feat: adds authentication to mcp server under feature flag (#9095)

* init auth forms

* Add iam endpoint

* Add radix radio

* Add radio group UI element

* Add IAM endpoint to types

* Add auth modal

* Remove auth from tools component

* Add auth modal to mcp server tab

* Add placeholders to fields

* Add dynamic headers

* changed authentication name

* CHanged paddings

* Added header and button under feature flag

* [autofix.ci] apply automated fixes

* update api key form field

* add credential handling and fix feature flag

* Update autologin condition

* design update

* style updates

* ci details

* revert ci logs

* test update, ff name update, and username + pass -> basic

* restore ci

* default fix

* added iam endpoint

* add oauth

* remove secretstr

* updated backend test and schema

* updated test

* updated test user can update

* test fix

---------

Co-authored-by: Mike Fortman <michael.fortman@datastax.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
This commit is contained in:
Lucas Oliveira 2025-07-22 17:04:47 -03:00 • committed by GitHub
commit 9e24202466
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
19 changed files with 1066 additions and 141 deletions

View file

@ -206,20 +206,30 @@ async def test_update_project_mcp_settings_success(
):
"""Test successful update of MCP settings using real database."""
# Create settings for updating the flow
settings = [
{
"id": str(test_flow_for_update.id),
"action_name": "updated_action",
"action_description": "Updated description",
"mcp_enabled": False,
"name": test_flow_for_update.name,
"description": test_flow_for_update.description,
}
]
json_payload = {
"settings": [
{
"id": str(test_flow_for_update.id),
"action_name": "updated_action",
"action_description": "Updated description",
"mcp_enabled": False,
"name": test_flow_for_update.name,
"description": test_flow_for_update.description,
}
],
"auth_settings": {
"auth_type": "none",
"api_key": None,
"iam_endpoint": None,
"username": None,
"password": None,
"bearer_token": None,
},
}
# Make the real PATCH request
response = await client.patch(
f"api/v1/mcp/project/{user_test_project.id}", headers=logged_in_headers, json=settings
f"api/v1/mcp/project/{user_test_project.id}", headers=logged_in_headers, json=json_payload
)
# Assert response
@ -268,11 +278,21 @@ async def test_update_project_mcp_settings_empty_settings(client: AsyncClient, u
# Use real database objects instead of mocks to avoid the coroutine issue
# Empty settings list
settings: list = []
json_payload = {
"settings": [],
"auth_settings": {
"auth_type": "none",
"api_key": None,
"iam_endpoint": None,
"username": None,
"password": None,
"bearer_token": None,
},
}
# Make the request to the actual endpoint
response = await client.patch(
f"api/v1/mcp/project/{user_test_project.id}", headers=logged_in_headers, json=settings
f"api/v1/mcp/project/{user_test_project.id}", headers=logged_in_headers, json=json_payload
)
# Verify response - the real endpoint should handle empty settings correctly
@ -385,20 +405,30 @@ async def test_user_can_update_own_flow_mcp_settings(
):
"""Test that a user can update MCP settings for their own flows using real database."""
# User attempts to update their own flow settings
updated_settings = [
{
"id": str(user_test_flow.id),
"action_name": "updated_user_action",
"action_description": "Updated user action description",
"mcp_enabled": False,
"name": "User Test Flow",
"description": "This flow belongs to the active user",
}
]
json_payload = {
"settings": [
{
"id": str(user_test_flow.id),
"action_name": "updated_user_action",
"action_description": "Updated user action description",
"mcp_enabled": False,
"name": "User Test Flow",
"description": "This flow belongs to the active user",
}
],
"auth_settings": {
"auth_type": "none",
"api_key": None,
"iam_endpoint": None,
"username": None,
"password": None,
"bearer_token": None,
},
}
# Make the PATCH request to update settings
response = await client.patch(
f"api/v1/mcp/project/{user_test_project.id}", headers=logged_in_headers, json=updated_settings
f"api/v1/mcp/project/{user_test_project.id}", headers=logged_in_headers, json=json_payload
)
# Should succeed as the user owns this project and flow