Files
DocsGPT/docsgpt/core/settings/connectors.py
T
arc53-machine f882ef49a7 refactor: read settings directly instead of getattr with a second default
About 85 call sites read a setting as getattr(settings, "NAME", fallback),
each carrying its own copy of the default. Every one of those names is a
field with a default on the model, so the fallback could never apply to
the real settings object; it only masked drift. Two had drifted:

- OPENAI_PROMPT_CACHE_KEY defaults to True on the model but the reader
  fell back to False, and two test stubs relied on that.
- SharePoint's MICROSOFT_AUTHORITY fallback to
  https://login.microsoftonline.com/<tenant> never fired, because the
  attribute always exists (as None), so MSAL got authority=None. The
  connector now derives the tenant authority when the setting is unset,
  as its test always assumed.

Four places read EMBEDDINGS_KEY straight from os.environ, skipping the
"None"/"" normalisation the model applies; they read the setting now.
Test stubs that replaced a module's settings with a SimpleNamespace list
every setting the code under test reads.
2026-09-17 11:14:34 +01:00

52 lines
2.3 KiB
Python

"""OAuth credentials for external source connectors."""
from __future__ import annotations
from typing import Optional
from pydantic import Field
from docsgpt.core.settings._shared import SettingsGroup
class ConnectorSettings(SettingsGroup):
"""Client credentials and callback URLs for Google Drive, Microsoft, Confluence, GitHub and MCP."""
# Google Drive integration.
GOOGLE_CLIENT_ID: Optional[str] = Field(default=None, description="Google OAuth client id.")
GOOGLE_CLIENT_SECRET: Optional[str] = Field(default=None, description="Google OAuth client secret.")
CONNECTOR_REDIRECT_BASE_URI: str = Field(
default="http://127.0.0.1:7091/api/connectors/callback",
description="OAuth callback URL; register it as-is in your provider's console (e.g. GCP).",
)
CONNECTOR_ALLOWED_ORIGINS: Optional[str] = Field(
default=None,
description=(
"Comma-separated frontend origins allowed to receive connector OAuth results, e.g. "
"https://docsgpt.example.com. The callback origin and OIDC_FRONTEND_URL are always allowed; a "
"loopback callback also allows localhost:5173."
),
)
# Microsoft Entra ID (Azure AD) integration.
MICROSOFT_CLIENT_ID: Optional[str] = Field(default=None, description="Azure AD application (client) id.")
MICROSOFT_CLIENT_SECRET: Optional[str] = Field(default=None, description="Azure AD application client secret.")
MICROSOFT_TENANT_ID: str = Field(
default="common", description="Azure AD tenant id, or 'common' for multi-tenant."
)
MICROSOFT_AUTHORITY: Optional[str] = Field(
default=None,
description="Authority URL override; unset derives https://login.microsoftonline.com/<MICROSOFT_TENANT_ID>.",
)
# Confluence Cloud integration.
CONFLUENCE_CLIENT_ID: Optional[str] = Field(default=None, description="Confluence Cloud OAuth client id.")
CONFLUENCE_CLIENT_SECRET: Optional[str] = Field(default=None, description="Confluence Cloud OAuth client secret.")
# GitHub source.
GITHUB_ACCESS_TOKEN: Optional[str] = Field(default=None, description="GitHub PAT with read access to repositories.")
MCP_OAUTH_REDIRECT_URI: Optional[str] = Field(
default=None, description="Public callback URL for MCP OAuth; unset derives it from CONNECTOR_REDIRECT_BASE_URI."
)