Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
9755ccd
fix(webui): promote dialogs to the top layer, one z-index scale (FR-055)
Dumbris Sep 25, 2026
9f70c2a
feat: navigation, review and tool-tier quick wins (Spec 109 PR a)
Dumbris Sep 25, 2026
55ebcce
feat(macos): tool tier + approval labels + Add to MCPProxy (Spec 109 …
Dumbris Sep 25, 2026
7b08df1
chore(oas): regenerate OpenAPI spec for Tool.tier
Dumbris Sep 25, 2026
3fa2854
fix: address review round 1
Dumbris Sep 25, 2026
20ddead
fix: address review round 2
Dumbris Sep 25, 2026
211b18a
fix: address review round 3
Dumbris Sep 25, 2026
df3d93c
fix: address review round 4
Dumbris Sep 25, 2026
ef0bc40
fix: address review round 6
Dumbris Sep 25, 2026
05d0384
fix: address review round 7
Dumbris Sep 26, 2026
9b7e1b1
feat(catalog): add source-agnostic catalog search backend (Spec 109 F…
Dumbris Sep 25, 2026
9fa49c8
feat(import): add Paste-source URL/command detection and preview enri…
Dumbris Sep 25, 2026
5c8644b
feat(cli): add 'mcpproxy catalog search|show|add' (FR-066)
Dumbris Sep 25, 2026
9986685
feat(cli): add 'upstream add --secret-env/--secret-header' (FR-065)
Dumbris Sep 25, 2026
466ab2e
feat(web): add the catalog-first /add-server page (Spec 109 FR-060-065)
Dumbris Sep 25, 2026
b3192d6
feat(mcp): make search_servers' registry optional (Spec 109 FR-067)
Dumbris Sep 25, 2026
f89476b
feat(macos): add catalog models + shared secret ref-name helper (Spec…
Dumbris Sep 25, 2026
28706d7
chore(oas): regenerate OpenAPI spec for GET /catalog/search
Dumbris Sep 25, 2026
ab75d47
test(catalog): pin secret_like name-rule override and non-admin user-…
Dumbris Sep 25, 2026
ce0be59
fix: address review round 1 findings on catalog/add-server (Spec 109 …
Dumbris Sep 26, 2026
b1ddae5
fix: address review round 3 findings on catalog/add-server (Spec 109 …
Dumbris Sep 26, 2026
dbb0bf9
docs(spec): add Spec 110 catalog popularity signal (spec, plan, tasks)
Dumbris Sep 26, 2026
d35c994
docs(spec): fold zcode round-1 spec review into Spec 110
Dumbris Sep 26, 2026
8e153c5
feat(catalog): add GitHub-stars popularity signal core (Spec 110 T001…
Dumbris Sep 26, 2026
37fbed9
feat(catalog): wire popularity provider into runtime, CLI, and E2E (T…
Dumbris Sep 26, 2026
24431cd
fix(catalog): enforce popularity cache cap across restarts
Dumbris Sep 26, 2026
9386f9c
fix(catalog): harden popularity fetcher per review round 2
Dumbris Sep 26, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 19 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# MCPProxy Makefile

.PHONY: help build build-server build-docker build-deb swagger swagger-verify frontend-build frontend-dev backend-dev clean test test-coverage test-e2e test-e2e-oauth lint dev-setup docs-setup docs-dev docs-build docs-clean bench-discovery
.PHONY: help build build-server build-docker build-deb swagger swagger-verify frontend-build frontend-dev backend-dev clean test test-coverage test-e2e test-e2e-oauth test-descendant-pids test-e2e-cleanup-check lint dev-setup docs-setup docs-dev docs-build docs-clean bench-discovery

SWAGGER_BIN ?= $(HOME)/go/bin/swag
SWAGGER_OUT ?= oas
Expand All @@ -20,6 +20,8 @@ help:
@echo " make test-coverage - Run tests with coverage"
@echo " make test-e2e - Run all E2E tests"
@echo " make test-e2e-oauth - Run OAuth E2E tests with Playwright"
@echo " make test-descendant-pids - Unit test for the E2E cleanup trap's process-tree walk"
@echo " make test-e2e-cleanup-check - Integration test: E2E cleanup trap reaps only its own processes"
@echo " make lint - Run linter"
@echo " make dev-setup - Install development dependencies (swag, frontend, Playwright)"
@echo ""
Expand Down Expand Up @@ -176,6 +178,22 @@ test-e2e: test-e2e-oauth
@echo "🧪 Running E2E tests..."
./scripts/test-api-e2e.sh

# Unit test for descendant_pids (scripts/descendant-pids.sh), the process-tree
# walk the E2E cleanup trap uses to reap only what a run itself spawned.
# Hermetic — no built binary required.
test-descendant-pids:
@echo "🧪 Running descendant_pids unit test..."
./scripts/descendant-pids.test.sh

# Integration test: proves the E2E cleanup trap reaps only what its own run
# started (a decoy mcpproxy on another port survives) and that it actually
# reaps a real orphan of the run (the launcher-test fixture). Requires a
# built ./mcpproxy binary; not part of `test-e2e` since it re-runs the whole
# E2E suite as a subprocess.
test-e2e-cleanup-check:
@echo "🧪 Running E2E cleanup-trap safety check..."
./scripts/test-api-e2e-cleanup-check.sh

# Documentation site commands
docs-setup:
@echo "📦 Installing documentation dependencies..."
Expand Down
1 change: 1 addition & 0 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -1035,3 +1035,4 @@ Legend: `shipped` ≥95% checked · `in-flight` 1–94% · `drafted` 0% · `—`
| [105-agent-scope-hardening](./specs/105-agent-scope-hardening/) | `in-flight` | 94/113 (83%) |
| [106-security-residual-fixes](./specs/106-security-residual-fixes/) | `shipped` | 18/19 (95%) |
| [107-server-edition-sso-hardening](./specs/107-server-edition-sso-hardening/) | `shipped` | 126/126 (100%) |
| [110-catalog-popularity](./specs/110-catalog-popularity/) | `in-flight` | 19/23 (83%) |
22 changes: 22 additions & 0 deletions cmd/generate-types/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -325,6 +325,25 @@ export interface IsolationDefaults {
working_dir?: string;
}

`)

// Tier constants - generated from internal/contracts/tier.go
// Spec 109 FR-028/X11: one pure function (contracts.AnnotationTier)
// computes this everywhere — the Web/macOS/CLI surfaces never derive
// their own. `unknown` is returned only by the review payload composer,
// never by AnnotationTier itself.
sb.WriteString(`export const TierRead = 'read' as const;
export const TierWrite = 'write' as const;
export const TierDestructive = 'destructive' as const;
export const TierUnannotated = 'unannotated' as const;
export const TierUnknown = 'unknown' as const;
export type Tier =
| typeof TierRead
| typeof TierWrite
| typeof TierDestructive
| typeof TierUnannotated
| typeof TierUnknown;

`)

// Tool types
Expand All @@ -341,6 +360,9 @@ export interface IsolationDefaults {
// Tool-level quarantine status surfaced by the same approval record.
// Optional because non-quarantined tools simply omit the field.
approval_status?: string;
// Computed by contracts.AnnotationTier (Spec 109 FR-028) — never derive
// this from annotations on the frontend (X11).
tier?: Tier;
// Why the trust_mode: scan gate held this tool for review (spec 086
// FR-018). held_signals names the matched deterministic check ids, e.g.
// "tpa.TPA-2026-0001.hidden_instruction". All three are absent unless the
Expand Down
Loading
Loading