fix(mcp): ignore project allowlist overrides for env expansion
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
@@ -1,7 +1,21 @@
|
|||||||
import { describe, expect, it } from "bun:test";
|
import { afterEach, describe, expect, it, mock, spyOn } from "bun:test";
|
||||||
import { mergeConfigs, parseConfigPartially } from "./plugin-config";
|
import { mkdtempSync, mkdirSync, rmSync, writeFileSync } from "node:fs"
|
||||||
|
import { tmpdir } from "node:os"
|
||||||
|
import { join } from "node:path"
|
||||||
|
import * as shared from "./shared"
|
||||||
|
import { loadPluginConfig, mergeConfigs, parseConfigPartially } from "./plugin-config";
|
||||||
import { OhMyOpenCodeConfigSchema, type OhMyOpenCodeConfig } from "./config";
|
import { OhMyOpenCodeConfigSchema, type OhMyOpenCodeConfig } from "./config";
|
||||||
|
|
||||||
|
const tempDirs: string[] = []
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
mock.restore()
|
||||||
|
|
||||||
|
for (const dir of tempDirs.splice(0)) {
|
||||||
|
rmSync(dir, { recursive: true, force: true })
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
describe("mergeConfigs", () => {
|
describe("mergeConfigs", () => {
|
||||||
describe("categories merging", () => {
|
describe("categories merging", () => {
|
||||||
// given base config has categories, override has different categories
|
// given base config has categories, override has different categories
|
||||||
@@ -277,3 +291,34 @@ describe("parseConfigPartially", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
describe("loadPluginConfig", () => {
|
||||||
|
it("should only honor mcp_env_allowlist from user config", () => {
|
||||||
|
// given
|
||||||
|
const rootDir = mkdtempSync(join(tmpdir(), "omo-plugin-config-"))
|
||||||
|
const userConfigDir = join(rootDir, "user-config")
|
||||||
|
const projectDir = join(rootDir, "project")
|
||||||
|
const projectConfigDir = join(projectDir, ".opencode")
|
||||||
|
|
||||||
|
tempDirs.push(rootDir)
|
||||||
|
mkdirSync(userConfigDir, { recursive: true })
|
||||||
|
mkdirSync(projectConfigDir, { recursive: true })
|
||||||
|
|
||||||
|
writeFileSync(
|
||||||
|
join(userConfigDir, "oh-my-openagent.jsonc"),
|
||||||
|
JSON.stringify({ mcp_env_allowlist: ["USER_ONLY_TOKEN"] })
|
||||||
|
)
|
||||||
|
writeFileSync(
|
||||||
|
join(projectConfigDir, "oh-my-openagent.jsonc"),
|
||||||
|
JSON.stringify({ mcp_env_allowlist: ["PROJECT_TOKEN"] })
|
||||||
|
)
|
||||||
|
|
||||||
|
spyOn(shared, "getOpenCodeConfigDir").mockReturnValue(userConfigDir)
|
||||||
|
|
||||||
|
// when
|
||||||
|
const config = loadPluginConfig(projectDir, {})
|
||||||
|
|
||||||
|
// then
|
||||||
|
expect(config.mcp_env_allowlist).toEqual(["USER_ONLY_TOKEN"])
|
||||||
|
})
|
||||||
|
})
|
||||||
|
|||||||
@@ -210,8 +210,9 @@ export function loadPluginConfig(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Load user config first (base). Parse empty config through Zod to apply field defaults.
|
// Load user config first (base). Parse empty config through Zod to apply field defaults.
|
||||||
|
const userConfig = loadConfigFromPath(userConfigPath, ctx)
|
||||||
let config: OhMyOpenCodeConfig =
|
let config: OhMyOpenCodeConfig =
|
||||||
loadConfigFromPath(userConfigPath, ctx) ?? OhMyOpenCodeConfigSchema.parse({});
|
userConfig ?? OhMyOpenCodeConfigSchema.parse({});
|
||||||
|
|
||||||
// Override with project config
|
// Override with project config
|
||||||
const projectConfig = loadConfigFromPath(projectConfigPath, ctx);
|
const projectConfig = loadConfigFromPath(projectConfigPath, ctx);
|
||||||
@@ -221,6 +222,7 @@ export function loadPluginConfig(
|
|||||||
|
|
||||||
config = {
|
config = {
|
||||||
...config,
|
...config,
|
||||||
|
mcp_env_allowlist: userConfig?.mcp_env_allowlist ?? [],
|
||||||
};
|
};
|
||||||
|
|
||||||
log("Final merged config", {
|
log("Final merged config", {
|
||||||
|
|||||||
Reference in New Issue
Block a user