fix(coderd): actually wire the chat template allowlist into tools (#23626)

Problem: previously, the deployment-wide chat template allowlist was never actually wired in from `chatd.go`

- Extracts `parseChatTemplateAllowlist` into shared `coderd/util/xjson.ParseUUIDList`
- Adds `Server.chatTemplateAllowlist()` method that reads the allowlist from DB
- Passes `AllowedTemplateIDs` callback to `ListTemplates`, `ReadTemplate`, and `CreateWorkspace` tool constructors

> 🤖 Created by Coder Agents and reviewed by a human.
This commit is contained in:
Cian Johnston
2026-03-25 22:15:27 +00:00
committed by GitHub
parent dab4e6f0a4
commit 7a9d57cd87
5 changed files with 262 additions and 23 deletions
+6 -19
View File
@@ -44,6 +44,7 @@ import (
"github.com/coder/coder/v2/coderd/searchquery"
"github.com/coder/coder/v2/coderd/tracing"
"github.com/coder/coder/v2/coderd/util/ptr"
"github.com/coder/coder/v2/coderd/util/xjson"
"github.com/coder/coder/v2/coderd/workspaceapps"
"github.com/coder/coder/v2/coderd/x/chatd"
"github.com/coder/coder/v2/coderd/x/chatd/chatprovider"
@@ -2870,7 +2871,7 @@ func (api *API) getChatTemplateAllowlist(rw http.ResponseWriter, r *http.Request
})
return
}
ids, parseErr := parseChatTemplateAllowlist(raw)
parsed, parseErr := xjson.ParseUUIDList(raw)
if parseErr != nil {
httpapi.Write(ctx, rw, http.StatusInternalServerError, codersdk.Response{
Message: "Stored template allowlist is corrupt.",
@@ -2878,6 +2879,10 @@ func (api *API) getChatTemplateAllowlist(rw http.ResponseWriter, r *http.Request
})
return
}
ids := make([]string, len(parsed))
for i, id := range parsed {
ids[i] = id.String()
}
resp := codersdk.ChatTemplateAllowlist{
TemplateIDs: ids,
}
@@ -2983,24 +2988,6 @@ func (api *API) putChatTemplateAllowlist(rw http.ResponseWriter, r *http.Request
rw.WriteHeader(http.StatusNoContent)
}
// parseChatTemplateAllowlist parses the raw JSON string from the
// database into a list of template ID strings. Returns an empty
// slice when the value is empty. Returns an error when the stored
// JSON is corrupt or otherwise cannot be unmarshalled.
func parseChatTemplateAllowlist(raw string) ([]string, error) {
if raw == "" {
return []string{}, nil
}
var ids []string
if err := json.Unmarshal([]byte(raw), &ids); err != nil {
return nil, xerrors.Errorf("unmarshal template allowlist: %w", err)
}
if ids == nil {
return []string{}, nil
}
return ids, nil
}
// EXPERIMENTAL: this endpoint is experimental and is subject to change.
//
//nolint:revive // get-return: revive assumes get* must be a getter, but this is an HTTP handler.