Route automatic Unraid diagnostics through read-only MUA
This commit is contained in:
@@ -24,7 +24,7 @@ class Filter:
|
||||
"github": "server:mcp:github-local",
|
||||
"homeassistant": "server:mcp:homeassistant-local",
|
||||
"arr": "server:mcp:arr-local",
|
||||
"unraid": "server:mcp:unraid-readonly-local",
|
||||
"unraid": "server:mcp:mua-readonly-local",
|
||||
"navidrome": "server:mcp:navidrome-local",
|
||||
"platform": "server:mcp:athena-platform",
|
||||
"operator": "server:mcp:athena-operator-local",
|
||||
@@ -35,7 +35,7 @@ class Filter:
|
||||
"github": "GitHub",
|
||||
"homeassistant": "Home Assistant",
|
||||
"arr": "Sonarr/Radarr",
|
||||
"unraid": "Unraid-Diagnose",
|
||||
"unraid": "Unraid-Diagnose (MUA read-only)",
|
||||
"navidrome": "Navidrome",
|
||||
"platform": "Athena-Plattformwissen",
|
||||
"operator": "Athena Operator",
|
||||
|
||||
@@ -44,6 +44,7 @@ if [[ -s /etc/mike-ai/github-mcp.env ]] && \
|
||||
fi
|
||||
python3 - "$db" "$FILTER_DIR" "$ACTION_DIR" "${OPENWEBUI_FILTER_OWNER_ID:-}" "$navidrome_enabled" "$github_enabled" <<'PY'
|
||||
import json
|
||||
import copy
|
||||
import pathlib
|
||||
import sqlite3
|
||||
import sys
|
||||
@@ -204,6 +205,13 @@ with con:
|
||||
"Docker, Shares, Netzwerk, UPS und Logs. Für dieselbe Anfrage nicht zusätzlich "
|
||||
"MUA aufrufen; MUA nur für dessen spezielle oder freigegebene Verwaltungsaktionen.",
|
||||
),
|
||||
"mua-readonly-local": (
|
||||
"Unraid-Diagnose (MUA read-only)",
|
||||
"Automatisch verwendbarer, serverseitig in Open WebUI auf reine Lese- und "
|
||||
"Diagnosewerkzeuge begrenzter MUA-Zugang. Für Containerbestand, Logs, System, "
|
||||
"Storage, Shares und Netzwerkstatus. Keine Start/Stop-, Installations-, "
|
||||
"Änderungs- oder freie Shell-Funktion. Für bewusste Verwaltung MUA separat wählen.",
|
||||
),
|
||||
"mua": (
|
||||
"MUA (Unraid-Verwaltung)",
|
||||
"Nur für ausdrücklich benötigte MUA-spezifische oder freigegebene Unraid-"
|
||||
@@ -268,6 +276,60 @@ with con:
|
||||
info["name"] = name
|
||||
info["description"] = description
|
||||
changed = True
|
||||
# Clone the existing authenticated MUA connection into a second
|
||||
# OpenWebUI connection whose exposed function list is strictly
|
||||
# read-only. The bearer value remains in the database and is neither
|
||||
# printed nor copied into Git. Automatic routing uses only this clone;
|
||||
# the original MUA connection remains available for deliberate admin.
|
||||
mua_source = next(
|
||||
(
|
||||
connection for connection in connections
|
||||
if isinstance(connection, dict)
|
||||
and str((connection.get("info") or {}).get("id", "")).lower() == "mua"
|
||||
),
|
||||
None,
|
||||
)
|
||||
if mua_source is not None:
|
||||
readonly_functions = ",".join((
|
||||
"unraid_docker_list", "unraid_docker_inspect", "unraid_docker_logs",
|
||||
"unraid_docker_analyze_logs", "unraid_docker_processes",
|
||||
"unraid_docker_stats", "unraid_docker_info",
|
||||
"unraid_docker_update_status", "unraid_ca_search",
|
||||
"unraid_network_inventory", "unraid_network_list",
|
||||
"unraid_network_inspect", "unraid_network_host_state",
|
||||
"unraid_network_audit_tcp", "unraid_network_lan_probe",
|
||||
"unraid_system_health", "unraid_storage_status",
|
||||
"unraid_disk_health", "unraid_notifications_list",
|
||||
"unraid_shares_list", "unraid_share_inspect",
|
||||
"unraid_system_connection_test", "unraid_system_shell_readonly",
|
||||
))
|
||||
readonly = copy.deepcopy(mua_source)
|
||||
readonly["config"] = {
|
||||
"enable": True,
|
||||
"function_name_filter_list": readonly_functions,
|
||||
"access_grants": [],
|
||||
}
|
||||
name, description = descriptions["mua-readonly-local"]
|
||||
readonly["info"] = {
|
||||
"id": "mua-readonly-local",
|
||||
"name": name,
|
||||
"description": description,
|
||||
}
|
||||
existing_index = next(
|
||||
(
|
||||
index for index, connection in enumerate(connections)
|
||||
if isinstance(connection, dict)
|
||||
and str((connection.get("info") or {}).get("id", "")).lower()
|
||||
== "mua-readonly-local"
|
||||
),
|
||||
None,
|
||||
)
|
||||
if existing_index is None:
|
||||
connections.append(readonly)
|
||||
changed = True
|
||||
elif connections[existing_index] != readonly:
|
||||
connections[existing_index] = readonly
|
||||
changed = True
|
||||
if navidrome_enabled and not any(
|
||||
isinstance(connection, dict)
|
||||
and (
|
||||
|
||||
Reference in New Issue
Block a user