Playwright Tests / test-playwright (1, 2) (push) Canceled after 0s
Playwright Tests / test-playwright (2, 2) (push) Canceled after 0s
pre-commit / pre-commit (push) Canceled after 0s
Test Backend / test-backend (push) Canceled after 0s
Compose Smoke Test / test-compose (push) Canceled after 0s
Playwright Tests / merge-reports (push) Canceled after 0s
The engine now speaks MCP at /mcp, with a built-in OAuth 2.1 authorization server in front of it: an agent registers itself, sends a human to the browser to approve it, and exchanges the resulting code for a token. PKCE is required, codes are single-use and stored only as hashes, the browser is redirected to the URI that was registered rather than the one asked for, and refresh tokens rotate so that replaying a spent one revokes the whole line. Twenty tools cover reading, building, publishing and running flows, and each one calls the same REST endpoint the dashboard calls, in-process, carrying the caller's own token. That keeps one description of what a flow is and what may be done to it — validation, the draft/publish split, the version check — and means an agent can do nothing a person could not do in the browser. Agent tokens are RS256 with a keypair of their own rather than the secret that signs browser sessions, so deleting the key withdraws every agent without logging anyone out, and deps.decode_token grew the branch that trusting a second issuer will need when the hosted login arrives. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
20 lines
671 B
Python
20 lines
671 B
Python
from fastapi import APIRouter
|
|
|
|
from app.api.routes import flows, login, oauth, private, secrets, users, utils
|
|
from app.core.config import settings
|
|
|
|
api_router = APIRouter()
|
|
api_router.include_router(login.router)
|
|
api_router.include_router(users.router)
|
|
api_router.include_router(utils.router)
|
|
api_router.include_router(flows.router)
|
|
api_router.include_router(flows.ws_router)
|
|
api_router.include_router(secrets.router)
|
|
# Always mounted so the generated SDK stays the same shape; the endpoints
|
|
# themselves refuse to work unless MCP is switched on.
|
|
api_router.include_router(oauth.router)
|
|
|
|
|
|
if settings.ENVIRONMENT == "local":
|
|
api_router.include_router(private.router)
|