mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
[codex] Centralize plugin auth capability filtering (#27902)
## Summary This is the first step in making plugin auth routing consistent. The rule should not live as one-off checks in every place that loads or displays plugin capabilities. This PR introduces a small resolver for the auth-level policy: given a plugin's declared apps, MCP servers, current auth mode, and active state, return the capabilities that are actually usable in that context. ## Why Product rule: - SiWC auth can use app connectors, so app declarations stay available. - API-key/direct auth cannot use app connectors, so app declarations are removed. - When an active plugin has both an app and an MCP server with the same name, the app route wins for Codex-backed auth and the conflicting MCP server is hidden. Putting that rule in `capabilities.rs` gives the rest of the stack one place to ask instead of duplicating auth checks in loader, manager, marketplace, and details code. ## Validation - `cargo fmt` - `cargo test -p codex-core-plugins`
This commit is contained in:
committed by
GitHub
Unverified
parent
8aac63f477
commit
7e0dce91df
@@ -1,4 +1,6 @@
|
||||
use crate::OPENAI_CURATED_MARKETPLACE_NAME;
|
||||
use crate::app_mcp_routing::apply_app_mcp_routing_policy;
|
||||
use crate::app_mcp_routing::apps_route_available;
|
||||
use crate::manifest::PluginManifestHooks;
|
||||
use crate::manifest::PluginManifestPaths;
|
||||
use crate::manifest::load_plugin_manifest;
|
||||
@@ -1085,20 +1087,17 @@ pub async fn load_plugin_mcp_servers(
|
||||
auth_mode: Option<AuthMode>,
|
||||
) -> HashMap<String, McpServerConfig> {
|
||||
let mut mcp_servers = load_declared_plugin_mcp_servers(plugin_root).await;
|
||||
if !auth_mode.is_some_and(AuthMode::uses_codex_backend) || mcp_servers.is_empty() {
|
||||
if !apps_route_available(auth_mode) || mcp_servers.is_empty() {
|
||||
return mcp_servers;
|
||||
}
|
||||
|
||||
let app_declarations = load_plugin_apps(plugin_root).await;
|
||||
if app_declarations.is_empty() {
|
||||
return mcp_servers;
|
||||
}
|
||||
|
||||
let app_declaration_names = app_declarations
|
||||
.iter()
|
||||
.map(|app| app.name.as_str())
|
||||
.collect::<HashSet<_>>();
|
||||
mcp_servers.retain(|name, _| !app_declaration_names.contains(name.as_str()));
|
||||
let mut app_declarations = load_plugin_apps(plugin_root).await;
|
||||
apply_app_mcp_routing_policy(
|
||||
&mut app_declarations,
|
||||
&mut mcp_servers,
|
||||
auth_mode,
|
||||
/*plugin_active*/ true,
|
||||
);
|
||||
mcp_servers
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user