mcp door: mint workspace-owner service session for team runtime bearer
ci / gates (push) Successful in 5s
ci / rust (push) Failing after 10s
ci / frontend (push) Successful in 25s
ci / e2e (push) Skipped
ci / publish (push) Skipped

The runtime template's static clawmates_door bearer is rejected by
cm_auth::authenticate() (needs an auth_sessions row). Every per-team
agent was getting `unauthorized: missing or invalid bearer token` and
`0 tool(s) registered from 0 server(s)`.

Add AuthService::mint_service_session + users::owner_of_workspace and
mint a 30d service session in try_team_gateway_url; inject it into the
freshly-spawned team container's config.toml [[mcp.servers]] clawmates
Authorization header via prewrite_daemon_config_with_risk (bearer arg).

Follow-up: apply the same pattern to research::spawn (per-topic) and
per-loop spawn paths.

Co-Authored-By: Claude Opus 4.7 <[email protected]>
This commit is contained in:
Omar Sobh
2026-07-18 13:37:27 -07:00
co-authored by Claude Opus 4.7
parent 8cd0c7bd01
commit 49f94a5360
4 changed files with 124 additions and 9 deletions
+19
View File
@@ -72,6 +72,25 @@ pub async fn find_by_email(pool: &PgPool, email: &str) -> Result<User, DbError>
})
}
/// The workspace's owner (earliest-joined user with role=owner). Used by
/// internal service paths (e.g. per-team runtime MCP auth) that need to
/// mint a bearer scoped to the workspace but don't have a caller in hand.
pub async fn owner_of_workspace(
pool: &PgPool,
workspace_id: WorkspaceId,
) -> Result<UserId, DbError> {
let row = sqlx::query!(
"SELECT id FROM users
WHERE workspace_id = $1 AND role = 'owner'
ORDER BY created_at, id
LIMIT 1",
workspace_id.as_uuid(),
)
.fetch_one(pool)
.await?;
Ok(UserId::from(row.id))
}
/// Members table for the Team page (§8.3), in join order.
pub async fn list_by_workspace(
pool: &PgPool,