odysseus/routes
Léo 2e2bb5231e
Some checks are pending
CI / Focused test guidance (report-only) (push) Waiting to run
CI / Python syntax (compileall) (push) Waiting to run
CI / JS syntax (node --check) (push) Waiting to run
CI / Python tests (pytest) (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
ci / docker publish / build (amd64) (push) Waiting to run
ci / docker publish / build (arm64) (push) Waiting to run
ci / docker publish / merge manifest + tag (push) Blocked by required conditions
fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032)
* fix(mcp): stop assuming http://localhost:7000 for the OAuth callback

The MCP OAuth callback origin is wrong on any install not reached at
http://localhost:7000, and on Docker it cannot be corrected at all.
Three sites, one assumption:

- The redirect base fell back to a fixed port 7000. The app binds APP_PORT
  natively (app.py, launcher.py) and the macOS launcher defaults to 7860,
  where 7000 is AirPlay Receiver, so the callback lands on another service
  entirely. The fallback now follows APP_PORT. The hostname stays localhost
  rather than internal_api_base()'s 127.0.0.1: this URI is registered with
  the authorization server, so changing the host would invalidate the
  registrations that already exist.

- The paste-back form hardcoded an http:// action. Serving the page over
  HTTPS, Chrome raises its insecure-form interstitial, and overriding that
  posts plain HTTP at a TLS port, which fails too. Either way the
  authorization code never reaches Odysseus. The action now carries the
  scheme the request arrived on.

- OAUTH_REDIRECT_BASE_URL is the only fix available to a Docker install,
  because the container listens on 7000 and cannot see the host port map,
  but compose never forwarded it and nothing documented it. Both fixed.

* fix(mcp): make the paste-back form action relative and export APP_PORT

Answers the review on #6032. Three of the fixes did not survive contact with
the deployments they targeted.

- The form action derived its scheme from request.url.scheme. uvicorn only
  honours X-Forwarded-Proto from a peer inside --forwarded-allow-ips, which
  defaults to 127.0.0.1; the Dockerfile CMD sets no override, so a proxy
  arriving over the Docker bridge is untrusted and the scheme stays http.
  That is mixed content on exactly the HTTPS installs paste-back exists for.
  A relative action is resolved by the browser against the origin the page
  came from, which is right under every proxy setup, and it drops the Host
  header from the page entirely.

- The APP_PORT fallback never fired for the shipped launchers. start-macos.sh,
  the generated .app launcher and launch-windows.ps1 all pass --port to
  uvicorn without putting the value in the environment, so the motivating
  case, macOS on 7860, still registered localhost:7000. Each now exports it.
  internal_api_base() and companion pairing read APP_PORT too and were wrong
  in the same way.

- .env.example pointed Google MCP servers at OAUTH_REDIRECT_BASE_URL.
  add_server writes Desktop App credentials, and Google only accepts loopback
  redirects for that client type, so a public origin comes back as
  redirect_uri_mismatch. The variable is for the DCR flow; Google stays on the
  loopback default and finishes remotely through paste-back.

The Host header is no longer reflected into the page, so the escaping
regression test asserts its absence instead of its escaping.
2026-08-15 23:09:01 -06:00
..
admin_wipe refactor(routes): move admin_wipe domain into routes/admin_wipe/ subpackage (#5659) 2026-07-21 12:39:27 +02:00
cleanup refactor(routes): move cleanup domain into routes/cleanup/ subpackage (#5658) 2026-07-21 12:38:32 +02:00
compare refactor(routes): move compare domain into routes/compare/ subpackage (#5660) 2026-07-21 12:40:09 +02:00
contacts Merge remote-tracking branch 'origin/dev' 2026-07-07 00:51:34 +00:00
document refactor(routes): move document domain into routes/document/ subpackage (#5885) 2026-08-04 03:54:55 -06:00
gallery fix(gallery): handle MPS float64 mask inputs (#5903) 2026-08-12 01:23:43 +01:00
history fix(history): defer full transcript hydration to model sends (#5929) 2026-08-10 19:39:21 +01:00
mcp fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032) 2026-08-15 23:09:01 -06:00
memory fix(memory): don't let an unreadable store get overwritten with an empty one (#5831) 2026-08-06 02:33:50 -06:00
note fix(reminders): support OAuth SMTP accounts (#5649) 2026-07-22 16:03:35 +02:00
research feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
search refactor(routes): move search domain into routes/search/ subpackage (#5779) 2026-07-28 22:26:29 +02:00
vault refactor(routes): move vault domain into routes/vault/ subpackage (#5780) 2026-08-03 20:44:00 +02:00
webhook refactor(routes): move webhook domain into routes/webhook/ subpackage (#5781) 2026-08-03 20:44:31 +02:00
__init__.py Odysseus v1.0 2026-05-31 23:58:26 +09:00
_validators.py fix(hwfit): validate remote SSH detection targets (#3718) 2026-06-11 00:43:49 +02:00
admin_wipe_routes.py refactor(routes): move admin_wipe domain into routes/admin_wipe/ subpackage (#5659) 2026-07-21 12:39:27 +02:00
api_token_routes.py fix(api): normalize non-object JSON bodies to empty dict in token PATCH (#3976) 2026-06-15 18:05:15 +01:00
assistant_routes.py feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
auth_routes.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
backup_routes.py fix(memory): don't let an unreadable store get overwritten with an empty one (#5831) 2026-08-06 02:33:50 -06:00
calendar_routes.py fix(calendar): keep default creation transactional (#5806) 2026-08-12 04:51:52 +01:00
chat_helpers.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
chat_routes.py fix(agent): retire superseded approvals 2026-08-15 07:49:52 +00:00
chatgpt_subscription_routes.py feat: add ChatGPT Subscription provider (#2876) 2026-06-08 10:19:18 +02:00
cleanup_routes.py refactor(routes): move cleanup domain into routes/cleanup/ subpackage (#5658) 2026-07-21 12:38:32 +02:00
codex_routes.py fix: improve uploaded document retrieval and deep research reuse (#4784) 2026-06-27 19:24:17 +01:00
compare_routes.py refactor(routes): move compare domain into routes/compare/ subpackage (#5660) 2026-07-21 12:40:09 +02:00
contacts_routes.py Merge remote-tracking branch 'origin/dev' 2026-07-07 00:51:34 +00:00
cookbook_helpers.py Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
cookbook_output.py fix(cookbook): report dead finished downloads as completed instead of stopped (#4025) 2026-06-15 15:26:55 +09:00
cookbook_routes.py fix(cookbook): record real Windows pid for local serve so Stop kills the model (#5912) 2026-08-12 10:32:24 +01:00
copilot_routes.py feat: add ChatGPT Subscription provider (#2876) 2026-06-08 10:19:18 +02:00
device_flow.py feat: add ChatGPT Subscription provider (#2876) 2026-06-08 10:19:18 +02:00
diagnostics_routes.py feat(ui): add real-time diagnostic logs console (#974) 2026-06-15 10:32:51 +02:00
document_helpers.py refactor(routes): move document domain into routes/document/ subpackage (#5885) 2026-08-04 03:54:55 -06:00
document_routes.py refactor(routes): move document domain into routes/document/ subpackage (#5885) 2026-08-04 03:54:55 -06:00
editor_draft_routes.py Ignore invalid editor draft payloads (#1533) 2026-06-03 14:07:03 +09:00
email_helpers.py fix(email): route summaries through shared LLM adapter (#5841) 2026-08-08 23:06:41 +02:00
email_pollers.py fix(email): route summaries through shared LLM adapter (#5841) 2026-08-08 23:06:41 +02:00
email_routes.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
embedding_routes.py feat(paths): abstract runtime path logic for frozen distribution packages (#969) 2026-06-15 17:44:10 +01:00
emoji_routes.py refactor(constants): single source of truth for data dir (#3368) 2026-06-08 09:58:52 +02:00
font_routes.py Keep compact font family names together (#1263) 2026-06-03 14:24:30 +09:00
gallery_helpers.py Merge dev into main for testing 2026-06-28 14:07:23 +00:00
gallery_routes.py Merge dev into main for testing 2026-06-28 14:07:23 +00:00
history_routes.py refactor(routes): move history domain into routes/history/ subpackage (#5090) 2026-07-04 13:36:35 +02:00
hwfit_routes.py Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
mcp_routes.py refactor(routes): move mcp domain into routes/mcp/ subpackage (#5899) 2026-08-11 02:24:55 -06:00
memory_routes.py refactor(routes): move memory domain into routes/memory/ subpackage (#5007) 2026-06-30 17:52:14 +02:00
model_routes.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
note_routes.py refactor(routes): move note domain into routes/note/ subpackage (#5236) 2026-07-20 13:52:30 +02:00
personal_routes.py fix(personal): run directory indexing off the event loop (#5634) 2026-08-15 10:12:47 +01:00
prefs_routes.py refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
preset_routes.py fix(ai): offload model resolution from async paths 2026-06-28 00:48:35 +01:00
research_routes.py refactor(routes): move research domain into routes/research/ subpackage 2026-06-28 14:34:11 +01:00
search_routes.py refactor(routes): move search domain into routes/search/ subpackage (#5779) 2026-07-28 22:26:29 +02:00
session_routes.py fix(history): defer full transcript hydration to model sends (#5929) 2026-08-10 19:39:21 +01:00
shell_routes.py Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
signature_routes.py Constrain signature uploads to PNG data (#2844) 2026-06-05 13:17:43 +02:00
skills_routes.py fix(agent): close approval continuation gaps 2026-08-15 06:14:37 +00:00
stt_routes.py refactor(uploads): centralize upload byte-limits in upload_limits.py (#3364) (#3518) 2026-06-09 01:24:30 +02:00
task_routes.py fix(tasks): gate cookbook serve task execution (#5235) 2026-07-05 13:19:04 +01:00
tts_routes.py Odysseus v1.0 2026-05-31 23:58:26 +09:00
upload_routes.py fix(stabilization): harden attachment lifecycle and agent guard signals (#5420) 2026-07-11 15:14:14 +01:00
vault_routes.py refactor(routes): move vault domain into routes/vault/ subpackage (#5780) 2026-08-03 20:44:00 +02:00
webhook_routes.py refactor(routes): move webhook domain into routes/webhook/ subpackage (#5781) 2026-08-03 20:44:31 +02:00
workspace_routes.py feat(agent): confine agent file/shell tools to a selectable workspace (#3665) 2026-06-11 18:17:54 +02:00