mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-05 10:13:39 +00:00
One GitHub connection feeds both a Knowledge source and an agent tool. Users connect with a personal access token, checked against GitHub and named after the account, or, when an admin registers a GitHub App (GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET, GITHUB_APP_SLUG), with Sign in with GitHub. App tokens expire after eight hours and are refreshed before each sync or tool call; tokens with no expiry are never treated as expired. The catalog gains an optional second sign-in method (oauth_settings, exposed as sign_in_methods) without changing any other connector. Sync lists the repositories the connection can read (the token's own, or the App installations') and ingests one with the connection's token. The tool is GitHub's read-only MCP server (api.githubcopilot.com/mcp/readonly): setup discovers its actions and creates it bound to the connection, and the executor sends the connection's token only to that server.
68 lines
3.1 KiB
Python
68 lines
3.1 KiB
Python
"""OAuth credentials for external source connectors."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from typing import Optional
|
|
|
|
from pydantic import Field
|
|
|
|
from docsgpt.core.settings._shared import SettingsGroup
|
|
|
|
|
|
class ConnectorSettings(SettingsGroup):
|
|
"""Client credentials and callback URLs for Google Drive, Microsoft, Confluence, GitHub and MCP."""
|
|
|
|
# Google Drive integration.
|
|
GOOGLE_CLIENT_ID: Optional[str] = Field(default=None, description="Google OAuth client id.")
|
|
GOOGLE_CLIENT_SECRET: Optional[str] = Field(default=None, description="Google OAuth client secret.")
|
|
CONNECTOR_REDIRECT_BASE_URI: str = Field(
|
|
default="http://127.0.0.1:7091/api/connectors/callback",
|
|
description="OAuth callback URL; register it as-is in your provider's console (e.g. GCP).",
|
|
)
|
|
CONNECTOR_ALLOWED_ORIGINS: Optional[str] = Field(
|
|
default=None,
|
|
description=(
|
|
"Comma-separated frontend origins allowed to receive connector OAuth results, e.g. "
|
|
"https://docsgpt.example.com. The callback origin and OIDC_FRONTEND_URL are always allowed; a "
|
|
"loopback callback also allows localhost:5173."
|
|
),
|
|
)
|
|
|
|
# Microsoft Entra ID (Azure AD) integration.
|
|
MICROSOFT_CLIENT_ID: Optional[str] = Field(default=None, description="Azure AD application (client) id.")
|
|
MICROSOFT_CLIENT_SECRET: Optional[str] = Field(default=None, description="Azure AD application client secret.")
|
|
MICROSOFT_TENANT_ID: str = Field(
|
|
default="common", description="Azure AD tenant id, or 'common' for multi-tenant."
|
|
)
|
|
MICROSOFT_AUTHORITY: Optional[str] = Field(
|
|
default=None,
|
|
description="Authority URL override; unset derives https://login.microsoftonline.com/<MICROSOFT_TENANT_ID>.",
|
|
)
|
|
|
|
# Confluence Cloud integration.
|
|
CONFLUENCE_CLIENT_ID: Optional[str] = Field(default=None, description="Confluence Cloud OAuth client id.")
|
|
CONFLUENCE_CLIENT_SECRET: Optional[str] = Field(default=None, description="Confluence Cloud OAuth client secret.")
|
|
|
|
# GitHub source.
|
|
GITHUB_ACCESS_TOKEN: Optional[str] = Field(
|
|
default=None,
|
|
description=(
|
|
"Instance-wide GitHub token for the public-repository upload. It raises GitHub's rate limit and is never "
|
|
"used to read a private repository; users connect their own GitHub account for those."
|
|
),
|
|
)
|
|
# GitHub App behind "Sign in with GitHub" on the GitHub connector.
|
|
GITHUB_CLIENT_ID: Optional[str] = Field(
|
|
default=None,
|
|
description="GitHub App client id. With the secret and slug, offers Sign in with GitHub next to tokens.",
|
|
)
|
|
GITHUB_CLIENT_SECRET: Optional[str] = Field(default=None, description="GitHub App client secret.")
|
|
GITHUB_APP_SLUG: Optional[str] = Field(
|
|
default=None,
|
|
description="GitHub App URL name (github.com/apps/<slug>), for the link where users choose repositories.",
|
|
)
|
|
|
|
MCP_OAUTH_REDIRECT_URI: Optional[str] = Field(
|
|
default=None, description="Public callback URL for MCP OAuth; unset derives it from CONNECTOR_REDIRECT_BASE_URI."
|
|
)
|