Implements the foundational layer that all SynapBus features depend on: - internal/storage: SQLite connection manager (WAL mode, busy_timeout, foreign_keys) and embedded migration runner using modernc.org/sqlite - internal/messaging: MessagingService with send, read inbox, claim, mark done/failed, and FTS5 search. SQLite-backed MessageStore with conversation auto-creation and read/unread tracking via inbox_state. - internal/agents: AgentService with register, authenticate (bcrypt), update, deregister, discover by capability. HTTP auth middleware. - internal/mcp: MCP server using mark3labs/mcp-go with 9 registered tools (send_message, read_inbox, claim_messages, mark_done, search_messages, register_agent, discover_agents, update_agent, deregister_agent). SSE transport, health endpoint, connection manager. - internal/trace: Async trace recorder with buffered channel for recording agent actions to SQLite traces table. - cmd/synapbus: Updated main.go wiring storage, migrations, services, MCP server, chi router, and graceful shutdown. All code compiles with CGO_ENABLED=0. Full test suite passes. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
62 lines
1.7 KiB
Go
62 lines
1.7 KiB
Go
package agents
|
|
|
|
import (
|
|
"context"
|
|
"log/slog"
|
|
"net/http"
|
|
"strings"
|
|
)
|
|
|
|
type contextKey string
|
|
|
|
const agentContextKey contextKey = "agent"
|
|
|
|
// AgentFromContext extracts the authenticated agent from the context.
|
|
func AgentFromContext(ctx context.Context) (*Agent, bool) {
|
|
agent, ok := ctx.Value(agentContextKey).(*Agent)
|
|
return agent, ok
|
|
}
|
|
|
|
// ContextWithAgent returns a new context with the agent set.
|
|
func ContextWithAgent(ctx context.Context, agent *Agent) context.Context {
|
|
return context.WithValue(ctx, agentContextKey, agent)
|
|
}
|
|
|
|
// AuthMiddleware creates HTTP middleware that authenticates requests via API key.
|
|
func AuthMiddleware(service *AgentService) func(http.Handler) http.Handler {
|
|
return func(next http.Handler) http.Handler {
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
authHeader := r.Header.Get("Authorization")
|
|
if authHeader == "" {
|
|
http.Error(w, `{"error":"unauthorized","message":"Missing Authorization header"}`, http.StatusUnauthorized)
|
|
return
|
|
}
|
|
|
|
parts := strings.SplitN(authHeader, " ", 2)
|
|
if len(parts) != 2 || !strings.EqualFold(parts[0], "Bearer") {
|
|
http.Error(w, `{"error":"unauthorized","message":"Invalid Authorization header format"}`, http.StatusUnauthorized)
|
|
return
|
|
}
|
|
|
|
apiKey := parts[1]
|
|
agent, err := service.Authenticate(r.Context(), apiKey)
|
|
if err != nil {
|
|
slog.Warn("authentication failed",
|
|
"remote_addr", r.RemoteAddr,
|
|
"error", err,
|
|
)
|
|
http.Error(w, `{"error":"unauthorized","message":"Invalid API key"}`, http.StatusUnauthorized)
|
|
return
|
|
}
|
|
|
|
slog.Debug("agent authenticated",
|
|
"agent", agent.Name,
|
|
"remote_addr", r.RemoteAddr,
|
|
)
|
|
|
|
ctx := ContextWithAgent(r.Context(), agent)
|
|
next.ServeHTTP(w, r.WithContext(ctx))
|
|
})
|
|
}
|
|
}
|