Skip to content

feat(mcp): implement Phase D — admin-only repo-browser tools - #3183

Merged
amirbiron merged 5 commits into
mainfrom
claude/mcp-codekeeper-webapp-ldnzsg
Jul 20, 2026
Merged

feat(mcp): implement Phase D — admin-only repo-browser tools#3183
amirbiron merged 5 commits into
mainfrom
claude/mcp-codekeeper-webapp-ldnzsg

Conversation

@amirbiron

@amirbiron amirbiron commented Jul 19, 2026

Copy link
Copy Markdown
Owner

מימוש דפדפן הריפו ב-MCP (קריאה בלבד, אדמין בלבד), לפי סעיף 13 במסמך התכנון:

  • 4 כלים חדשים מעל ה-Repo Sync Engine הקיים (ללא לוגיקת persistence חדשה): codekeeper_list_repos / list_repo_tree (עימוד+סינון) / get_repo_file (מעטפת יציבה: ok/binary/too_large + not_found/path_denied) / search_repo (snippets).
  • שער אדמין fail-closed: require_admin ב-auth.py (config.ADMIN_USER_IDS בלבד, בלי מפלט CHATOPS_ALLOW_ALL_IF_NO_ADMINS; רשימה ריקה = אף אחד) בגוף כל כלי, ו-AdminAwareFastMCP שמסתיר את הכלים מ-tools/list ללא-אדמין (הסתרה = UX, החסימה האמיתית בגוף).
  • מדיניות סינון סודות מחייבת (repo_policy.py): חסימה/השמטה/דילוג של .env*, .pem, id_rsa וכו' בכל שלושת המשטחים; נרמול נתיבים case-insensitive על נתיב מלא ו-basename; fail-closed על שגיאה פנימית; הרחבה דרך MCP_REPO_DENYLIST_EXTRA.
  • תקרות שרת + clamp (repo_handlers.py): limit 50/200, per_page 200/1000, max_results 50/100, תקציב פלט 256KB עם truncated.
  • הערת הביקורת של המשתמש Fix pastebin-python install in ci workflow #1: אינדקס unique ל-repo_metadata נוצר כחלק מהפאזה — גם ב-scripts/create_repo_indexes.py וגם best-effort באתחול ה-backend.
  • הערת הביקורת של המשתמש Remove problematic telegram package #2: כשל קריאה בזמן sync פעיל מחזיר {"error": "sync_in_progress", "retry_after": 30} (בדיקת sync_jobs.running) — כדי שהמודל הקורא יחזור אחרי המתנה ולא יסיק שהקובץ לא קיים.
  • תיעוד: README (כולל הערת פריסה — דיסק פר-שירות ב-Render + REPO_MIRROR_PATH), environment-variables.rst + config_inspector (MCP_REPO_DENYLIST_EXTRA חדש), ועדכון סטטוס פאזה ד' במסמך התכנון (כולל retry_after וסגירת פער 6).

טסטים: 61 חדשים (policy/backend/handlers/require_admin/visibility) — 145 עוברים סה"כ; black/ruff/flake8 נקי; אומת גם שער האדמין בשרשרת המלאה.

עיינתי בתיעוד: https://amirbiron.github.io/CodeBot/

Claude-Session: https://claude.ai/code/session_01WNFuSyshwpRcxozVZEui5K

תבנית Pull Request

✨ תיאור קצר

  • מה שיניתם ולמה? (2-3 משפטים)

📦 שינויים עיקריים

  • קוד (Backend)
  • בוט טלגרם
  • מסד נתונים/מיגרציות
  • תיעוד (docs/)
  • DevOps/CI/CD

פירוט נקודות (רשימת תבליטים):

🧪 בדיקות

  • איך בדקתם? מה עבר? מה נשאר?
  • Unit
  • Integration
  • Manual

🧪 בדיקות נדרשות ב‑PR

  • 🔍 Code Quality & Security
  • Unit Tests (3.11)
  • Unit Tests (3.12)

📝 סוג שינוי

  • feat: פיצ'ר חדש
  • fix: תיקון באג
  • docs: שינוי תיעוד בלבד
  • refactor: שינוי קוד ללא שינוי התנהגות
  • perf: שיפור ביצועים
  • chore/ci: תשתית/CI
  • breaking change: שינוי שובר תאימות

דוגמאות Conventional Commits

סוג דוגמה להודעה מתי להשתמש
feat feat: הוספת מסך הגדרות פיצ'ר חדש למשתמש
fix fix: תיקון קריסה בעת התחברות תיקון באג מול משתמשים/פרודקשן
chore chore: שדרוג Gradle ל-8.9 תחזוקה, כלי פיתוח, housekeeping
docs docs: עדכון README עם הוראות התקנה שינויי תיעוד בלבד
refactor refactor: חילוץ Repository ל-UseCases שינוי מבני ללא שינוי התנהגות
test test: הוספת בדיקות ל-LoginViewModel הוספת/עדכון בדיקות
build build: הוספת flavor staging ל-CI שינויים בבילד/תלויות/תצורה

✅ צ'קליסט

  • הקוד עוקב אחרי הסגנון (Black/isort/flake8/mypy)
  • בדיקות רצות ועוברות
  • תיעוד עודכן (README/Docs)
  • אם נוספו ג'ובים חדשים (Background Jobs) – וודא שהם רשומים ב-services/register_jobs.py (כולל Callback/Trigger להפעלה ידנית — למשל callback_name/trigger_func לפי המבנה) כדי שיופיעו בדשבורד
  • אם נוספו/שונו משתני סביבה – עודכן docs/environment-variables.rst וגם services/config_inspector_service.py
  • אם נוספו/השתנו טוקנים – עודכן גם docs/webapp/theming_and_css.rst + FEATURE_SUGGESTIONS/theme_matrix.md
  • אין סודות/מפתחות בקוד
  • אין מחיקות מסוכנות/פעולות על root (ראו .cursorrules)
  • הודעת הקומיט תואמת Conventional Commits (ע"פ הטבלה)
  • CHANGELOG עודכן אם נדרש
  • כל ה‑Required Checks לעיל ירוקים
  • צילום/וידאו UI מצורף אם רלוונטי

🧩 השפעות/סיכונים

  • השפעה אפשרית על פרודקשן, ביצועים, או אבטחה:

🔗 קישורים

🧯 סיכון / החזרה לאחור (Rollback)

  • תוכנית חזרה לאחור במקרה תקלה:

Summary by CodeRabbit

  • תכונות חדשות
    • נוסף דפדפן ריפוזיטוריז לקריאה בלבד דרך כלי MCP: רשימת ריפוזיטוריז, עץ נתיבים, שליפת קובץ וחיפוש טקסט.
    • הכלים מוגבלים לאדמינים בלבד; במשתמשים ללא הרשאה הם מוסתרים ולא ניתן לגשת להם.
  • שיפורים
    • בזמן סנכרון פעיל מוחזרת שגיאת sync_in_progress עם retry_after של 30 שניות.
    • עודכנה הרחבת ה-denylist דרך משתני סביבה, וכן נוספה הגדרת autosync מקומי למראות.
  • תיעוד
    • עודכנו מסמכי שרת ה‑MCP והגדרת הפריסה/התנהגות הכלים, כולל תיאור כלי האדמין ומדיניות הסודות.

מימוש דפדפן הריפו ב-MCP (קריאה בלבד, אדמין בלבד), לפי סעיף 13 במסמך התכנון:

- 4 כלים חדשים מעל ה-Repo Sync Engine הקיים (ללא לוגיקת persistence חדשה):
  codekeeper_list_repos / list_repo_tree (עימוד+סינון) / get_repo_file (מעטפת
  יציבה: ok/binary/too_large + not_found/path_denied) / search_repo (snippets).
- שער אדמין fail-closed: require_admin ב-auth.py (config.ADMIN_USER_IDS בלבד,
  בלי מפלט CHATOPS_ALLOW_ALL_IF_NO_ADMINS; רשימה ריקה = אף אחד) בגוף כל כלי,
  ו-AdminAwareFastMCP שמסתיר את הכלים מ-tools/list ללא-אדמין (הסתרה = UX,
  החסימה האמיתית בגוף).
- מדיניות סינון סודות מחייבת (repo_policy.py): חסימה/השמטה/דילוג של .env*,
  *.pem, id_rsa* וכו' בכל שלושת המשטחים; נרמול נתיבים case-insensitive על נתיב
  מלא ו-basename; fail-closed על שגיאה פנימית; הרחבה דרך MCP_REPO_DENYLIST_EXTRA.
- תקרות שרת + clamp (repo_handlers.py): limit 50/200, per_page 200/1000,
  max_results 50/100, תקציב פלט 256KB עם truncated.
- הערת הביקורת של המשתמש #1: אינדקס unique ל-repo_metadata נוצר כחלק מהפאזה —
  גם ב-scripts/create_repo_indexes.py וגם best-effort באתחול ה-backend.
- הערת הביקורת של המשתמש #2: כשל קריאה בזמן sync פעיל מחזיר
  {"error": "sync_in_progress", "retry_after": 30} (בדיקת sync_jobs.running) —
  כדי שהמודל הקורא יחזור אחרי המתנה ולא יסיק שהקובץ לא קיים.
- תיעוד: README (כולל הערת פריסה — דיסק פר-שירות ב-Render + REPO_MIRROR_PATH),
  environment-variables.rst + config_inspector (MCP_REPO_DENYLIST_EXTRA חדש),
  ועדכון סטטוס פאזה ד' במסמך התכנון (כולל retry_after וסגירת פער 6).

טסטים: 61 חדשים (policy/backend/handlers/require_admin/visibility) — 145 עוברים
סה"כ; black/ruff/flake8 נקי; אומת גם שער האדמין בשרשרת המלאה.

עיינתי בתיעוד: https://amirbiron.github.io/CodeBot/

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WNFuSyshwpRcxozVZEui5K
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@github-actions

Copy link
Copy Markdown

🧯 Dangerous deletes guard report

Policy: see .cursorrules — dangerous deletions are blocked unless wrapped safely.

Summary:

  • Flagged findings (blocking): 0
    0
  • Excluded matches (not blocking): 15
  • Total matches (all files): 129

Flagged findings (file:line:snippet):
(none)

Excluded matches (by path pattern)
./webapp/static/js/md_preview.bundle.js.map:4:  "sourcesContent": ["// Markdown-it plugin to render GitHub-style task lists; see\n//\n// https://github.com/blog/1375-task-lists-in-gfm-issues-pulls-comments\n// https://github.com/blog/1825-t … [truncated]
./README.md:842:find . -name "__pycache__" -exec rm -rf {} +
./Dockerfile:42:    rm -rf /var/lib/apt/lists/*
./Dockerfile:121:    rm -rf /var/lib/apt/lists/*
./node_modules/mermaid/dist/mermaid.min.js:1524:`,"getStyles"),c1e=RQe});var h1e={};dr(h1e,{diagram:()=>NQe});var NQe,f1e=N(()=>{"use strict";$ge();a1e();l1e();u1e();NQe={parser:Fge,db:n1e,renderer:o1e,styles:c1e}});var m1e,g1e=N(()=>{"use  … [truncated]
./node_modules/mermaid/dist/mermaid.min.js.map:4:  "sourcesContent": ["/**\n* Default values for dimensions\n*/\nconst defaultIconDimensions = Object.freeze({\n\tleft: 0,\n\ttop: 0,\n\twidth: 16,\n\theight: 16\n});\n/**\n* Default values fo … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.core/chunk-KS23V3DP.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequence  … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm/chunk-2M32CCKP.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequence d … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm.min/chunk-4HFYJGYH.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequen … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm.min/chunk-4HFYJGYH.mjs:1:var r={name:"mermaid",version:"11.12.0",description:"Markdown-ish syntax for generating flowcharts, mindmaps, sequence diagrams, class diagrams, gantt charts, git graph … [truncated]
./node_modules/mermaid/dist/mermaid.js.map:4:  "sourcesContent": ["/**\n* Default values for dimensions\n*/\nconst defaultIconDimensions = Object.freeze({\n\tleft: 0,\n\ttop: 0,\n\twidth: 16,\n\theight: 16\n});\n/**\n* Default values for tr … [truncated]
./node_modules/katex/src/fonts/Makefile:139:	rm -rf pfa ff otf ttf woff woff2
./node_modules/katex/package.json:153:    "build": "rimraf dist/ && mkdirp dist && cp README.md dist && rollup -c --failAfterWarnings && webpack && node update-sri.js package dist/README.md",
./docs/Makefile:24:	rm -rf $(BUILDDIR)
./docs/DOCUMENTATION_GUIDE.md:453:rm -rf _build

@coderabbitai

coderabbitai Bot commented Jul 19, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@amirbiron, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 44 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d4d6324f-8309-4422-be38-8f290c56db3d

📥 Commits

Reviewing files that changed from the base of the PR and between 264010d and 13d6c42.

📒 Files selected for processing (2)
  • mcp_server/repo_autosync.py
  • tests/test_mcp_repo_autosync.py
📝 Walkthrough

Walkthrough

נוסף דפדפן ריפוזיטוריז לקריאה בלבד ב-MCP, הכולל ארבעה כלים אדמיניים, הרשאות fail-closed, denylist לנתיבים רגישים, mirrors מקומיים, autosync, חיפוש, פאג’ינציה וטיפול ב־sync_in_progress.

Changes

דפדפן ריפוזיטוריז ואבטחת גישה

Layer / File(s) Summary
הרשאות ומדיניות נתיבים
mcp_server/auth.py, mcp_server/repo_policy.py, services/config_inspector_service.py, tests/test_mcp_require_admin.py, tests/test_mcp_repo_policy.py
נוספו הרשאות אדמין מסוג fail-closed ומדיניות denylist לנתיבים רגישים, כולל הרחבה דרך MCP_REPO_DENYLIST_EXTRA.
שירות הקריאה וחוזי התגובה
mcp_server/repo_backend.py, scripts/create_repo_indexes.py, tests/test_mcp_repo_backend.py
נוסף RepoBackend עבור רשימת ריפוזיטוריז, עצי קבצים, שליפת קבצים וחיפוש, עם אינדקס ייחודי, סינון נתיבים, הגבלת פלט ותגובה sync_in_progress.
רענון אוטומטי של mirrors
mcp_server/repo_autosync.py, tests/test_mcp_repo_autosync.py, docs/environment-variables.rst
נוסף worker רקע שמאתחל mirrors חסרים, מבצע fetch לפי SHA, מונע ריצות כפולות ומכיל שגיאות.
רישום כלי MCP וחיבור האפליקציה
mcp_server/repo_handlers.py, mcp_server/server.py, mcp_server/app.py, tests/test_mcp_repo_handlers.py, tests/test_mcp_server_build.py
נוספו handlers לוולידציה ול-clamping, ארבעה כלי MCP אדמיניים, הסתרת כלים מ-tools/list וחיבור RepoBackend למסלולי האפליקציה.
תיעוד וחוזי הפיצ'ר
mcp_server/README.md, docs/mcp-server.rst, docs/environment-variables.rst, docs/index.rst, FEATURE_SUGGESTIONS/FEATURE_MCP_CLAUDE_INTEGRATION.md
התיעוד עודכן עבור Phase D, הרשאות אדמין, denylist, mirrors, autosync וחוזה השגיאה בזמן sync.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant AdminClient
  participant AdminAwareFastMCP
  participant RepoHandlers
  participant RepoBackend
  participant RepoMirror
  participant RepoAutosync
  AdminClient->>AdminAwareFastMCP: tools/list או קריאת כלי repo
  AdminAwareFastMCP->>RepoHandlers: העברת קלט לאחר בדיקת אדמין
  RepoHandlers->>RepoBackend: list_tree/get_file/search
  RepoBackend->>RepoMirror: קריאת mirror או חיפוש
  RepoAutosync->>RepoMirror: clone או fetch לפי SHA
  RepoMirror-->>RepoBackend: תוצאות או שגיאת קריאה
  RepoBackend-->>RepoHandlers: תוצאת קריאה או sync_in_progress
  RepoHandlers-->>AdminAwareFastMCP: מעטפת כלי
  AdminAwareFastMCP-->>AdminClient: תגובת MCP
Loading

Possibly related PRs

Poem

אני ארנב עם mirror קטן,
מדלג בין עצים בלי לחשוף סוד.
אדמין נכנס — השביל נפתח,
sync רץ — נחכה עוד קצת.
ארבעה כלים, קוד בטוח.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed הכותרת תואמת היטב את עיקר השינוי: הוספת כלי repo-browser אדמיניסטרטיביים לשלב D.
Description check ✅ Passed התיאור מכסה את עיקרי השינוי, הבדיקות, הקישורים וההשפעות, אף שהוא לא ממלא את כל תבנית ה-PR במבנה מלא.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/mcp-codekeeper-webapp-ldnzsg

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

⏱️ Performance report

(No performance test durations collected. Mark tests with @pytest.mark.performance.)

@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

📖 Documentation Preview

The documentation has been built successfully!

To view locally:

  1. Download the artifacts
  2. Extract the zip file
  3. Open index.html in your browser

@codecov

codecov Bot commented Jul 19, 2026

Copy link
Copy Markdown

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
scripts/create_repo_indexes.py (1)

20-22: 🗄️ Data Integrity & Integration | 🔵 Trivial

שימו לב לסיכון מיגרציה: יצירת אינדקס unique תיכשל אם קיימים כבר repo_name כפולים.

אם באוסף repo_metadata יש כבר מסמכים עם repo_name כפול (מצטבר לפני הפיצ'ר), הרצת השורה הזו בסביבת פרודקשן תיכשל עם שגיאת duplicate key ותעצור את הסקריפט. מומלץ לבצע בדיקה מקדימה (למשל aggregate עם $group על repo_name + $match על count > 1) ולדווח/לנקות כפילויות לפני יצירת האינדקס, כדי לא להיתקע בזמן דיפלוי.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/create_repo_indexes.py` around lines 20 - 22, Update the
index-creation flow around db.repo_metadata.create_index to detect duplicate
repo_name values first, using aggregation grouped by repo_name and filtering
groups with count greater than one. Report or clean the duplicates before
attempting the unique index, and prevent index creation from proceeding when
unresolved duplicates remain.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@mcp_server/repo_backend.py`:
- Around line 154-176: Validate and normalize the page and per_page inputs
before calculating the slice in the repository listing handler: convert them
safely inside the existing error-handling flow, reject non-numeric values, and
clamp page to at least 1 and per_page to the supported positive limit. Use the
normalized page_i and per_page_i for slicing and for the returned "page" and
"per_page" fields, preserving the existing error response behavior for invalid
input.
- Around line 241-265: Update the result handling around the rows construction
and return payload so exceeding max_results sets truncated to true when
additional policy-allowed matches exist beyond the cap. Compute total from the
policy-filtered results before applying the max_results slice, ensuring it
reflects available results after is_denied filtering rather than the backend
total; preserve the byte-budget truncation behavior and add coverage in
test_search_caps_filters_and_snippets for both fields.

---

Nitpick comments:
In `@scripts/create_repo_indexes.py`:
- Around line 20-22: Update the index-creation flow around
db.repo_metadata.create_index to detect duplicate repo_name values first, using
aggregation grouped by repo_name and filtering groups with count greater than
one. Report or clean the duplicates before attempting the unique index, and
prevent index creation from proceeding when unresolved duplicates remain.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 96737f55-c8a7-435c-be19-c0e64dd5a09e

📥 Commits

Reviewing files that changed from the base of the PR and between b0a336d and 43d88f5.

📒 Files selected for processing (16)
  • FEATURE_SUGGESTIONS/FEATURE_MCP_CLAUDE_INTEGRATION.md
  • docs/environment-variables.rst
  • mcp_server/README.md
  • mcp_server/app.py
  • mcp_server/auth.py
  • mcp_server/repo_backend.py
  • mcp_server/repo_handlers.py
  • mcp_server/repo_policy.py
  • mcp_server/server.py
  • scripts/create_repo_indexes.py
  • services/config_inspector_service.py
  • tests/test_mcp_repo_backend.py
  • tests/test_mcp_repo_handlers.py
  • tests/test_mcp_repo_policy.py
  • tests/test_mcp_require_admin.py
  • tests/test_mcp_server_build.py

Comment thread mcp_server/repo_backend.py Outdated
Comment thread mcp_server/repo_backend.py Outdated
claude added 3 commits July 19, 2026 23:15
…ls, index dup-guard

תיקוני code review על מימוש פאזה ד' (כל שלושת הממצאים תקפים):

- list_tree: נרמול הגנתי של page/per_page גם בשכבת ה-backend (ה-handler כבר
  עושה clamp, אבל המתודה ציבורית): קלט לא-מספרי ⇒ ברירת מחדל, רצפה של 1,
  ותקרת TREE_PER_PAGE_MAX — הערכים המנורמלים משמשים גם לחיתוך וגם בתשובה
  (בלי slicing שלילי ובלי ValueError).
- search: total משקף עכשיו את מספר ההתאמות המותרות לאחר סינון המדיניות (ולא את
  ה-total הגולמי של המנוע שכולל נתיבים חסומים), ו-truncated נדלק גם כשקיימות
  התאמות מותרות מעבר ל-max_results (בנוסף לקיטום תקציב-הבייטים ולדגל המנוע).
- create_repo_indexes.py: בדיקת כפילויות repo_name (aggregation) לפני יצירת
  ה-unique index — כפילות מדווחת ומדלגת במקום להפיל את הסקריפט באמצע ריצת
  שאר האינדקסים.

טסטים: עודכן test_search_caps_filters_and_snippets (total+truncated), נוספו
טסט אי-קיטום מתחת לתקרה וטסט נרמול קלט לעץ. 147 עוברים; black/ruff/flake8 נקי.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WNFuSyshwpRcxozVZEui5K
הפיכת עדכון ה-mirrors בשירות ה-MCP לאוטומטי לגמרי, באותו דפוס כמו הוובאפ
(thread רקע דמון בתוך אותו שירות — לא cron ולא שירות Render נוסף):

- mcp_server/repo_autosync.py: לולאת רענון שמנצלת את מה שכבר קורה — הוובאפ
  מקבל את ה-webhook מ-GitHub ואחרי כל sync כותב last_synced_sha ל-Mongo
  המשותף. הלולאה משווה את ה-SHA המקומי ומריצה fetch כשיש סטייה; ריפו שקיים
  ב-repo_metadata אך חסר בדיסק המקומי משוכפל אוטומטית מ-repo_url
  (init_mirror אידמפוטנטי) — אין יותר initial_import ידני בצד ה-MCP.
- זרימה: merge ל-main → webhook לוובאפ → SHA ב-Mongo → ה-MCP מזהה ומושך.
- בזמן clone/fetch מקומי הכלים מחזירים sync_in_progress+retry_after
  (is_refreshing משולב ב-RepoBackend._sync_running לצד תור ה-jobs של הוובאפ).
- שליטה: MCP_REPO_AUTOSYNC (ברירת מחדל פעיל, 0 מכבה),
  MCP_REPO_AUTOSYNC_INTERVAL (ברירת מחדל 300ש', רצפה 30). מותנע מ-create_app
  עם עטיפת שגיאות — כשל בהתנעה לא מפיל את השירות.
- תיעוד: README (זרימה + ENV: צריך GITHUB_TOKENS לפרטיים, לא צריך
  GITHUB_WEBHOOK_SECRET ב-MCP), environment-variables.rst + config_inspector.

טסטים: 10 חדשים ל-refresh_once (clone-חסר, דילוג SHA-זהה, fetch על סטייה/חוסר
ודאות, בליעת שגיאות + ניקוי דגל, is_refreshing בזמן פעולה, kill-switch, רצפת
interval) + טסט backend ל-sync_in_progress ברענון מקומי. 157 עוברים; לינט נקי.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WNFuSyshwpRcxozVZEui5K
עמוד תיעוד חדש docs/mcp-server.rst (משולב ב-toctree תחת האינטגרציות):

- מה זה נותן + ארכיטקטורה בקצרה (in-process, user_id מהטוקן, Smart Projection).
- טבלאות כל 12 הכלים — 8 כלי משתמש + 4 כלי אדמין (דפדפן הריפו).
- אימות והרשאות: PAT/OAuth מאוחדים, שכבות read/write/אדמין.
- הפעלה צעד-אחר-צעד: שירות Render → מצב PAT → מצב OAuth (כולל אילו ENV על איזה
  שירות) → דפדפן הריפו (דיסק, ADMIN_USER_IDS, GITHUB_TOKENS; בלי webhook secret).
- חיבור משלושת הלקוחות (Claude.ai / Code / Desktop) עם פקודות מוכנות להעתקה.
- autosync (זרימת merge→webhook→SHA→fetch), מדיניות סינון הסודות, התנהגות
  sync_in_progress/retry_after, עקרונות אבטחה, וטבלת פתרון תקלות.

בנוסף: תיקון docstring ב-database/collections_manager.py (get_tags_metadata) —
רשימת ההגדרות השבורה הייתה שתי האזהרות היחידות בבניית Sphinx; אחרי התיקון
הבנייה כולה על 0 אזהרות (חובה לפי מדיניות ה-RTD fail_on_warning).

אומת: בנייה מלאה exit 0 עם 0 אזהרות; doc8 נקי על העמוד החדש.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WNFuSyshwpRcxozVZEui5K

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@mcp_server/repo_autosync.py`:
- Around line 115-117: Prevent Git secrets from reaching logs by adding a shared
sanitization helper and applying it to res.get("message") before logging
failures from init_mirror at mcp_server/repo_autosync.py lines 115-117 and
fetch_updates at mcp_server/repo_autosync.py line 131. Ensure token-bearing Git
URLs are redacted while preserving safe diagnostic details.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b518fced-d800-43c2-816e-495650495e74

📥 Commits

Reviewing files that changed from the base of the PR and between 43d88f5 and 264010d.

📒 Files selected for processing (12)
  • database/collections_manager.py
  • docs/environment-variables.rst
  • docs/index.rst
  • docs/mcp-server.rst
  • mcp_server/README.md
  • mcp_server/app.py
  • mcp_server/repo_autosync.py
  • mcp_server/repo_backend.py
  • scripts/create_repo_indexes.py
  • services/config_inspector_service.py
  • tests/test_mcp_repo_autosync.py
  • tests/test_mcp_repo_backend.py
🚧 Files skipped from review as they are similar to previous changes (6)
  • mcp_server/README.md
  • mcp_server/app.py
  • services/config_inspector_service.py
  • scripts/create_repo_indexes.py
  • mcp_server/repo_backend.py
  • tests/test_mcp_repo_backend.py

Comment thread mcp_server/repo_autosync.py
ממצא ביקורת: לוגי הכשל של autosync מדפיסים message שמגיע מתלות חיצונית
(init_mirror/fetch_updates) ועלול להכיל URL של git עם טוקן.

אימות מול הקוד: המנוע עצמו כבר מסנן את ה-stderr במקור (_run_git_command →
_sanitize_output, כולל ה-URL עם הטוקן), כך שלא נמצאה דליפה חיה בנתיבים
הקיימים — אבל אנחנו מלוגגים ערכים מתלות duck-typed, ולפי CLAUDE.md אסור
שסודות יגיעו ללוגים בכלל. לכן נוסף helper משותף `_redact`:

- מסיר credentials מ-userinfo של URL (https://user:token@host → https://***@host)
- מסיר צורות טוקן של GitHub (ghp_/gho_/ghu_/ghs_/ghr_/github_pat_)
- fail-closed: שגיאה פנימית ⇒ placeholder, לעולם לא הטקסט הגולמי
- מוחל על שני אתרי הלוג (clone failed / fetch failed)

טסטים: יחידה ל-_redact (URL עם credentials, טוקן חשוף, שימור אבחון תקין,
None) + טסט caplog שמוכיח שנתיב הכשל לא מדליף טוקן ללוג. 159 עוברים; לינט נקי.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WNFuSyshwpRcxozVZEui5K
@amirbiron
amirbiron merged commit f8b7057 into main Jul 20, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants