tests: add tests for plugins CLI Signed-off-by: Frederico Araujo <[email protected]> * fix: deprecation warning Signed-off-by: Frederico Araujo <[email protected]> * tests: add CLI tests Signed-off-by: Frederico Araujo <[email protected]> * tests: update plugin cli Signed-off-by: Frederico Araujo <[email protected]> * tests(plugins): added client hook tests for external plugins. Signed-off-by: Teryl Taylor <[email protected]> * chore: update template readmes Signed-off-by: Frederico Araujo <[email protected]> * fix: lint docstrings in cli Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors in docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors Signed-off-by: Frederico Araujo <[email protected]> * tests: add external plugin server tests Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanup Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * tests: fix cli dryrun test Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint issues Signed-off-by: Frederico Araujo <[email protected]> * tests: fix teardown of client http tests Signed-off-by: Frederico Araujo <[email protected]> * tests: skipping flaky tests Signed-off-by: Frederico Araujo <[email protected]> * docs: plugin lifecycle tools Signed-off-by: Frederico Araujo <[email protected]> * docs: add missing plugin lifecycle doc Signed-off-by: Frederico Araujo <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: Experimental Oauth 2.0 support in gateway (IBM#768) * Oauth 2.1 design Signed-off-by: Shamsul Arefin <[email protected]> * oauth 2.0 design Signed-off-by: Shamsul Arefin <[email protected]> * Support for oauth auth type in gateway Signed-off-by: Shamsul Arefin <[email protected]> * Decrypt client secret Signed-off-by: Shamsul Arefin <[email protected]> * authorization code flow, token storage, tool fetching, tool calling with Oauth2.0 Signed-off-by: Shamsul Arefin <[email protected]> * test fixes Signed-off-by: Shamsul Arefin <[email protected]> * 256 fuzz testing (IBM#760) * Implement comprehensive fuzz testing automation (IBM#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (IBM#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * feat: Bulk Import Tools modal wiring IBM#737 (IBM#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs IBM#737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * Implemented configuration export (IBM#764) Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * fixes Signed-off-by: Shamsul Arefin <[email protected]> * ruff fixes Signed-off-by: Shamsul Arefin <[email protected]> * fix flake8 errors Signed-off-by: Shamsul Arefin <[email protected]> * fix eslint errors Signed-off-by: Shamsul Arefin <[email protected]> * aiohttp added in the main dependencies section of pyproject.toml Signed-off-by: Shamsul Arefin <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic multiple heads issue Create merge migration to resolve parallel migration chains: - Main branch migrations (34492f99a0c4) - OAuth branch migrations (add_oauth_tokens_table) This resolves CI/CD test failures caused by Alembic not knowing which migration head to follow during 'alembic upgrade head'. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic migration chain - remove merge migration hack - Remove unnecessary merge migration file (813b45a70b53) - Fix OAuth config migration to follow proper chain (f8c9d3e2a1b4 → 34492f99a0c4) - OAuth tokens migration already correctly follows (add_oauth_tokens_table → f8c9d3e2a1b4) - Now single migration head without parallel branches This eliminates the 'Multiple heads are present' error in CI/CD tests by ensuring migrations follow a linear chain instead of creating parallel migration branches that need artificial merge migrations. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Shamsul Arefin <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Claude <[email protected]> * Fix pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> * 744 annotations (IBM#784) * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: plugins template (IBM#783) * feat: update context forge target in template's project dependencies Signed-off-by: Frederico Araujo <[email protected]> * fix: exclude jinja files from reformatting tabs Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins cli defaults Signed-off-by: Frederico Araujo <[email protected]> * fix: revert formatted Makefile template Signed-off-by: Frederico Araujo <[email protected]> * feat: add optional packages Signed-off-by: Frederico Araujo <[email protected]> * docs: update plugin template docs Signed-off-by: Frederico Araujo <[email protected]> * docs: update template readme Signed-off-by: Frederico Araujo <[email protected]> --------- Signed-off-by: Frederico Araujo <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * web lint Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * pytest fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * flake fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * alembic change Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * remove addtional line Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * Rebase and fix Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: RAKHI DUTTA <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Ian Molloy <[email protected]> Signed-off-by: Madhav Kandukuri <[email protected]> Signed-off-by: Vinod Muthusamy <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Vicky <[email protected]> Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Shoumi <[email protected]> Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> Co-authored-by: RAKHI DUTTA <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: Ian Molloy <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Frederico Araujo <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vicky <[email protected]> Co-authored-by: Veeresh K <[email protected]> Co-authored-by: Shoumi M <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Claude <[email protected]>
vk-playground
pushed a commit
to vk-playground/mcp-context-forge
that referenced
this pull request
Sep 16, 2025
* Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]>
vk-playground
added a commit
to vk-playground/mcp-context-forge
that referenced
this pull request
Sep 16, 2025
…g Implementation (IBM#786) * db.py update Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * pytest Signed-off-by: RAKHI DUTTA <[email protected]> * revert alembic with main version Signed-off-by: RAKHI DUTTA <[email protected]> * 138 view realtime logs in UI and export logs (CSV, JSON) (IBM#747) * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI Signed-off-by: Mihai Criveti <[email protected]> * Add logging UI readme Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * Update logging flake8 Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * test coverage Signed-off-by: Mihai Criveti <[email protected]> * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Fix test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 749 reverse proxy (IBM#750) * Fix download Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * Reverse proxy Signed-off-by: Mihai Criveti <[email protected]> * doctest improvements Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * (fix) Added missing prompts/get (IBM#748) Signed-off-by: Ian Molloy <[email protected]> * Adds RPC endpoints and updates RPC response and error handling (IBM#746) * Fix rpc endpoints Signed-off-by: Madhav Kandukuri <[email protected]> * Remove commented code Signed-off-by: Madhav Kandukuri <[email protected]> * remove duplicate code in session registry Signed-off-by: Madhav Kandukuri <[email protected]> * Linting fixes Signed-off-by: Madhav Kandukuri <[email protected]> * Fix tests Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Madhav Kandukuri <[email protected]> * 753 fix tool invocation invalid method (IBM#754) * Fix tool invocation 'Invalid method' error with backward compatibility (IBM#753) - Add backward compatibility for direct tool invocation (pre-PR IBM#746 format) - Support both old format (method=tool_name) and new format (method=tools/call) - Add comprehensive test coverage for RPC tool invocation scenarios - Ensure graceful fallback to gateway forwarding when method is not a tool The RPC endpoint now handles tool invocations in both formats: 1. New format: method='tools/call' with name and arguments in params 2. Old format: method='tool_name' with params as arguments (backward compat) This maintains compatibility with existing clients while supporting the new standardized RPC method structure introduced in PR IBM#746. Signed-off-by: Mihai Criveti <[email protected]> * Fix flake8 E722: Replace bare except with Exception Signed-off-by: Mihai Criveti <[email protected]> * lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: suppress bandit security warnings with appropriate nosec comments (IBM#755) - Added nosec B105 for ENV_TOKEN as it's an environment variable name, not a hardcoded secret - Added nosec B110 for intentional exception swallowing in cleanup/error handling paths - Both cases are legitimate uses where errors should be silently ignored to prevent cascading failures Signed-off-by: Mihai Criveti <[email protected]> * Add agents file Signed-off-by: Mihai Criveti <[email protected]> * pylint (IBM#759) Signed-off-by: Mihai Criveti <[email protected]> * Remove redundant title in readme. (IBM#757) Signed-off-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> * Update documentation with fixed image tag Signed-off-by: Mihai Criveti <[email protected]> * 256 fuzz testing (IBM#760) * Implement comprehensive fuzz testing automation (IBM#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (IBM#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * feat: Bulk Import Tools modal wiring IBM#737 (IBM#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs IBM#737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * Implemented configuration export (IBM#764) Signed-off-by: Mihai Criveti <[email protected]> * 185 186 import export (IBM#769) * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export Signed-off-by: Mihai Criveti <[email protected]> * Import export testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: local network address translation in discovery module (IBM#767) Signed-off-by: Frederico Araujo <[email protected]> * Well known (IBM#770) Signed-off-by: Mihai Criveti <[email protected]> * Update docs with jsonrpc tutorial (IBM#772) Signed-off-by: Mihai Criveti <[email protected]> * 137 metadata timestamps (IBM#776) * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Metadata / creation dates Signed-off-by: Mihai Criveti <[email protected]> * Security headers CSP Signed-off-by: Mihai Criveti <[email protected]> * Display metadata for resources Signed-off-by: Madhav Kandukuri <[email protected]> * eslint fix Signed-off-by: Madhav Kandukuri <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> * feat IBM#262: MCP Langchain Agent (IBM#781) * feat: Add bulk import UI modal for tools Signed-off-by: Vicky <[email protected]> * feat: Add Langchain agent with OpenAI & A2A endpoints (refs IBM#262) Signed-off-by: Vicky <[email protected]> * lint: prettier fix at ~L8090 (insert newline) Signed-off-by: Vicky <[email protected]> --------- Signed-off-by: Vicky <[email protected]> Co-authored-by: Vicky <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Cleanup pr Signed-off-by: Mihai Criveti <[email protected]> * Issue 587/rest tool error (IBM#778) * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * added params extraction from url logic Signed-off-by: Veeresh K <[email protected]> * Rebase and lint / test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * edit column header (IBM#777) Signed-off-by: Shoumi <[email protected]> * Test case update (IBM#775) * session_registry test case updates Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update for routers/reverse_proxy Signed-off-by: Mohan Lakshmaiah <[email protected]> * test case update to mcpgateway/reverse_proxy.py Signed-off-by: Mohan Lakshmaiah <[email protected]> * Fix formatting issues from pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: add plugins cli, external plugin support, plugin template (IBM#722) * feat: add support for external plugins Signed-off-by: Teryl Taylor <[email protected]> * feat(plugins): add external mcp server and associated test cases. Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed yamllint issues Signed-off-by: Teryl Taylor <[email protected]> * fix(lint): fixed flake8 issue. Signed-off-by: Teryl Taylor <[email protected]> * feat: define plugins cli and implement bootstrap command Signed-off-by: Frederico Araujo <[email protected]> * fix: implement install and package CLI commands Signed-off-by: Frederico Araujo <[email protected]> * fix: remote avoid insecure shell=True in subprocess invocation Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: move copier config to repository root Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier template Signed-off-by: Frederico Araujo <[email protected]> * feat: get default author from git config Signed-off-by: Frederico Araujo <[email protected]> * feat: update copier settings Signed-off-by: Frederico Araujo <[email protected]> * fix: copier config syntax Signed-off-by: Frederico Araujo <[email protected]> * feat: add external plugin template modules Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: template syntax Signed-off-by: Frederico Araujo <[email protected]> * fix: make template Signed-off-by: Frederico Araujo <[email protected]> * feat: fix template issue Signed-off-by: Frederico Araujo <[email protected]> * fix: toml template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin mcp server initialization Signed-off-by: Frederico Araujo <[email protected]> * feat: init module for plugin framework Signed-off-by: Frederico Araujo <[email protected]> * feat: add chuck runtime and container wrapping Signed-off-by: Frederico Araujo <[email protected]> * fix: makefile template Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins config path Signed-off-by: Frederico Araujo <[email protected]> * feat: add .env.template Signed-off-by: Frederico Araujo <[email protected]> * feat: add tools and resources support Signed-off-by: Frederico Araujo <[email protected]> * fix: lint yaml Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanups Signed-off-by: Frederico Araujo <[email protected]> * feat: update manifest.in Signed-off-by: Frederico Araujo <[email protected]> * chore: linting Signed-off-by: Frederico Araujo <[email protected]> * fix: plugin config variable Signed-off-by: Frederico Araujo <[email protected]> * fix(tests): fixed doctests for plugins. Signed-off-by: Teryl Taylor <[email protected]> * refactor: external plugin server and plugin external API Signed-off-by: Frederico Araujo <[email protected]> * docs(plugins): removed subpackages from examples Signed-off-by: Teryl Taylor <[email protected]> * docs: update plugin docs to use public framework API Signed-off-by: Frederico Araujo <[email protected]> * fix(plugin): added resource payloads to base plugin. Signed-off-by: Teryl Taylor <[email protected]> * feat: udpate test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update test templates Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update plugin template Signed-off-by: Frederico Araujo <[email protected]> * feat: update tempalte makefile Signed-off-by: Frederico Araujo <[email protected]> * feat: add template for native plugin Signed-off-by: Frederico Araujo <[email protected]> * feat: add readme for native template Signed-off-by: Frederico Araujo <[email protected]> * feat: force boostrap to be a subcommnand Signed-off-by: Frederico Araujo <[email protected]> * tests(plugin): added http streamable and error tests. Signed-off-by: Teryl Taylor <[email protected]> * tests: add tests for plugins CLI Signed-off-by: Frederico Araujo <[email protected]> * fix: deprecation warning Signed-off-by: Frederico Araujo <[email protected]> * tests: add CLI tests Signed-off-by: Frederico Araujo <[email protected]> * tests: update plugin cli Signed-off-by: Frederico Araujo <[email protected]> * tests(plugins): added client hook tests for external plugins. Signed-off-by: Teryl Taylor <[email protected]> * chore: update template readmes Signed-off-by: Frederico Araujo <[email protected]> * fix: lint docstrings in cli Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors in docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint errors Signed-off-by: Frederico Araujo <[email protected]> * tests: add external plugin server tests Signed-off-by: Frederico Araujo <[email protected]> * chore: cleanup Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * chore: add missing docstrings Signed-off-by: Frederico Araujo <[email protected]> * tests: fix cli dryrun test Signed-off-by: Frederico Araujo <[email protected]> * chore: fix lint issues Signed-off-by: Frederico Araujo <[email protected]> * tests: fix teardown of client http tests Signed-off-by: Frederico Araujo <[email protected]> * tests: skipping flaky tests Signed-off-by: Frederico Araujo <[email protected]> * docs: plugin lifecycle tools Signed-off-by: Frederico Araujo <[email protected]> * docs: add missing plugin lifecycle doc Signed-off-by: Frederico Araujo <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> * feat: Experimental Oauth 2.0 support in gateway (IBM#768) * Oauth 2.1 design Signed-off-by: Shamsul Arefin <[email protected]> * oauth 2.0 design Signed-off-by: Shamsul Arefin <[email protected]> * Support for oauth auth type in gateway Signed-off-by: Shamsul Arefin <[email protected]> * Decrypt client secret Signed-off-by: Shamsul Arefin <[email protected]> * authorization code flow, token storage, tool fetching, tool calling with Oauth2.0 Signed-off-by: Shamsul Arefin <[email protected]> * test fixes Signed-off-by: Shamsul Arefin <[email protected]> * 256 fuzz testing (IBM#760) * Implement comprehensive fuzz testing automation (IBM#256) - Add property-based testing with Hypothesis for JSON-RPC, JSONPath, and schema validation - Add coverage-guided fuzzing with Atheris for deep code path exploration - Add API endpoint fuzzing with Schemathesis for contract validation - Add security-focused testing for vulnerability discovery (SQL injection, XSS, etc.) - Add complete Makefile automation with fuzz-all, fuzz-quick, fuzz-extended targets - Add optional [fuzz] dependency group in pyproject.toml for clean installation - Add comprehensive reporting with JSON/Markdown outputs and executive summaries - Add complete developer documentation with examples and troubleshooting guides - Exclude fuzz tests from main test suite to prevent auth failures - Found multiple real bugs in JSON-RPC validation during development Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> * Update fuzz testing Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * 344 cors security headers (IBM#761) * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS ADRs Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Update CORS Signed-off-by: Mihai Criveti <[email protected]> * Fix compose Signed-off-by: Mihai Criveti <[email protected]> * Update helm chart Signed-off-by: Mihai Criveti <[email protected]> * Update CORS docs Signed-off-by: Mihai Criveti <[email protected]> * Update test Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * feat: Bulk Import Tools modal wiring IBM#737 (IBM#739) * feat: Bulk Import Tools modal wiring and backend implementation - Add modal UI in admin.html with bulk import button and dialog - Implement modal open/close/ESC functionality in admin.js - Add POST /admin/tools/import endpoint with rate limiting - Support both JSON textarea and file upload inputs - Validate JSON structure and enforce 200 tool limit - Return detailed success/failure information per tool - Include loading states and comprehensive error handling Refs IBM#737 Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate admin_import_tools function and fix HTML formatting - Remove duplicate admin_import_tools function definition - Fix HTML placeholder attribute to use double quotes - Add missing closing div tag - Fix flake8 blank line issues Signed-off-by: Mihai Criveti <[email protected]> * feat: Complete bulk import backend with file upload support and enhanced docs - Add file upload support to admin_import_tools endpoint - Fix response format to match frontend expectations - Add UI usage documentation with modal instructions - Update API docs to show all three input methods - Enhance bulk import guide with UI and API examples Backend improvements: - Support tools_file form field for JSON file uploads - Proper file content parsing with error handling - Response includes imported/failed counts and details - Frontend-compatible response format for UI display Signed-off-by: Mihai Criveti <[email protected]> * Bulk import Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove conflicting inline script and fix bulk import functionality - Remove conflicting inline JavaScript that was preventing form submission - Fix indentation in setupBulkImportModal function - Ensure bulk import modal uses proper admin.js implementation - Restore proper form submission handling for bulk import This fixes the issue where bulk import appeared to do nothing. Signed-off-by: Mihai Criveti <[email protected]> * fix: Integrate bulk import setup with main initialization - Add setupBulkImportModal() to main initialization sequence - Remove duplicate DOMContentLoaded listener - Ensure bulk import doesn't interfere with other tab functionality Signed-off-by: Mihai Criveti <[email protected]> * fix: JavaScript formatting issues in bulk import modal - Fix multiline querySelector formatting - Fix multiline Error constructor formatting - Ensure prettier compliance for web linting Signed-off-by: Mihai Criveti <[email protected]> * debug: Temporarily disable bulk import setup to test tabs Signed-off-by: Mihai Criveti <[email protected]> * fix: Remove duplicate setupFormValidation call and delay bulk import setup - Remove duplicate setupFormValidation() call that could cause conflicts - Use setTimeout to delay bulk import modal setup after other initialization - Add better null safety to form element queries - This should fix tab switching issues Signed-off-by: Mihai Criveti <[email protected]> * fix: Restore proper initialization sequence for tab functionality - Remove setTimeout delay for bulk import setup - Keep bulk import setup in main initialization but with error handling - Ensure tab navigation isn't affected by bulk import modal setup Signed-off-by: Mihai Criveti <[email protected]> * fix: Correct HTML structure and restore tab navigation - Move bulk import modal to correct location after tools panel - Remove extra closing div that was breaking HTML structure - Ensure proper page-level modal placement - Restore tab navigation functionality for all tabs This fixes the broken Global Resources, Prompts, Gateways, Roots, and Metrics tabs. Signed-off-by: Mihai Criveti <[email protected]> * feat: Add configurable bulk import settings Configuration additions: - MCPGATEWAY_BULK_IMPORT_MAX_TOOLS (default: 200) - MCPGATEWAY_BULK_IMPORT_RATE_LIMIT (default: 10) Implementation: - config.py: Add new settings with defaults - admin.py: Use configurable rate limit and batch size - .env.example: Document all bulk import environment variables - admin.html: Use dynamic max tools value in UI text - CLAUDE.md: Document configuration options for developers - docs: Update bulk import guide with configuration details This makes bulk import fully configurable for different deployment scenarios. Signed-off-by: Mihai Criveti <[email protected]> * Update docs Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * Implemented configuration export (IBM#764) Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * cleanup Signed-off-by: Shamsul Arefin <[email protected]> * fixes Signed-off-by: Shamsul Arefin <[email protected]> * ruff fixes Signed-off-by: Shamsul Arefin <[email protected]> * fix flake8 errors Signed-off-by: Shamsul Arefin <[email protected]> * fix eslint errors Signed-off-by: Shamsul Arefin <[email protected]> * aiohttp added in the main dependencies section of pyproject.toml Signed-off-by: Shamsul Arefin <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic multiple heads issue Create merge migration to resolve parallel migration chains: - Main branch migrations (34492f99a0c4) - OAuth branch migrations (add_oauth_tokens_table) This resolves CI/CD test failures caused by Alembic not knowing which migration head to follow during 'alembic upgrade head'. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Fix Alembic migration chain - remove merge migration hack - Remove unnecessary merge migration file (813b45a70b53) - Fix OAuth config migration to follow proper chain (f8c9d3e2a1b4 → 34492f99a0c4) - OAuth tokens migration already correctly follows (add_oauth_tokens_table → f8c9d3e2a1b4) - Now single migration head without parallel branches This eliminates the 'Multiple heads are present' error in CI/CD tests by ensuring migrations follow a linear chain instead of creating parallel migration branches that need artificial merge migrations. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> * Review, rebase and lint Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Shamsul Arefin <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Claude <[email protected]> * Fix pre-commit hooks Signed-off-by: Mihai Criveti <[email protected]> * 744 annotations (IBM#784) * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> * Fix annotations edit Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: Mihai Criveti <[email protected]> * fix: plugins template (IBM#783) * feat: update context forge target in template's project dependencies Signed-off-by: Frederico Araujo <[email protected]> * fix: exclude jinja files from reformatting tabs Signed-off-by: Frederico Araujo <[email protected]> * fix: plugins cli defaults Signed-off-by: Frederico Araujo <[email protected]> * fix: revert formatted Makefile template Signed-off-by: Frederico Araujo <[email protected]> * feat: add optional packages Signed-off-by: Frederico Araujo <[email protected]> * docs: update plugin template docs Signed-off-by: Frederico Araujo <[email protected]> * docs: update template readme Signed-off-by: Frederico Araujo <[email protected]> --------- Signed-off-by: Frederico Araujo <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * doc test Signed-off-by: RAKHI DUTTA <[email protected]> * edit-tool Signed-off-by: RAKHI DUTTA <[email protected]> * web lint Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * pytest fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * flake fix Signed-off-by: RAKHI DUTTA <[email protected]> * revert with main Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * alembic change Signed-off-by: RAKHI DUTTA <[email protected]> * flake8 fix Signed-off-by: RAKHI DUTTA <[email protected]> * remove addtional line Signed-off-by: RAKHI DUTTA <[email protected]> * alembic Signed-off-by: RAKHI DUTTA <[email protected]> * Rebase and fix Signed-off-by: Mihai Criveti <[email protected]> --------- Signed-off-by: RAKHI DUTTA <[email protected]> Signed-off-by: Mihai Criveti <[email protected]> Signed-off-by: Ian Molloy <[email protected]> Signed-off-by: Madhav Kandukuri <[email protected]> Signed-off-by: Vinod Muthusamy <[email protected]> Signed-off-by: Frederico Araujo <[email protected]> Signed-off-by: Vicky <[email protected]> Signed-off-by: Veeresh K <[email protected]> Signed-off-by: Shoumi <[email protected]> Signed-off-by: Mohan Lakshmaiah <[email protected]> Signed-off-by: Teryl Taylor <[email protected]> Signed-off-by: Shamsul Arefin <[email protected]> Co-authored-by: RAKHI DUTTA <[email protected]> Co-authored-by: Mihai Criveti <[email protected]> Co-authored-by: Ian Molloy <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: Vinod Muthusamy <[email protected]> Co-authored-by: VK <[email protected]> Co-authored-by: Frederico Araujo <[email protected]> Co-authored-by: Madhav Kandukuri <[email protected]> Co-authored-by: Vicky <[email protected]> Co-authored-by: Veeresh K <[email protected]> Co-authored-by: Shoumi M <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Mohan Lakshmaiah <[email protected]> Co-authored-by: Teryl Taylor <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Shamsul Arefin <[email protected]> Co-authored-by: Claude <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
📊 PR Implementation Summary: Comprehensive Metadata Tracking
Closes #137
🎯 Feature Delivered
Complete audit trail and metadata tracking for all MCP Gateway entities (Tools, Resources, Prompts, Servers, Gateways) with full backwards compatibility and auth-agnostic support.
🔧 Implementation Overview
Problem Solved
Solution Delivered
AUTH_REQUIRED=true/false
📁 Files Modified
1. Database Layer
mcpgateway/alembic/versions/34492f99a0c4_add_comprehensive_metadata_to_all_.py
✨ NEWnullable=True
for backwards compatibilitymcpgateway/db.py
✏️ MODIFIEDTool
,Resource
,Prompt
,Server
,Gateway
created_by
,created_from_ip
,created_via
,created_user_agent
modified_by
,modified_from_ip
,modified_via
,modified_user_agent
import_batch_id
,federation_source
,version
2. API Schema Layer
mcpgateway/schemas.py
✏️ MODIFIEDToolRead
,ResourceRead
,PromptRead
,ServerRead
,GatewayRead
3. Business Logic Layer
mcpgateway/utils/metadata_capture.py
✨ NEWMetadataCapture
utility class for extracting request contextextract_username()
method handles both JWT dict and string auth responsesmcpgateway/services/tool_service.py
✏️ MODIFIEDregister_tool
andupdate_tool
methods to accept metadata parametersmcpgateway/services/gateway_service.py
✏️ MODIFIEDregister_gateway
to capture metadata for federated entitiesmcpgateway/services/prompt_service.py
✏️ MODIFIEDregister_prompt
method to accept and store metadata4. API Endpoints
mcpgateway/main.py
✏️ MODIFIEDcreate_tool
,update_tool
,create_prompt
,register_gateway
endpointsRequest
parameter for context extraction across all creation endpointsmcpgateway/admin.py
✏️ MODIFIED5. Frontend Layer
mcpgateway/static/admin.js
✏️ MODIFIEDviewTool
,viewGateway
,viewPrompt
,viewServer
mcpgateway/templates/admin.html
✏️ MODIFIED📊 Metadata Fields Implemented
created_by
"admin"
,"alice"
,"anonymous"
created_from_ip
"192.168.1.100"
,"10.0.0.1"
created_via
"ui"
,"api"
,"import"
,"federation"
created_user_agent
"Mozilla/5.0"
,"curl/7.68.0"
modified_by
"bob"
,"system"
,"anonymous"
modified_from_ip
"172.16.0.1"
modified_via
"ui"
,"api"
modified_user_agent
"HTTPie/2.4.0"
import_batch_id
"550e8400-e29b-41d4-a716-446655440000"
federation_source
"gateway-prod-east"
version
1
,2
,3
...🛡️ Backwards Compatibility Strategy
✅ Migration Safety
nullable=True
- existing entities haveNULL
valuesOptional[T]
- gracefully handle missing metadata🖥️ UI Compatibility
Created By: "Legacy Entity"
(instead of null)Created At: "Pre-metadata"
(instead of null)Version: "1"
(automatic default)🔧 Auth Compatibility
AUTH_REQUIRED=true
: Captures actual usernames ("admin"
,"alice"
)AUTH_REQUIRED=false
: Uses"anonymous"
- no breaking changes🧪 Testing & Validation
✅ Test Results
🔍 Test Coverage
🚀 Impact & Benefits
🔒 Security & Compliance
🐛 Operational Excellence
📈 User Experience
💻 Technical Highlights
🏗️ Architecture
MetadataCapture
class🔧 Implementation Patterns
🌐 Integration Points
🎯 Key Success Factors
🔮 Future Enhancement Opportunities
📋 Deployment Notes
Migration Required
# Run this to apply metadata columns: alembic upgrade head
Environment Variables
AUTH_REQUIRED
settingX-Forwarded-For
headers automaticallyMonitoring
This implementation provides enterprise-grade audit capabilities while maintaining the stability and compatibility of existing MCP Gateway deployments.
🐛 Issues Resolved
During implementation, several user-reported issues were identified and fixed:
Issue #1: Missing Gateway Metadata Display
viewGateway()
functionIssue #2: MCP Tools Showing "Legacy Entity"
gateway_service.py
to capture federation metadata during auto-discoveryCreated Via: federation
andFederation Source: [gateway-name]
Issue #3: Broken Prompt Creation from Admin UI
admin_add_prompt
JSON parsingIssue #4: API Entities Not Showing Metadata
extract_username()
function to handle both JWT dict and string auth responsesIssue #5: Incomplete Entity Coverage
Quality Assurance Issues
📚 Documentation Added
docs/docs/manage/metadata-tracking.md
✨ NEW - Comprehensive user guidedocs/docs/manage/index.md
✏️ UPDATED - Added metadata tracking to management overviewdocs/docs/overview/features.md
✏️ UPDATED - Added audit tracking to feature listdocs/docs/overview/ui.md
✏️ UPDATED - Documented metadata viewing in Admin UIThis implementation provides enterprise-grade audit capabilities while maintaining the stability and compatibility of existing MCP Gateway deployments.