mcp door: mint workspace-owner service session for team runtime bearer
The runtime template's static clawmates_door bearer is rejected by cm_auth::authenticate() (needs an auth_sessions row). Every per-team agent was getting `unauthorized: missing or invalid bearer token` and `0 tool(s) registered from 0 server(s)`. Add AuthService::mint_service_session + users::owner_of_workspace and mint a 30d service session in try_team_gateway_url; inject it into the freshly-spawned team container's config.toml [[mcp.servers]] clawmates Authorization header via prewrite_daemon_config_with_risk (bearer arg). Follow-up: apply the same pattern to research::spawn (per-topic) and per-loop spawn paths. Co-Authored-By: Claude Opus 4.7 <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
8cd0c7bd01
commit
49f94a5360
@@ -72,6 +72,25 @@ pub async fn find_by_email(pool: &PgPool, email: &str) -> Result<User, DbError>
|
||||
})
|
||||
}
|
||||
|
||||
/// The workspace's owner (earliest-joined user with role=owner). Used by
|
||||
/// internal service paths (e.g. per-team runtime MCP auth) that need to
|
||||
/// mint a bearer scoped to the workspace but don't have a caller in hand.
|
||||
pub async fn owner_of_workspace(
|
||||
pool: &PgPool,
|
||||
workspace_id: WorkspaceId,
|
||||
) -> Result<UserId, DbError> {
|
||||
let row = sqlx::query!(
|
||||
"SELECT id FROM users
|
||||
WHERE workspace_id = $1 AND role = 'owner'
|
||||
ORDER BY created_at, id
|
||||
LIMIT 1",
|
||||
workspace_id.as_uuid(),
|
||||
)
|
||||
.fetch_one(pool)
|
||||
.await?;
|
||||
Ok(UserId::from(row.id))
|
||||
}
|
||||
|
||||
/// Members table for the Team page (§8.3), in join order.
|
||||
pub async fn list_by_workspace(
|
||||
pool: &PgPool,
|
||||
|
||||
Reference in New Issue
Block a user