feat(core): improve mcp management (#15221)

#### PR Dependency Tree


* **PR #15221** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added MCP credential management (create/reveal, list, rotate, revoke)
with expiration and status tracking.
* Introduced read-only vs read/write access modes, with read/write
tooling enabled only when permitted.
* Added workspace MCP credential configuration UI, including token
reveal and setup generation.
  * Added MCP credential GraphQL APIs to back the UI.
* **Changes**
* Replaced legacy access-token support with MCP credentials across
authentication and realtime updates.
* **Bug Fixes**
* MCP authentication now reliably rejects revoked, rotated, expired, or
disabled-user credentials.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
DarkSky
2026-07-12 19:30:44 +08:00
committed by GitHub
parent abf37d3dfa
commit 9b81c6debd
57 changed files with 2180 additions and 1213 deletions

View File

@@ -34,6 +34,7 @@
},
"devDependencies": {
"@affine-tools/utils": "workspace:*",
"@affine/auth": "workspace:*",
"@affine/i18n": "workspace:*",
"@affine/native": "workspace:*",
"@affine/nbstore": "workspace:*",
@@ -75,7 +76,6 @@
"zod": "^3.25.76"
},
"dependencies": {
"@affine/auth": "workspace:*",
"async-call-rpc": "^6.4.2",
"electron-updater": "^6.8.3",
"link-preview-js": "^4.0.0",

View File

@@ -3,9 +3,27 @@ import path from 'node:path';
import * as esbuild from 'esbuild';
import { config, mode, rootDir } from './common';
import { config, electronDir, mode, rootDir } from './common';
async function assertNoRuntimeWorkspaceDependencies() {
const packageJson = JSON.parse(
await fs.readFile(path.resolve(electronDir, 'package.json'), 'utf8')
) as { dependencies?: Record<string, string> };
const workspaceDependencies = Object.entries(
packageJson.dependencies ?? {}
).filter(([, version]) => version.startsWith('workspace:'));
if (workspaceDependencies.length) {
throw new Error(
`Electron workspace dependencies must be bundled and declared as devDependencies: ${workspaceDependencies
.map(([name]) => name)
.join(', ')}`
);
}
}
async function buildLayers() {
await assertNoRuntimeWorkspaceDependencies();
const common = config();
const define: Record<string, string> = {

View File

@@ -7,8 +7,8 @@
},
"include": ["./src"],
"references": [
{ "path": "../../../common/auth" },
{ "path": "../../../../tools/utils" },
{ "path": "../../../common/auth" },
{ "path": "../../i18n" },
{ "path": "../../native" },
{ "path": "../../../common/nbstore" },