release: 0.1.4 — forward cp_jwt + bucket via params._meta
On login the gateway now captures user.id from /v1/auth/login, derives
the user's MinIO bucket (user-<id>-files), and persists both in
~/.a2a/credentials.json. UpstreamAgent.callTool injects
``params._meta = { cp_jwt, cp_url, bucket }`` on every tools/call so
upstream agents see the same caller context the platform orchestrator
provides. Unauthenticated clients omit _meta — back-compat preserved.
Requires a2a-pack with the matching _meta handler in
``a2a_pack/mcp/server.py`` (companion change in apps/a2a).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -39,14 +39,25 @@ export interface GatewayHandle {
|
||||
|
||||
export async function buildGateway(opts: GatewayOptions = {}): Promise<GatewayHandle> {
|
||||
const cfg = opts.agents ?? (await loadConfig()).agents;
|
||||
const token =
|
||||
opts.token !== undefined
|
||||
? opts.token
|
||||
: (await loadCredentials())?.token ?? null;
|
||||
const creds = opts.token !== undefined ? null : await loadCredentials();
|
||||
const token = opts.token !== undefined ? opts.token : creds?.token ?? null;
|
||||
// Forward CP credentials + bucket as params._meta so upstream agents
|
||||
// can act on behalf of the caller (mirrors the platform-orchestrator
|
||||
// call shape). When the user isn't logged in, _meta is omitted and
|
||||
// upstream sees the same unauthenticated context as before.
|
||||
const cpJwt = creds?.token ?? null;
|
||||
const cpUrl = creds?.apiUrl ?? null;
|
||||
const bucket = creds?.bucket ?? null;
|
||||
|
||||
const upstreams = new Map<string, UpstreamAgent>();
|
||||
for (const a of cfg) {
|
||||
upstreams.set(a.name, new UpstreamAgent({ name: a.name, url: a.url, token }));
|
||||
upstreams.set(
|
||||
a.name,
|
||||
new UpstreamAgent({
|
||||
name: a.name, url: a.url, token,
|
||||
cpJwt, cpUrl, bucket,
|
||||
}),
|
||||
);
|
||||
}
|
||||
|
||||
const server =
|
||||
|
||||
Reference in New Issue
Block a user