feat: add configs for external auth MCP usage + tool allow/denylist (#19794)

Closes https://github.com/coder/internal/issues/988

The logic for allowing/denying tools can be found in https://github.com/coder/aibridge/pull/4/files#diff-330a6371a583dd8cadeed79b95499e3a87960ad8ea4d6a94061e8f88a44834c3 (`ProxyBase.filterAllowedTools`).
This commit is contained in:
Danny Kopping
2025-09-16 20:31:29 +02:00
committed by GitHub
parent 655a36c392
commit 348a2e0285
11 changed files with 88 additions and 0 deletions
+3
View File
@@ -742,6 +742,9 @@ type ExternalAuthConfig struct {
ExtraTokenKeys []string `json:"-" yaml:"extra_token_keys"`
DeviceFlow bool `json:"device_flow" yaml:"device_flow"`
DeviceCodeURL string `json:"device_code_url" yaml:"device_code_url"`
MCPURL string `json:"mcp_url" yaml:"mcp_url"`
MCPToolAllowRegex string `json:"mcp_tool_allow_regex" yaml:"mcp_tool_allow_regex"`
MCPToolDenyRegex string `json:"mcp_tool_deny_regex" yaml:"mcp_tool_deny_regex"`
// Regex allows API requesters to match an auth config by
// a string (e.g. coder.com) instead of by it's type.
//
+3
View File
@@ -399,6 +399,9 @@ func TestExternalAuthYAMLConfig(t *testing.T) {
Regex: "^https://example.com/.*$",
DisplayName: "GitHub",
DisplayIcon: "/static/icons/github.svg",
MCPURL: "https://api.githubcopilot.com/mcp/",
MCPToolAllowRegex: ".*",
MCPToolDenyRegex: "create_gist",
}
// Input the github section twice for testing a slice of configs.
+3
View File
@@ -17,6 +17,9 @@ externalAuthProviders:
- token
device_flow: true
device_code_url: https://example.com/device
mcp_url: https://api.githubcopilot.com/mcp/
mcp_tool_allow_regex: .*
mcp_tool_deny_regex: create_gist
regex: ^https://example.com/.*$
display_name: GitHub
display_icon: /static/icons/github.svg