Przeglądaj źródła

fix: normalize server URL, add opt-in insecure TLS, fix uid=0 search

- Strip a trailing /api/v1 from GOGS_SERVER_URL so both the base URL and
  the full API URL work in configuration.
- Add GOGS_INSECURE_TLS (default false) to disable TLS certificate
  verification for Gogs servers with self-signed certificates. Verification
  stays on by default and a warning is printed to stderr when enabled.
- search_repositories: use `uid !== undefined` so an explicit uid of 0 is
  passed through instead of being replaced by the || fallback.
- Document GOGS_INSECURE_TLS and GOGS_REPO in README.md and .env.example.
Void User 3 tygodni temu
rodzic
commit
8d36b811f0
5 zmienionych plików z 37 dodań i 2 usunięć
  1. 6 0
      .env.example
  2. 13 0
      README.md
  3. 8 2
      src/gogs-client.ts
  4. 8 0
      src/index.ts
  5. 2 0
      src/types.ts

+ 6 - 0
.env.example

@@ -12,6 +12,12 @@ GOGS_ACCESS_TOKEN=your-access-token-here
 # Example: GOGS_REPO=myuser/myproject
 # GOGS_REPO=
 
+# Optional: Disable TLS certificate verification (default: false)
+# Only enable this if your Gogs server uses a self-signed certificate.
+# WARNING: this makes the connection vulnerable to man-in-the-middle attacks,
+# which can expose your access token. Never enable it over an untrusted network.
+# GOGS_INSECURE_TLS=true
+
 # Transport mode: 'stdio' (default) or 'http'
 # - stdio: For use with MCP clients (Claude Desktop, etc.)
 # - http: For HTTP-based access with SSE

+ 13 - 0
README.md

@@ -175,6 +175,13 @@ Create a `.env` file or set environment variables:
 GOGS_SERVER_URL=https://your-gogs-server.com
 GOGS_ACCESS_TOKEN=your-access-token-here
 
+# Restrict access to a single repository (optional, format: owner/repo)
+GOGS_REPO=myuser/myproject
+
+# Disable TLS certificate verification (optional, default: false)
+# Only for self-signed certificates - see warning below
+GOGS_INSECURE_TLS=true
+
 # Transport mode (optional, default: stdio)
 TRANSPORT_MODE=stdio  # or 'http' for HTTP/SSE transport
 
@@ -188,6 +195,12 @@ The access token is optional but recommended. Without it:
 - Some operations requiring authentication will fail
 - Only public repositories will be accessible
 
+`GOGS_INSECURE_TLS=true` turns off TLS certificate verification so the server can
+talk to a Gogs instance using a self-signed certificate. It is off by default.
+Enabling it removes protection against man-in-the-middle attacks, which can leak
+your access token, so only use it on a trusted network. The preferred fix is to
+add your CA certificate to the system trust store instead.
+
 ### Transport Modes
 
 The server supports two transport modes:

+ 8 - 2
src/gogs-client.ts

@@ -4,6 +4,7 @@
  */
 
 import axios, { AxiosInstance } from 'axios';
+import https from 'https';
 import type {
   GogsUser,
   GogsRepository,
@@ -41,7 +42,7 @@ export class GogsClient {
   private serverUrl: string;
 
   constructor(config: GogsConfig) {
-    this.serverUrl = config.serverUrl.replace(/\/$/, '');
+    this.serverUrl = config.serverUrl.replace(/\/$/, '').replace(/\/api\/v1$/, '');
 
     this.client = axios.create({
       baseURL: `${this.serverUrl}/api/v1`,
@@ -49,6 +50,11 @@ export class GogsClient {
         'Content-Type': 'application/json',
         ...(config.accessToken && { Authorization: `token ${config.accessToken}` }),
       },
+      ...(config.insecureTls && {
+        httpsAgent: new https.Agent({
+          rejectUnauthorized: false,
+        }),
+      }),
     });
 
     this.client.interceptors.response.use(
@@ -124,7 +130,7 @@ export class GogsClient {
     const response = await this.client.get<GogsSearchResponse<GogsRepository>>('/repos/search', {
       params: {
         q: query,
-        uid: options?.uid || 0,
+        uid: options?.uid !== undefined ? options.uid : 0,
         limit: options?.limit || 10,
         page: options?.page || 1,
       },

+ 8 - 0
src/index.ts

@@ -19,6 +19,7 @@ config();
 const GOGS_SERVER_URL = process.env.GOGS_SERVER_URL;
 const GOGS_ACCESS_TOKEN = process.env.GOGS_ACCESS_TOKEN;
 const GOGS_REPO = process.env.GOGS_REPO;
+const GOGS_INSECURE_TLS = process.env.GOGS_INSECURE_TLS === 'true';
 const TRANSPORT_MODE = process.env.TRANSPORT_MODE || 'stdio';
 const HTTP_PORT = parseInt(process.env.HTTP_PORT || '3000', 10);
 const HTTP_HOST = process.env.HTTP_HOST || '0.0.0.0';
@@ -44,9 +45,16 @@ if (GOGS_REPO) {
 }
 
 // Initialize Gogs client
+if (GOGS_INSECURE_TLS) {
+  console.error(
+    'Warning: GOGS_INSECURE_TLS is enabled - TLS certificate verification is disabled'
+  );
+}
+
 const gogsClient = new GogsClient({
   serverUrl: GOGS_SERVER_URL,
   accessToken: GOGS_ACCESS_TOKEN,
+  insecureTls: GOGS_INSECURE_TLS,
 });
 
 // Create MCP server with all tools and handlers

+ 2 - 0
src/types.ts

@@ -81,6 +81,8 @@ export interface GogsCommit {
 export interface GogsConfig {
   serverUrl: string;
   accessToken?: string;
+  /** Disable TLS certificate verification (self-signed certs). Insecure - opt-in only. */
+  insecureTls?: boolean;
 }
 
 export interface GogsIssue {