odysseus/routes
Amir Fathi 9d5c031914
Some checks failed
CI / Focused test guidance (report-only) (push) Has been cancelled
CI / Python syntax (compileall) (push) Has been cancelled
CI / JS syntax (node --check) (push) Has been cancelled
CI / Python tests (pytest) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (javascript-typescript) (push) Has been cancelled
CodeQL / Analyze (python) (push) Has been cancelled
ci / docker publish / build (amd64) (push) Has been cancelled
ci / docker publish / build (arm64) (push) Has been cancelled
ci / docker publish / merge manifest + tag (push) Has been cancelled
fix(mcp): reject malformed Args on Add MCP Server instead of silently defaulting to [] (#6215)
* fix(mcp): reject malformed Args on Add MCP Server instead of silently defaulting to []

* test(mcp): pass every Form param add_server reads past args validation

CI's pytest run showed test_add_server_still_accepts_valid_json_args and
test_add_server_still_defaults_empty_args_to_empty_list failing with
TypeError: the JSON object must be str, bytes or bytearray, not Form.

Calling the endpoint function directly bypasses FastAPI's dependency
resolution, so an unpassed Form(...) parameter (url, oauth_file,
oauth_config) arrives as the Form marker object itself rather than its
declared default, and add_server's later `if oauth_file:` check reads
that marker as truthy. The malformed-args test never hit this because it
raises before reaching that code. Not a production bug: a real HTTP
request resolves these through FastAPI before add_server ever runs.

* fix(mcp): reject non-list args and surface the new 400 in the Admin panel

o3LL's review on #6215 found two gaps in the args validation this PR adds:
the Admin panel posts to the same /api/mcp/servers endpoint but never
validates Args client-side, so the new 400 falls into the generic failure
branch and shows "Added but connection failed: unknown". Mirror the same
JSON.parse guard settings.js already has.

Also add an isinstance(list) check next to the existing JSON parse, since
valid-but-wrong-shaped JSON (args=5) reaches StdioServerParameters(args=5)
and 500s in the error formatter. Pre-existing on dev, same validation site
this PR already touches.

* fix(admin): surface the server's 400 detail instead of a generic connection-failed message

The Admin add-server handler read needs_oauth/connected/error but never
res.ok, so a request rejected by the isinstance(list) check added for
#6211 (args=5, a valid-JSON-but-non-list value the client-side JSON.parse
guard cannot catch) fell into the same-shape else branch as a successful
add whose connection attempt failed, and the form fields were cleared as
if the server had accepted it.
2026-09-11 15:36:41 +02:00
..
admin_wipe refactor(routes): move admin_wipe domain into routes/admin_wipe/ subpackage (#5659) 2026-07-21 12:39:27 +02:00
cleanup refactor(routes): move cleanup domain into routes/cleanup/ subpackage (#5658) 2026-07-21 12:38:32 +02:00
compare refactor(routes): move compare domain into routes/compare/ subpackage (#5660) 2026-07-21 12:40:09 +02:00
contacts Merge remote-tracking branch 'origin/dev' 2026-07-07 00:51:34 +00:00
document refactor(routes): move document domain into routes/document/ subpackage (#5885) 2026-08-04 03:54:55 -06:00
gallery fix(gallery): handle MPS float64 mask inputs (#5903) 2026-08-12 01:23:43 +01:00
history Merge commit from fork 2026-09-05 19:20:49 +02:00
mcp fix(mcp): reject malformed Args on Add MCP Server instead of silently defaulting to [] (#6215) 2026-09-11 15:36:41 +02:00
memory fix(memory): don't let an unreadable store get overwritten with an empty one (#5831) 2026-08-06 02:33:50 -06:00
note fix(reminders): support OAuth SMTP accounts (#5649) 2026-07-22 16:03:35 +02:00
research feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
search refactor(routes): move search domain into routes/search/ subpackage (#5779) 2026-07-28 22:26:29 +02:00
task refactor(routes): move task domain into routes/task/ subpackage 2026-08-17 10:07:17 +08:00
vault refactor(routes): move vault domain into routes/vault/ subpackage (#5780) 2026-08-03 20:44:00 +02:00
webhook refactor(routes): move webhook domain into routes/webhook/ subpackage (#5781) 2026-08-03 20:44:31 +02:00
__init__.py Odysseus v1.0 2026-05-31 23:58:26 +09:00
_validators.py fix(hwfit): validate remote SSH detection targets (#3718) 2026-06-11 00:43:49 +02:00
admin_wipe_routes.py refactor(routes): move admin_wipe domain into routes/admin_wipe/ subpackage (#5659) 2026-07-21 12:39:27 +02:00
api_token_routes.py fix(api): normalize non-object JSON bodies to empty dict in token PATCH (#3976) 2026-06-15 18:05:15 +01:00
assistant_routes.py feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
auth_routes.py fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
backup_routes.py fix(memory): don't let an unreadable store get overwritten with an empty one (#5831) 2026-08-06 02:33:50 -06:00
calendar_routes.py fix(calendar): keep default creation transactional (#5806) 2026-08-12 04:51:52 +01:00
chat_helpers.py fix(agent): allow remaining actions for an approved task (#6113) 2026-08-19 08:01:34 -06:00
chat_routes.py Merge commit from fork 2026-09-05 19:20:49 +02:00
chatgpt_subscription_routes.py feat: add ChatGPT Subscription provider (#2876) 2026-06-08 10:19:18 +02:00
cleanup_routes.py refactor(routes): move cleanup domain into routes/cleanup/ subpackage (#5658) 2026-07-21 12:38:32 +02:00
codex_routes.py fix: improve uploaded document retrieval and deep research reuse (#4784) 2026-06-27 19:24:17 +01:00
compare_routes.py refactor(routes): move compare domain into routes/compare/ subpackage (#5660) 2026-07-21 12:40:09 +02:00
contacts_routes.py Merge remote-tracking branch 'origin/dev' 2026-07-07 00:51:34 +00:00
cookbook_helpers.py fix(cookbook): activate local Windows venv in bash runner (#5734) 2026-08-18 16:19:33 +02:00
cookbook_output.py fix(cookbook): report dead finished downloads as completed instead of stopped (#4025) 2026-06-15 15:26:55 +09:00
cookbook_routes.py fix(cookbook): activate local Windows venv in bash runner (#5734) 2026-08-18 16:19:33 +02:00
copilot_routes.py feat: add ChatGPT Subscription provider (#2876) 2026-06-08 10:19:18 +02:00
device_flow.py feat: add ChatGPT Subscription provider (#2876) 2026-06-08 10:19:18 +02:00
diagnostics_routes.py feat(ui): add real-time diagnostic logs console (#974) 2026-06-15 10:32:51 +02:00
document_helpers.py refactor(routes): move document domain into routes/document/ subpackage (#5885) 2026-08-04 03:54:55 -06:00
document_routes.py refactor(routes): move document domain into routes/document/ subpackage (#5885) 2026-08-04 03:54:55 -06:00
editor_draft_routes.py Ignore invalid editor draft payloads (#1533) 2026-06-03 14:07:03 +09:00
email_helpers.py fix(email): route summaries through shared LLM adapter (#5841) 2026-08-08 23:06:41 +02:00
email_pollers.py fix(email): route summaries through shared LLM adapter (#5841) 2026-08-08 23:06:41 +02:00
email_routes.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
embedding_routes.py feat(paths): abstract runtime path logic for frozen distribution packages (#969) 2026-06-15 17:44:10 +01:00
emoji_routes.py refactor(constants): single source of truth for data dir (#3368) 2026-06-08 09:58:52 +02:00
font_routes.py Keep compact font family names together (#1263) 2026-06-03 14:24:30 +09:00
gallery_helpers.py Merge dev into main for testing 2026-06-28 14:07:23 +00:00
gallery_routes.py Merge dev into main for testing 2026-06-28 14:07:23 +00:00
history_routes.py refactor(routes): move history domain into routes/history/ subpackage (#5090) 2026-07-04 13:36:35 +02:00
hwfit_routes.py Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
mcp_routes.py refactor(routes): move mcp domain into routes/mcp/ subpackage (#5899) 2026-08-11 02:24:55 -06:00
memory_routes.py refactor(routes): move memory domain into routes/memory/ subpackage (#5007) 2026-06-30 17:52:14 +02:00
model_routes.py fix(models): show API models by default (#6089) 2026-08-17 13:41:04 +02:00
note_routes.py refactor(routes): move note domain into routes/note/ subpackage (#5236) 2026-07-20 13:52:30 +02:00
personal_routes.py fix(personal): run directory indexing off the event loop (#5634) 2026-08-15 10:12:47 +01:00
prefs_routes.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
preset_routes.py fix(ai): offload model resolution from async paths 2026-06-28 00:48:35 +01:00
research_routes.py refactor(routes): move research domain into routes/research/ subpackage 2026-06-28 14:34:11 +01:00
search_routes.py refactor(routes): move search domain into routes/search/ subpackage (#5779) 2026-07-28 22:26:29 +02:00
session_routes.py Merge commit from fork 2026-09-05 19:20:49 +02:00
shell_routes.py Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
signature_routes.py Constrain signature uploads to PNG data (#2844) 2026-06-05 13:17:43 +02:00
skills_routes.py fix(agent): allow remaining actions for an approved task (#6113) 2026-08-19 08:01:34 -06:00
stt_routes.py refactor(uploads): centralize upload byte-limits in upload_limits.py (#3364) (#3518) 2026-06-09 01:24:30 +02:00
task_routes.py refactor(routes): move task domain into routes/task/ subpackage 2026-08-17 10:07:17 +08:00
tts_routes.py Odysseus v1.0 2026-05-31 23:58:26 +09:00
upload_routes.py fix(stabilization): harden attachment lifecycle and agent guard signals (#5420) 2026-07-11 15:14:14 +01:00
vault_routes.py refactor(routes): move vault domain into routes/vault/ subpackage (#5780) 2026-08-03 20:44:00 +02:00
webhook_routes.py refactor(routes): move webhook domain into routes/webhook/ subpackage (#5781) 2026-08-03 20:44:31 +02:00
workspace_routes.py feat(agent): confine agent file/shell tools to a selectable workspace (#3665) 2026-06-11 18:17:54 +02:00