feat: Phase 11 — CRUD (create/update/delete) + auth + web UI
- Core: createDocument/updateDocument/deleteDocument (file + DB + revision + chunks) - Parser: stringifyFile (serialize markdown with frontmatter to disk) - API: tRPC CRUD routers (auth-gated via requireWriteAuth middleware) - API: createContext now passes expectedSecret from deps (request-scoped auth) - MCP: 3 new write tools (create_document, update_document, delete_document) - Web: /create page + ?edit=1 form, /api/auth/login (cookie-based), /api/docs REST CRUD - Web: Edit buttons on homepage + doc pages (auth-gated) - Tests: 8 new tests (5 tRPC CRUD + 3 MCP CRUD auth), 40 total all green
This commit is contained in:
@@ -4,9 +4,12 @@ import { db } from "@mcpedia/db";
|
||||
export interface Context {
|
||||
db: typeof db;
|
||||
// Raw `x-webhook-secret` header from the incoming request, if present.
|
||||
// State-changing tRPC mutations (restoreRevision) require it to match
|
||||
// WEBHOOK_SECRET; read-only procedures ignore it.
|
||||
// State-changing tRPC mutations (restoreRevision, CRUD) require it to match
|
||||
// the configured secret; read-only procedures ignore it.
|
||||
webhookSecret?: string;
|
||||
// The configured expected secret (from deps). Used by requireWriteAuth
|
||||
// to validate the header — request-scoped so tests can inject a fake.
|
||||
expectedSecret: string;
|
||||
}
|
||||
|
||||
export const t = initTRPC.context<Context>().create();
|
||||
|
||||
Reference in New Issue
Block a user