1 Commits

Author SHA1 Message Date
024f14000e release: 0.1.4 — forward cp_jwt + bucket via params._meta
All checks were successful
build / test (push) Successful in 29s
publish / npm (push) Successful in 30s
On login the gateway now captures user.id from /v1/auth/login, derives
the user's MinIO bucket (user-<id>-files), and persists both in
~/.a2a/credentials.json. UpstreamAgent.callTool injects
``params._meta = { cp_jwt, cp_url, bucket }`` on every tools/call so
upstream agents see the same caller context the platform orchestrator
provides. Unauthenticated clients omit _meta — back-compat preserved.

Requires a2a-pack with the matching _meta handler in
``a2a_pack/mcp/server.py`` (companion change in apps/a2a).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 20:53:07 -03:00
7 changed files with 67 additions and 29 deletions

4
package-lock.json generated
View File

@@ -1,12 +1,12 @@
{ {
"name": "a2amcp", "name": "a2amcp",
"version": "0.1.3", "version": "0.1.4",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "a2amcp", "name": "a2amcp",
"version": "0.1.3", "version": "0.1.4",
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"@modelcontextprotocol/sdk": "^1.0.4", "@modelcontextprotocol/sdk": "^1.0.4",

View File

@@ -1,6 +1,6 @@
{ {
"name": "a2amcp", "name": "a2amcp",
"version": "0.1.3", "version": "0.1.4",
"description": "MCP gateway for a2acloud agents. Run as a local MCP server; expose any number of deployed A2A agents to Claude Code, Cursor, and other MCP clients.", "description": "MCP gateway for a2acloud agents. Run as a local MCP server; expose any number of deployed A2A agents to Claude Code, Cursor, and other MCP clients.",
"type": "module", "type": "module",
"bin": { "bin": {

View File

@@ -52,23 +52,21 @@ export class ControlPlaneClient {
} }
login(email: string, password: string) { login(email: string, password: string) {
return this.request<{ access_token: string; user: { email: string } }>( return this.request<{
"POST", access_token: string;
"/v1/auth/login", user: { id: number; email: string };
{ email, password }, }>("POST", "/v1/auth/login", { email, password });
);
} }
signup(email: string, password: string) { signup(email: string, password: string) {
return this.request<{ access_token: string; user: { email: string } }>( return this.request<{
"POST", access_token: string;
"/v1/auth/signup", user: { id: number; email: string };
{ email, password }, }>("POST", "/v1/auth/signup", { email, password });
);
} }
me() { me() {
return this.request<{ email: string }>("GET", "/v1/me"); return this.request<{ id: number; email: string }>("GET", "/v1/me");
} }
listAgents() { listAgents() {

View File

@@ -92,7 +92,14 @@ program
const api = resolveApiUrl(opts.api); const api = resolveApiUrl(opts.api);
try { try {
const out = await new ControlPlaneClient(api, null).login(email, password); const out = await new ControlPlaneClient(api, null).login(email, password);
await saveCredentials({ apiUrl: api, token: out.access_token, email: out.user.email }); const bucket = `user-${out.user.id}-files`;
await saveCredentials({
apiUrl: api,
token: out.access_token,
email: out.user.email,
userId: out.user.id,
bucket,
});
output.write(`logged in as ${out.user.email} @ ${api}\n`); output.write(`logged in as ${out.user.email} @ ${api}\n`);
} catch (err) { } catch (err) {
fail(err instanceof ApiError ? err.message : (err as Error).message); fail(err instanceof ApiError ? err.message : (err as Error).message);

View File

@@ -14,6 +14,8 @@ export interface Credentials {
apiUrl: string; apiUrl: string;
token: string; token: string;
email: string; email: string;
userId?: number;
bucket?: string;
} }
const credsDir = () => path.join(os.homedir(), ".a2a"); const credsDir = () => path.join(os.homedir(), ".a2a");
@@ -28,6 +30,8 @@ export async function loadCredentials(): Promise<Credentials | null> {
apiUrl: data.api_url ?? DEFAULT_API_URL, apiUrl: data.api_url ?? DEFAULT_API_URL,
token: data.token, token: data.token,
email: data.email ?? "", email: data.email ?? "",
userId: typeof data.user_id === "number" ? data.user_id : undefined,
bucket: typeof data.bucket === "string" ? data.bucket : undefined,
}; };
} catch (err: any) { } catch (err: any) {
if (err?.code === "ENOENT") return null; if (err?.code === "ENOENT") return null;
@@ -37,11 +41,14 @@ export async function loadCredentials(): Promise<Credentials | null> {
export async function saveCredentials(c: Credentials): Promise<void> { export async function saveCredentials(c: Credentials): Promise<void> {
await fs.mkdir(credsDir(), { recursive: true }); await fs.mkdir(credsDir(), { recursive: true });
await fs.writeFile( const out: Record<string, unknown> = {
credsFile(), api_url: c.apiUrl,
JSON.stringify({ api_url: c.apiUrl, token: c.token, email: c.email }), token: c.token,
{ mode: 0o600 }, email: c.email,
); };
if (c.userId !== undefined) out.user_id = c.userId;
if (c.bucket !== undefined) out.bucket = c.bucket;
await fs.writeFile(credsFile(), JSON.stringify(out), { mode: 0o600 });
} }
export async function clearCredentials(): Promise<boolean> { export async function clearCredentials(): Promise<boolean> {

View File

@@ -39,14 +39,25 @@ export interface GatewayHandle {
export async function buildGateway(opts: GatewayOptions = {}): Promise<GatewayHandle> { export async function buildGateway(opts: GatewayOptions = {}): Promise<GatewayHandle> {
const cfg = opts.agents ?? (await loadConfig()).agents; const cfg = opts.agents ?? (await loadConfig()).agents;
const token = const creds = opts.token !== undefined ? null : await loadCredentials();
opts.token !== undefined const token = opts.token !== undefined ? opts.token : creds?.token ?? null;
? opts.token // Forward CP credentials + bucket as params._meta so upstream agents
: (await loadCredentials())?.token ?? null; // can act on behalf of the caller (mirrors the platform-orchestrator
// call shape). When the user isn't logged in, _meta is omitted and
// upstream sees the same unauthenticated context as before.
const cpJwt = creds?.token ?? null;
const cpUrl = creds?.apiUrl ?? null;
const bucket = creds?.bucket ?? null;
const upstreams = new Map<string, UpstreamAgent>(); const upstreams = new Map<string, UpstreamAgent>();
for (const a of cfg) { for (const a of cfg) {
upstreams.set(a.name, new UpstreamAgent({ name: a.name, url: a.url, token })); upstreams.set(
a.name,
new UpstreamAgent({
name: a.name, url: a.url, token,
cpJwt, cpUrl, bucket,
}),
);
} }
const server = const server =

View File

@@ -12,6 +12,18 @@ export interface UpstreamConfig {
name: string; name: string;
url: string; url: string;
token: string | null; token: string | null;
/** Forwarded to the upstream as ``params._meta.cp_jwt`` on tools/call.
* Lets the upstream agent act on the caller's behalf (file/agent CRUD
* on /v1/me/*) — same path the platform orchestrator uses. */
cpJwt?: string | null;
/** Paired with ``cpJwt``. The upstream agent uses this as the base URL
* when calling back into /v1/me/*. */
cpUrl?: string | null;
/** User's MinIO bucket (``user-<id>-files``). Forwarded as
* ``params._meta.bucket`` so agents that touch the workspace
* (agent-builder, file tools) get a context whose
* ``ctx.workspace.bucket`` resolves to the right bucket. */
bucket?: string | null;
} }
export interface UpstreamTool { export interface UpstreamTool {
@@ -88,9 +100,12 @@ export class UpstreamAgent {
name: string, name: string,
arguments_: Record<string, unknown>, arguments_: Record<string, unknown>,
): Promise<UpstreamCallResult> { ): Promise<UpstreamCallResult> {
return this.rpc<UpstreamCallResult>("tools/call", { const meta: Record<string, unknown> = {};
name, if (this.cfg.cpJwt) meta.cp_jwt = this.cfg.cpJwt;
arguments: arguments_, if (this.cfg.cpUrl) meta.cp_url = this.cfg.cpUrl;
}); if (this.cfg.bucket) meta.bucket = this.cfg.bucket;
const params: Record<string, unknown> = { name, arguments: arguments_ };
if (Object.keys(meta).length > 0) params._meta = meta;
return this.rpc<UpstreamCallResult>("tools/call", params);
} }
} }