* feat: add TenantExtension auth to MCP endpoint Replace static MCP_AUTH_TOKEN check with TenantExtension authentication, making MCP use the same auth path as REST API. - MCPMiddleware now calls tenant_extension.authenticate() - Sets _current_schema from TenantContext for multi-tenant isolation - Returns 401 on AuthenticationError (same as REST API) - DefaultTenantExtension: no auth (local dev) - ApiKeyTenantExtension: validates against env var - CloudTenantExtension: HMAC + DB lookup (production) Adds tests for middleware auth rejection, acceptance, and schema routing. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Address PR review: backwards compatibility for MCP auth - Keep MCP_AUTH_TOKEN env var for legacy MCP servers - Add authenticate_mcp() method to TenantExtension base class - Default implementation calls authenticate() - Extensions can override to opt-out of MCP auth - Add mcp_auth_disabled config option to ApiKeyTenantExtension - Set HINDSIGHT_API_TENANT_MCP_AUTH_DISABLED=true to skip MCP auth - Remove CloudTenantExtension from public docstring - Add tests for legacy auth token and mcp_auth_disabled flag - Update MCP docs with new auth configuration Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Add search_docs MCP tool for documentation search Implements a new MCP tool that searches Hindsight documentation using Vectorize RAG pipelines. The tool supports: - Searching core (OSS) docs, cloud docs, or both - Configurable number of results (1-10) - Returns ranked results with URLs, similarity scores, and text snippets New environment variables: - HINDSIGHT_API_VECTORIZE_ORG_ID - HINDSIGHT_API_VECTORIZE_API_TOKEN - HINDSIGHT_API_VECTORIZE_CORE_PIPELINE_ID - HINDSIGHT_API_VECTORIZE_CLOUD_PIPELINE_ID - HINDSIGHT_API_VECTORIZE_API_BASE_URL Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Add documentation for search_docs MCP tool - Add Vectorize environment variables to configuration.md - Add search_docs tool to MCP server available tools - Add reflect tool documentation (was missing) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Add tests for search_docs MCP tool Tests cover: - DocsSource enum values and parsing - _clean_text HTML stripping helper - _search_vectorize_pipeline with mocked httpx - Tool registration and function execution - Source filtering (core/cloud/all) - Result sorting by similarity - Error handling for pipeline failures - HTML cleaning in results - Invalid source defaulting to 'all' Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Move search_docs to hindsight-cloud, add MCPExtension pattern - Add MCPExtension base class for registering additional MCP tools - Load MCPExtension in create_mcp_server when configured - Remove search_docs tool (moved to hindsight-cloud CloudMCPExtension) - Remove Vectorize config from hindsight-core - Add tests for MCPExtension pattern - Update docs to remove search_docs references The MCPExtension pattern allows cloud (or any extension package) to register additional MCP tools via: HINDSIGHT_API_MCP_EXTENSION=package.module:ExtensionClass Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Address PR review feedback - Remove CloudTenantExtension mention from MCPMiddleware docstring - Fix docs: clarify that ApiKeyTenantExtension must be explicitly enabled - Revert changes to versioned docs (0.3 and 0.4) - synced automatically on release Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Format mcp.py line length Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
169 lines
6.1 KiB
Python
169 lines
6.1 KiB
Python
"""Tests for MCPExtension loading and tool registration."""
|
|
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
import pytest
|
|
from fastmcp import FastMCP
|
|
|
|
from hindsight_api import MemoryEngine
|
|
from hindsight_api.extensions.mcp import MCPExtension
|
|
|
|
|
|
class MockMCPExtension(MCPExtension):
|
|
"""Test extension that registers a custom tool."""
|
|
|
|
def __init__(self, config=None):
|
|
super().__init__(config)
|
|
self.register_tools_called = False
|
|
self.registered_mcp = None
|
|
self.registered_memory = None
|
|
|
|
def register_tools(self, mcp: FastMCP, memory: MemoryEngine) -> None:
|
|
"""Register a test tool to verify extension was called."""
|
|
self.register_tools_called = True
|
|
self.registered_mcp = mcp
|
|
self.registered_memory = memory
|
|
|
|
@mcp.tool()
|
|
async def test_extension_tool(query: str) -> str:
|
|
"""A test tool registered by the extension."""
|
|
return f"Extension tool received: {query}"
|
|
|
|
|
|
class TestMCPExtensionBase:
|
|
"""Tests for MCPExtension base class."""
|
|
|
|
def test_mcp_extension_is_abstract(self):
|
|
"""MCPExtension.register_tools is abstract and must be implemented."""
|
|
with pytest.raises(TypeError, match="abstract method"):
|
|
MCPExtension()
|
|
|
|
def test_subclass_can_be_instantiated(self):
|
|
"""Subclass implementing register_tools can be instantiated."""
|
|
ext = MockMCPExtension()
|
|
assert ext is not None
|
|
assert ext.register_tools_called is False
|
|
|
|
def test_register_tools_receives_mcp_and_memory(self):
|
|
"""register_tools receives FastMCP and MemoryEngine instances."""
|
|
ext = MockMCPExtension()
|
|
mcp = FastMCP("test")
|
|
memory = MagicMock(spec=MemoryEngine)
|
|
|
|
ext.register_tools(mcp, memory)
|
|
|
|
assert ext.register_tools_called is True
|
|
assert ext.registered_mcp is mcp
|
|
assert ext.registered_memory is memory
|
|
|
|
|
|
class TestMCPExtensionLoading:
|
|
"""Tests for MCPExtension loading in create_mcp_server."""
|
|
|
|
@pytest.fixture
|
|
def mock_memory(self):
|
|
"""Create a mock MemoryEngine."""
|
|
memory = MagicMock()
|
|
memory._tenant_extension = MagicMock()
|
|
memory._tenant_extension.authenticate_mcp = MagicMock()
|
|
return memory
|
|
|
|
def test_create_mcp_server_without_extension(self, mock_memory):
|
|
"""create_mcp_server works without MCPExtension configured."""
|
|
from hindsight_api.api.mcp import create_mcp_server
|
|
|
|
with patch("hindsight_api.api.mcp.load_extension", return_value=None):
|
|
mcp = create_mcp_server(mock_memory)
|
|
|
|
# Core tools should be registered
|
|
tools = mcp._tool_manager._tools
|
|
assert "retain" in tools
|
|
assert "recall" in tools
|
|
assert "reflect" in tools
|
|
# Extension tool should NOT be present
|
|
assert "test_extension_tool" not in tools
|
|
|
|
def test_create_mcp_server_with_extension(self, mock_memory):
|
|
"""create_mcp_server loads and calls MCPExtension when configured."""
|
|
from hindsight_api.api.mcp import create_mcp_server
|
|
|
|
mock_ext = MockMCPExtension()
|
|
|
|
with patch("hindsight_api.api.mcp.load_extension", return_value=mock_ext):
|
|
mcp = create_mcp_server(mock_memory)
|
|
|
|
# Extension should have been called
|
|
assert mock_ext.register_tools_called is True
|
|
|
|
# Core tools should still be registered
|
|
tools = mcp._tool_manager._tools
|
|
assert "retain" in tools
|
|
assert "recall" in tools
|
|
|
|
# Extension tool should also be registered
|
|
assert "test_extension_tool" in tools
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_extension_tool_is_callable(self, mock_memory):
|
|
"""Tool registered by extension can be called."""
|
|
from hindsight_api.api.mcp import create_mcp_server
|
|
|
|
mock_ext = MockMCPExtension()
|
|
|
|
with patch("hindsight_api.api.mcp.load_extension", return_value=mock_ext):
|
|
mcp = create_mcp_server(mock_memory)
|
|
|
|
# Get and call the extension tool
|
|
tools = mcp._tool_manager._tools
|
|
test_tool = tools["test_extension_tool"]
|
|
result = await test_tool.fn(query="hello world")
|
|
|
|
assert result == "Extension tool received: hello world"
|
|
|
|
def test_load_extension_called_with_correct_args(self, mock_memory):
|
|
"""load_extension is called with 'MCP' prefix and MCPExtension class."""
|
|
from hindsight_api.api.mcp import create_mcp_server
|
|
|
|
with patch("hindsight_api.api.mcp.load_extension") as mock_load:
|
|
mock_load.return_value = None
|
|
create_mcp_server(mock_memory)
|
|
|
|
mock_load.assert_called_once_with("MCP", MCPExtension)
|
|
|
|
|
|
class TestMCPExtensionIntegration:
|
|
"""Integration tests verifying extension tools work end-to-end."""
|
|
|
|
@pytest.fixture
|
|
def mock_memory(self):
|
|
"""Create a mock MemoryEngine with required methods."""
|
|
memory = MagicMock()
|
|
memory.retain_batch_async = MagicMock()
|
|
memory.submit_async_retain = MagicMock(return_value={"operation_id": "test-op"})
|
|
memory.recall_async = MagicMock(return_value=MagicMock(results=[]))
|
|
memory.reflect_async = MagicMock(return_value=MagicMock(text="reflection"))
|
|
memory.list_banks = MagicMock(return_value=[])
|
|
memory.get_bank_profile = MagicMock(return_value={"id": "test"})
|
|
memory._tenant_extension = MagicMock()
|
|
return memory
|
|
|
|
def test_extension_tools_coexist_with_core_tools(self, mock_memory):
|
|
"""Extension tools are added alongside core tools, not replacing them."""
|
|
from hindsight_api.api.mcp import create_mcp_server
|
|
|
|
mock_ext = MockMCPExtension()
|
|
|
|
with patch("hindsight_api.api.mcp.load_extension", return_value=mock_ext):
|
|
mcp = create_mcp_server(mock_memory)
|
|
|
|
tools = mcp._tool_manager._tools
|
|
# All core tools present
|
|
assert "retain" in tools
|
|
assert "recall" in tools
|
|
assert "reflect" in tools
|
|
assert "list_banks" in tools
|
|
assert "create_bank" in tools
|
|
# Extension tool also present
|
|
assert "test_extension_tool" in tools
|
|
# Total: 5 core + 1 extension = 6 tools
|
|
assert len(tools) == 6
|