mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 03:15:06 +03:00
## I have read the [CONTRIBUTING.md](<https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md>) file. YES ## What kind of change does this PR introduce? Feature / refactor. ## What is the current behavior? The dashboard assistant runs `@supabase/mcp-server-supabase` in-process over an in-memory transport (`lib/ai/supabase-mcp.ts`). ## What is the new behavior? The assistant connects to the **remote MCP server** over HTTP (`@ai-sdk/mcp`), forwarding the dashboard session token as a bearer. URL comes from `NEXT_PUBLIC_MCP_URL` with a local-dev fallback; platform-only, and Nimbus works via the same env var. * **Tool model unchanged:** UI-controlled `execute_sql` (with `needsApproval`) and `deploy_edge_function` still come from Studio; the allowlist (`TOOL_CATEGORY_MAP`) remains the gate keeping the remote's write tools away from the assistant (`read_only` is defense-in-depth). * **Attribution:** sends `x-source-name: supabase-studio` (+ `x-source-version`) → logged as `source_name`/`client_name`. * **Connection lifecycle:** the HTTP client is closed via the request's `AbortSignal` (tools execute later during streaming); `signal` is required on `getTools`/`getMcpTools`. * **Resilience:** a remote-MCP failure degrades to the remaining tools instead of failing the assistant. * **Drift protection:** relied-upon tools are typed against `keyof typeof supabaseMcpToolSchemas`, so a package bump that renames/removes one fails `pnpm typecheck`; a runtime check also warns if the deployed server returns fewer tools. * Adds unit tests for the above. ## Additional context * Verified end-to-end against a local remote MCP server with a dashboard token: `initialize` 200, tools listed, a tool executed, client closed cleanly. * The remote MCP (mgmt-api) already accepts dashboard session tokens (GoTrue-JWT auth path) — no backend change needed. `NEXT_PUBLIC_MCP_URL` must point at each env's `/mcp`. * `@supabase/mcp-server-supabase` is kept — still used by the self-hosted `/api/mcp` routes. Closes [AI-137](https://linear.app/supabase/issue/AI-137/switch-dashboard-assistant-to-remote-mcp) ## Rollout * **Rollout:** merges with `USE_REMOTE_MCP` off (in-process); flip it to `true` per environment (staging → prod → Nimbus) once each one's prerequisites land. * **Rollback:** unset `USE_REMOTE_MCP` and redeploy to fall back to the in-process client — no revert needed. ## Summary by CodeRabbit * **Bug Fixes** * Improved AI request handling so tool loading and generation clean up properly when a request is cancelled or the browser connection closes. * Added safer fallback behavior when remote tool loading fails, so AI features can continue with available tools instead of stopping entirely. * Updated remote tool access to use the current project reference and preserve the correct access headers. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * AI tools now connect more reliably to remote services and stop cleanly when requests end or are canceled. * Tool loading is more resilient, continuing with available tools if remote access is unavailable. * **Bug Fixes** * Improved cleanup to prevent lingering connections during SQL generation and policy workflows. * Added safer handling for remote tool changes and invalid responses. * **Tests** * Expanded automated coverage for remote tool setup, cancellation, and fallback behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
140 lines
5.2 KiB
TypeScript
140 lines
5.2 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'
|
|
|
|
import { createSupabaseMCPClient } from './supabase-mcp'
|
|
|
|
const createMCPClientMock = vi.fn()
|
|
|
|
vi.mock('@ai-sdk/mcp', () => ({
|
|
createMCPClient: (...args: any[]) => createMCPClientMock(...args),
|
|
}))
|
|
|
|
const ACCESS_TOKEN = 'test-access-token'
|
|
const PROJECT_REF = 'abcdefghijklmnopqrst'
|
|
|
|
function getTransportConfig() {
|
|
expect(createMCPClientMock).toHaveBeenCalledTimes(1)
|
|
return createMCPClientMock.mock.calls[0][0]
|
|
}
|
|
|
|
describe('createSupabaseMCPClient', () => {
|
|
const originalMcpUrl = process.env.NEXT_PUBLIC_MCP_URL
|
|
const originalSha = process.env.VERCEL_GIT_COMMIT_SHA
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
createMCPClientMock.mockResolvedValue({ tools: vi.fn() })
|
|
delete process.env.VERCEL_GIT_COMMIT_SHA
|
|
})
|
|
|
|
afterEach(() => {
|
|
if (originalMcpUrl === undefined) delete process.env.NEXT_PUBLIC_MCP_URL
|
|
else process.env.NEXT_PUBLIC_MCP_URL = originalMcpUrl
|
|
if (originalSha === undefined) delete process.env.VERCEL_GIT_COMMIT_SHA
|
|
else process.env.VERCEL_GIT_COMMIT_SHA = originalSha
|
|
})
|
|
|
|
it('connects over the HTTP transport with the supabase-studio client name', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
const config = getTransportConfig()
|
|
expect(config.name).toBe('supabase-studio')
|
|
expect(config.transport.type).toBe('http')
|
|
})
|
|
|
|
it('targets the URL from NEXT_PUBLIC_MCP_URL with project_ref and read_only', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
const url = new URL(getTransportConfig().transport.url)
|
|
expect(url.origin + url.pathname).toBe('https://mcp.supabase.com/mcp')
|
|
expect(url.searchParams.get('project_ref')).toBe(PROJECT_REF)
|
|
expect(url.searchParams.get('read_only')).toBe('true')
|
|
})
|
|
|
|
it('forwards the dashboard access token as a bearer header', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
expect(getTransportConfig().transport.headers.Authorization).toBe(`Bearer ${ACCESS_TOKEN}`)
|
|
})
|
|
|
|
it('identifies assistant traffic with the x-source-name header', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
expect(getTransportConfig().transport.headers['x-source-name']).toBe('supabase-studio')
|
|
})
|
|
|
|
it('sends x-source-version from VERCEL_GIT_COMMIT_SHA when available', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
process.env.VERCEL_GIT_COMMIT_SHA = 'abc1234'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
expect(getTransportConfig().transport.headers['x-source-version']).toBe('abc1234')
|
|
})
|
|
|
|
it('omits x-source-version when VERCEL_GIT_COMMIT_SHA is not set', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
delete process.env.VERCEL_GIT_COMMIT_SHA
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
expect(getTransportConfig().transport.headers).not.toHaveProperty('x-source-version')
|
|
})
|
|
|
|
it('never leaks the access token into the URL', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
expect(getTransportConfig().transport.url).not.toContain(ACCESS_TOKEN)
|
|
})
|
|
|
|
it('always requests read-only mode', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
const url = new URL(getTransportConfig().transport.url)
|
|
expect(url.searchParams.get('read_only')).toBe('true')
|
|
})
|
|
|
|
it('falls back to the default local URL when NEXT_PUBLIC_MCP_URL is unset', async () => {
|
|
delete process.env.NEXT_PUBLIC_MCP_URL
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
const url = new URL(getTransportConfig().transport.url)
|
|
expect(url.origin + url.pathname).toBe('http://localhost:8080/mcp')
|
|
expect(url.searchParams.get('project_ref')).toBe(PROJECT_REF)
|
|
})
|
|
|
|
it('falls back to the default local URL when NEXT_PUBLIC_MCP_URL is an empty string', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = ''
|
|
|
|
await createSupabaseMCPClient({ accessToken: ACCESS_TOKEN, projectRef: PROJECT_REF })
|
|
|
|
const url = new URL(getTransportConfig().transport.url)
|
|
expect(url.origin + url.pathname).toBe('http://localhost:8080/mcp')
|
|
})
|
|
|
|
it('returns the client created by createMCPClient', async () => {
|
|
process.env.NEXT_PUBLIC_MCP_URL = 'https://mcp.supabase.com/mcp'
|
|
const fakeClient = { tools: vi.fn() }
|
|
createMCPClientMock.mockResolvedValueOnce(fakeClient)
|
|
|
|
const client = await createSupabaseMCPClient({
|
|
accessToken: ACCESS_TOKEN,
|
|
projectRef: PROJECT_REF,
|
|
})
|
|
|
|
expect(client).toBe(fakeClient)
|
|
})
|
|
})
|