13 Commits

Author SHA1 Message Date
can1357 5073602977 docs(mcp): clarify translated config precedence 2026-08-05 01:11:58 +02:00
roboomp 9f92d36425 fix(mcp): ordered project entries before user in translated importers
The Claude/Cursor/Gemini/Windsurf importers appended user entries before
project entries, so a project `enabled: false` could not claim its dedupe key
ahead of a same-named user server and the disable was silently ignored. Load
project entries first, matching the native/Codex loaders, so a project disable
suppresses a same-named user server.

Updated docs/mcp-config.md to reflect the project-first precedence and added
compound regression coverage.

Fixes #7652
2026-08-04 21:14:11 +00:00
can1357 ebd5e3f86f chore: update stale docs 2026-08-03 16:39:23 +02:00
Ogrodev f9bc96e96c fix(coding-agent): harden profile auth shipping gaps 2026-06-14 20:30:50 -03:00
Ogrodev dbe6c57576 Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias 2026-06-12 11:31:37 -03:00
can1357 371846167b docs: update docs 2026-06-12 14:43:35 +02:00
Ogrodev 2f60eaf938 feat(coding-agent): bind MCP OAuth credentials per profile via url-keyed ids
Store MCP OAuth credentials under deterministic mcp_oauth:<url> ids in each
profile's agent.db with refresh material embedded, so a definition-only entry
in a shared project mcp.json resolves each profile's own credential instead
of profiles clobbering each other's auth.credentialId pointer.

- Refresh material is single-source: embedded credential fields win over the
  config auth block (which may belong to another profile); legacy rows fall
  back to the auth block wholesale
- Wire the 401 refresh hook off the resolvable credential, not the auth
  block, so definition-only bindings refresh mid-session too
- The url-keyed fallback never overrides a pinned Authorization header
- Send prompt=consent by default (oauth.prompt to override, "" to omit) so
  reauth can switch accounts past an active browser session
- /mcp reauth fails fast on stdio transports (with an mcp-remote ~/.mcp-auth
  hint), probes http/sse without OAuth injection, GCs the superseded legacy
  row only after the flow succeeds, and leaves definition-only entries
  untouched on disk
- DCR-issued client secrets stay embedded in the stored credential and are
  never written into config files; user-supplied secrets survive reauth
2026-06-10 18:40:07 -03:00
Ogrodev b99039ded2 fix(coding-agent): profile-scope native config discovery and load symlinked extension dirs
Native user-level config discovery (MCP, skills, rules, slash commands, prompts, instructions, hooks, tools, settings, extensions, and the top-level SYSTEM.md/RULES.md/AGENTS.md) now resolves the user scope through getAgentDir() in builtin.ts, omp-extension-roots.ts, and the discovery-layer getUserPath() helper. A named profile sees only its own ~/.omp/profiles/<name>/agent config instead of the default profile's ~/.omp/agent leaking into every profile, matching the /mcp config writer and getMCPConfigPath("user").

discoverExtensionModulePaths now detects top-level symlinked directories that the native glob skips (follow_links=false) and synthesizes their index/package.json entry-point matches, so an extension shared across profiles via a symlink loads like a real directory. Symlinked extension files were already handled.

cli: check --tiny-worker on the profile-flag-stripped resolvedArgv, matching the adjacent --smoke-test check and launch routing.
2026-06-04 15:07:55 -03:00
can1357 1dba122c53 chore: updated docs 2026-05-31 04:36:14 +02:00
SUPREME e415adecd5 Allow disabling MCP client timeouts 2026-05-26 22:05:41 +05:30
can1357 9865a4ce6c docs: update docs 2026-04-30 06:47:01 +02:00
makoMakoGo cd84ccfb75 fix(docs): correct user MCP config path to ~/.omp/agent/mcp.json
fixes stale docs/schema that referenced ~/.omp/mcp.json

Related: #462, #264
2026-04-11 10:21:31 +08:00
can1357 66c80fd613 feat: add MCP JSON schema and documentation
fixes #462
2026-03-18 22:43:59 +01:00