mirror of
https://github.com/symfony/recipes-contrib.git
synced 2026-09-11 23:26:40 +03:00
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
603e85a508 |
@@ -1,67 +0,0 @@
|
||||
{
|
||||
"manifests": {
|
||||
"gplanchat/durable-bundle": {
|
||||
"manifest": {
|
||||
"bundles": {
|
||||
"Gplanchat\\Durable\\Bundle\\DurableBundle": [
|
||||
"all"
|
||||
]
|
||||
},
|
||||
"copy-from-recipe": {
|
||||
"config/": "%CONFIG_DIR%/"
|
||||
},
|
||||
"env": {
|
||||
"#1": "Where workflow resumes and activity runs are queued.",
|
||||
"#2": "sync:// handles them in the same process, which matches the in_memory",
|
||||
"#3": "backend the config starts from. Point them at a real transport",
|
||||
"#4": "(doctrine://, amqp://, redis://) when you move the journal off memory.",
|
||||
"MESSENGER_DURABLE_WORKFLOW_DSN": "sync://",
|
||||
"MESSENGER_DURABLE_ACTIVITY_DSN": "sync://"
|
||||
},
|
||||
"post-install-output": [
|
||||
" * Durable starts on the <comment>in_memory</comment> backend: workflows run, and are lost with the process.",
|
||||
" Set <comment>event_store.type</comment> and <comment>workflow_metadata.type</comment> to <comment>dbal</comment> in",
|
||||
" <comment>config/packages/durable.yaml</comment> to keep the journal in your database, and point the two",
|
||||
" <comment>MESSENGER_DURABLE_*_DSN</comment> variables at a real transport.",
|
||||
"",
|
||||
" * Then run the workers:",
|
||||
" <comment>php bin/console messenger:consume durable_workflows durable_activities</comment>",
|
||||
"",
|
||||
" * Documentation: <comment>https://durable.rocks/docs/getting-started/</comment>"
|
||||
]
|
||||
},
|
||||
"files": {
|
||||
"config/packages/durable.yaml": {
|
||||
"contents": [
|
||||
"durable:",
|
||||
" # in_memory keeps the journal in the PHP process: right for tests, lost on restart.",
|
||||
" # Use dbal to keep it in your database, or set temporal.dsn to reach a Temporal cluster.",
|
||||
" event_store:",
|
||||
" type: in_memory",
|
||||
" workflow_metadata:",
|
||||
" type: in_memory",
|
||||
" activity_transport:",
|
||||
" type: messenger",
|
||||
" transport_name: durable_activities",
|
||||
"",
|
||||
"framework:",
|
||||
" messenger:",
|
||||
" transports:",
|
||||
" durable_workflows: '%env(MESSENGER_DURABLE_WORKFLOW_DSN)%'",
|
||||
" durable_activities: '%env(MESSENGER_DURABLE_ACTIVITY_DSN)%'",
|
||||
"",
|
||||
" routing:",
|
||||
" Gplanchat\\Durable\\Transport\\ResumeWorkflowMessage: durable_workflows",
|
||||
" Gplanchat\\Durable\\Transport\\ActivityMessage: durable_activities",
|
||||
" Gplanchat\\Durable\\Transport\\FireWorkflowTimersMessage: sync",
|
||||
" Gplanchat\\Durable\\Transport\\DeliverWorkflowSignalMessage: sync",
|
||||
" Gplanchat\\Durable\\Transport\\DeliverWorkflowUpdateMessage: sync",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
}
|
||||
},
|
||||
"ref": "e438ab8d3b5aa6199ad13f3598acead044a4374b"
|
||||
}
|
||||
}
|
||||
}
|
||||
+4
-4
@@ -1,8 +1,8 @@
|
||||
{
|
||||
"aliases": [],
|
||||
"recipes": {
|
||||
"gplanchat/durable-bundle": [
|
||||
"0.1"
|
||||
"sulu/mcp-bundle": [
|
||||
"1.0"
|
||||
]
|
||||
},
|
||||
"recipe-conflicts": [],
|
||||
@@ -12,9 +12,9 @@
|
||||
"_links": {
|
||||
"repository": "github.com/symfony/recipes-contrib",
|
||||
"origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main",
|
||||
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2041/{package_dotted}.{version}.json",
|
||||
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2039/{package_dotted}.{version}.json",
|
||||
"recipe_template_relative": "{package_dotted}.{version}.json",
|
||||
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2041/archived/{package_dotted}/{ref}.json",
|
||||
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2039/archived/{package_dotted}/{ref}.json",
|
||||
"archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,140 @@
|
||||
{
|
||||
"manifests": {
|
||||
"sulu/mcp-bundle": {
|
||||
"manifest": {
|
||||
"bundles": {
|
||||
"Symfony\\AI\\McpBundle\\McpBundle": [
|
||||
"all"
|
||||
],
|
||||
"Sulu\\Mcp\\Infrastructure\\Symfony\\HttpKernel\\SuluMcpBundle": [
|
||||
"all"
|
||||
]
|
||||
},
|
||||
"copy-from-recipe": {
|
||||
"config/": "%CONFIG_DIR%/"
|
||||
},
|
||||
"env": {
|
||||
"SULU_MCP_SERVER_URL": "https://localhost"
|
||||
},
|
||||
"gitignore": [
|
||||
"/config/jwt/*.pem"
|
||||
],
|
||||
"post-install-output": [
|
||||
" <bg=blue;fg=white> </>",
|
||||
" <bg=blue;fg=white> What's next? </>",
|
||||
" <bg=blue;fg=white> </>",
|
||||
"",
|
||||
" * Set <comment>SULU_MCP_SERVER_URL</> in <comment>.env.local</> to the public base URL of this installation.",
|
||||
"",
|
||||
" * Generate the RSA key pair league/oauth2-server-bundle signs its tokens with,",
|
||||
" and point the OAUTH_* variables at it. Without it every MCP request fails with",
|
||||
" \"Invalid key supplied\":",
|
||||
"",
|
||||
" mkdir -p config/jwt",
|
||||
" openssl genrsa -aes128 -out config/jwt/private.pem 4096",
|
||||
" openssl rsa -in config/jwt/private.pem -pubout -out config/jwt/public.pem",
|
||||
"",
|
||||
" * The password and implicit grants of <comment>league/oauth2-server-bundle</> are deprecated while unset",
|
||||
" and MCP does not use them. Turn them off in <comment>config/packages/league_oauth2_server.yaml</>:",
|
||||
"",
|
||||
" league_oauth2_server:",
|
||||
" authorization_server:",
|
||||
" enable_password_grant: false",
|
||||
" enable_implicit_grant: false",
|
||||
"",
|
||||
" * Create the OAuth tables: <comment>bin/console doctrine:migrations:diff</> and <comment>migrate</>",
|
||||
"",
|
||||
" * Declare the MCP firewall in <comment>config/packages/security.yaml</> BEFORE the admin firewall.",
|
||||
" Both patterns match /admin/mcp and Symfony applies the first one in declaration order:",
|
||||
"",
|
||||
" firewalls:",
|
||||
" mcp:",
|
||||
" pattern: ^/admin/mcp/?$",
|
||||
" provider: sulu",
|
||||
" stateless: true",
|
||||
" entry_point: sulu_mcp.authentication_entry_point",
|
||||
" oauth2: true",
|
||||
" admin:",
|
||||
" pattern: ^/admin(\\/|$)",
|
||||
" # ...existing admin firewall...",
|
||||
"",
|
||||
" The pattern is anchored on purpose: /admin/mcp/authorize and /admin/mcp/consent/...",
|
||||
" need the logged-in Sulu user and must fall through to the admin firewall.",
|
||||
" Let the client-authenticated endpoints through in <comment>access_control</>:",
|
||||
"",
|
||||
" - { path: ^/\\.well-known/oauth-, roles: PUBLIC_ACCESS }",
|
||||
" - { path: ^/admin/mcp/register$, roles: PUBLIC_ACCESS }",
|
||||
" - { path: ^/admin/mcp/token$, roles: PUBLIC_ACCESS }",
|
||||
" - { path: ^/admin/mcp/?$, roles: IS_AUTHENTICATED_FULLY }",
|
||||
"",
|
||||
" * Create an OAuth client for hosted clients such as Claude.ai or ChatGPT:",
|
||||
" <comment>bin/console sulu:mcp:create-client \"Claude.ai Production\"</>",
|
||||
" Claude Code registers itself dynamically and needs no client up front.",
|
||||
"",
|
||||
" * Full guide: <comment>https://github.com/sulu/SuluMcpBundle/blob/1.0/docs/configuration.md</>"
|
||||
]
|
||||
},
|
||||
"files": {
|
||||
"config/packages/sulu_mcp.yaml": {
|
||||
"contents": [
|
||||
"sulu_mcp:",
|
||||
" # Publicly reachable base URL of this Sulu installation. Together with mcp_path",
|
||||
" # it forms the OAuth issuer and the resource identifier of the discovery documents.",
|
||||
" server_url: '%env(SULU_MCP_SERVER_URL)%'",
|
||||
"",
|
||||
"# The two sections below configure other bundles. They live in this file rather than in",
|
||||
"# their own so they merge with whatever those bundles' recipes wrote, instead of taking",
|
||||
"# ownership of a file that is not ours.",
|
||||
"",
|
||||
"mcp:",
|
||||
" servers:",
|
||||
" # The server SuluMcpBundle prepends; its remaining options are set there.",
|
||||
" sulu:",
|
||||
" http:",
|
||||
" # DNS rebinding protection. Left unset it accepts localhost only, so a server",
|
||||
" # reachable under its own domain answers every request with \"403 Forbidden:",
|
||||
" # Invalid Host header.\" after the OAuth handshake already succeeded, and without",
|
||||
" # writing anything to the log. Hosts carry no port.",
|
||||
" allowed_hosts:",
|
||||
" - '%env(key:host:url:SULU_MCP_SERVER_URL)%'",
|
||||
" - localhost",
|
||||
" - 127.0.0.1",
|
||||
" - '[::1]'",
|
||||
"",
|
||||
"league_oauth2_server:",
|
||||
" scopes:",
|
||||
" # `available` is contributed by SuluMcpBundle. `default` applies to clients that",
|
||||
" # request no scope of their own, and league leaves it to the project. Scope lists",
|
||||
" # are appended across files, so the entries the league recipe wrote stay; drop",
|
||||
" # them there if the project does not use them.",
|
||||
" default: ['mcp:tools', 'mcp:resources']",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
},
|
||||
"config/routes/sulu_mcp.yaml": {
|
||||
"contents": [
|
||||
"# MCP transport endpoint, registered by symfony/mcp-bundle at the path configured",
|
||||
"# in config/packages/sulu_mcp.yaml. Declare it only once - a second \"type: mcp\"",
|
||||
"# entry makes the route loader fail.",
|
||||
"mcp:",
|
||||
" resource: .",
|
||||
" type: mcp",
|
||||
"",
|
||||
"# OAuth endpoints behind the admin prefix. The prefix must match mcp_path.",
|
||||
"sulu_mcp_admin:",
|
||||
" resource: '@SuluMcpBundle/config/routing_admin.yaml'",
|
||||
" prefix: /admin",
|
||||
"",
|
||||
"# RFC 8414 / RFC 9728 discovery documents, unprefixed in the host's /.well-known/ namespace.",
|
||||
"sulu_mcp_website:",
|
||||
" resource: '@SuluMcpBundle/config/routing_website.yaml'",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
}
|
||||
},
|
||||
"ref": "5c8da8c17e2a8976aac6614c4fbdbc3ce841eb06"
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user