Commit Graph

3 Commits

Author SHA1 Message Date
Aletheia
263e6e9b75 fix: OAuth token endpoint multipart support + governor_enabled bool round-trip
Ported from the Android edition's server:

- Add python-multipart: the OAuth endpoints parse credentials with
  request.form(), and Starlette needs this package when a client POSTs
  the token request as multipart/form-data. Without it those requests
  500'd ('the small auth bug').
- governor_enabled now round-trips SQLite's 0/1 as JSON true/false on
  read and normalises any truthy input to 0/1 on write. Strict clients
  (kotlinx-serialization) reject anything else.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 20:06:55 +02:00
Aletheia
6a8bc353c5 feat: OAuth 2.0 support, server-side safety governor, multi-user auth mode
Publishes server work that shipped in the Android edition but never made
it to this repo:

- Full OAuth 2.0 flow (discovery metadata, dynamic client registration,
  authorize + token endpoints) so claude.ai remote connectors and the
  Android app can authenticate per-user instead of relying on the
  sole-phone fallback.
- Safety governor: server-side heat model (intensity x time) with
  automatic cooldown, per-user overrides via GET/POST /safety/config,
  and governor state piggybacked on heartbeat pings so relay clients
  can display it.
- SB_REQUIRE_MCP_AUTH env flag for multi-user deployments (disables the
  unauthenticated sole-phone fallback).
- requirements-phone.txt and .env.example documenting the new knobs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 20:05:45 +02:00
Aletheia
142e83d512 Add files via upload 2026-03-14 19:40:48 +01:00