Compare commits
7 Commits
fix/admin-
...
feature/mc
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d20b4f396b | ||
|
|
ad0b15cc6e | ||
| af864ecb44 | |||
|
|
cc9481fc6c | ||
| cf578ce699 | |||
|
|
765efa1a1c | ||
| 86330885e3 |
@@ -15,6 +15,12 @@ ADMIN_USERNAME=admin
|
|||||||
ADMIN_PASSWORD=change-me
|
ADMIN_PASSWORD=change-me
|
||||||
SESSION_SECRET=change-me-session-secret
|
SESSION_SECRET=change-me-session-secret
|
||||||
MCP_TOKEN=change-me-mcp-token
|
MCP_TOKEN=change-me-mcp-token
|
||||||
|
MCP_AUTH_MODE=oauth
|
||||||
|
MCP_RESOURCE_URL=http://localhost:8001/mcp
|
||||||
|
MCP_OAUTH_ISSUER=
|
||||||
|
MCP_OAUTH_AUDIENCE=
|
||||||
|
MCP_OAUTH_JWKS_URL=
|
||||||
|
MCP_OAUTH_REQUIRED_SCOPE=mcp:tools
|
||||||
|
|
||||||
API_PORT=8000
|
API_PORT=8000
|
||||||
MCP_PORT=8001
|
MCP_PORT=8001
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@@ -4,6 +4,7 @@ __pycache__/
|
|||||||
*.py[cod]
|
*.py[cod]
|
||||||
*.db
|
*.db
|
||||||
.pytest_cache/
|
.pytest_cache/
|
||||||
|
pytest-cache-files-*/
|
||||||
.coverage
|
.coverage
|
||||||
htmlcov/
|
htmlcov/
|
||||||
postgres_data/
|
postgres_data/
|
||||||
|
|||||||
31
README.md
31
README.md
@@ -6,7 +6,7 @@
|
|||||||
|
|
||||||
- `api`: FastAPI, REST API, HTML-админка, healthcheck.
|
- `api`: FastAPI, REST API, HTML-админка, healthcheck.
|
||||||
- `worker`: weekly scheduler, который запускает парсинг по `CRAWL_CRON`.
|
- `worker`: weekly scheduler, который запускает парсинг по `CRAWL_CRON`.
|
||||||
- `mcp`: HTTP MCP endpoint с bearer token.
|
- `mcp`: HTTP MCP endpoint с OAuth/OIDC access token для внешних агентов или legacy static token для локального режима.
|
||||||
- `postgres`: основная БД.
|
- `postgres`: основная БД.
|
||||||
|
|
||||||
Парсер использует фиксированный источник сотрудников, по умолчанию `https://miem.hse.ru/persons`. Для каждой карточки сохраняются ФИО, должности, год начала работы, контакты, идентификаторы, вкладки профиля, секции, публикации, курсы, ВКР, JSON-снапшот и сжатый HTML-снапшот. Ссылки обходятся только из меню профиля самого сотрудника (`person-menu`), например `#sci`, `#teaching`, `#main`.
|
Парсер использует фиксированный источник сотрудников, по умолчанию `https://miem.hse.ru/persons`. Для каждой карточки сохраняются ФИО, должности, год начала работы, контакты, идентификаторы, вкладки профиля, секции, публикации, курсы, ВКР, JSON-снапшот и сжатый HTML-снапшот. Ссылки обходятся только из меню профиля самого сотрудника (`person-menu`), например `#sci`, `#teaching`, `#main`.
|
||||||
@@ -27,7 +27,13 @@ cp .env.example .env
|
|||||||
- `CRAWL_LIMIT`: опциональный лимит профилей для тестового запуска.
|
- `CRAWL_LIMIT`: опциональный лимит профилей для тестового запуска.
|
||||||
- `ADMIN_USERNAME`, `ADMIN_PASSWORD`: логин и пароль админки.
|
- `ADMIN_USERNAME`, `ADMIN_PASSWORD`: логин и пароль админки.
|
||||||
- `SESSION_SECRET`: секрет подписи cookie.
|
- `SESSION_SECRET`: секрет подписи cookie.
|
||||||
- `MCP_TOKEN`: bearer token для `/mcp`.
|
- `MCP_TOKEN`: статический bearer token для legacy/local режима `MCP_AUTH_MODE=token`.
|
||||||
|
- `MCP_AUTH_MODE`: режим авторизации MCP: `oauth` для внешних агентов или `token` для локальной отладки.
|
||||||
|
- `MCP_RESOURCE_URL`: публичный URL MCP endpoint, например `https://example.com/mcp`.
|
||||||
|
- `MCP_OAUTH_ISSUER`: issuer внешнего OIDC-провайдера.
|
||||||
|
- `MCP_OAUTH_AUDIENCE`: ожидаемый `aud` в OAuth access token.
|
||||||
|
- `MCP_OAUTH_JWKS_URL`: JWKS endpoint; если не задан, используется `<issuer>/.well-known/jwks.json`.
|
||||||
|
- `MCP_OAUTH_REQUIRED_SCOPE`: scope для доступа к MCP tools, по умолчанию `mcp:tools`.
|
||||||
- `PARSER_USE_PLAYWRIGHT`: включение Playwright-рендера динамических вкладок.
|
- `PARSER_USE_PLAYWRIGHT`: включение Playwright-рендера динамических вкладок.
|
||||||
|
|
||||||
## Локальный запуск
|
## Локальный запуск
|
||||||
@@ -82,7 +88,9 @@ curl -X POST http://localhost:8000/api/crawl-runs --cookie "miem_admin_session=.
|
|||||||
|
|
||||||
## MCP
|
## MCP
|
||||||
|
|
||||||
Endpoint: `POST /mcp`, авторизация `Authorization: Bearer <MCP_TOKEN>`.
|
Endpoint: `POST /mcp`, авторизация `Authorization: Bearer <token>`.
|
||||||
|
|
||||||
|
Для внешних ИИ-агентов используйте `MCP_AUTH_MODE=oauth`. В этом режиме статический `MCP_TOKEN` не принимается: клиент должен передать OAuth/OIDC access token с нужным scope.
|
||||||
|
|
||||||
Поддерживаемые tools:
|
Поддерживаемые tools:
|
||||||
|
|
||||||
@@ -92,7 +100,7 @@ Endpoint: `POST /mcp`, авторизация `Authorization: Bearer <MCP_TOKEN>
|
|||||||
- `list_employee_courses(profile_id_or_url)`
|
- `list_employee_courses(profile_id_or_url)`
|
||||||
- `get_crawl_status()`
|
- `get_crawl_status()`
|
||||||
|
|
||||||
Пример:
|
Пример локального legacy-режима со статическим токеном:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl http://localhost:8001/mcp \
|
curl http://localhost:8001/mcp \
|
||||||
@@ -101,6 +109,19 @@ curl http://localhost:8001/mcp \
|
|||||||
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
|
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Для production OAuth/OIDC настройте внешний authorization server и включите режим `oauth`:
|
||||||
|
|
||||||
|
```env
|
||||||
|
MCP_AUTH_MODE=oauth
|
||||||
|
MCP_RESOURCE_URL=https://example.com/mcp
|
||||||
|
MCP_OAUTH_ISSUER=https://auth.example.com
|
||||||
|
MCP_OAUTH_AUDIENCE=miem-mcp
|
||||||
|
MCP_OAUTH_JWKS_URL=https://auth.example.com/.well-known/jwks.json
|
||||||
|
MCP_OAUTH_REQUIRED_SCOPE=mcp:tools
|
||||||
|
```
|
||||||
|
|
||||||
|
MCP server работает как OAuth protected resource: он не выдает токены, а проверяет JWT access token по JWKS, `issuer`, `audience`, сроку действия и scope. Metadata для MCP-клиентов доступна по `GET /.well-known/oauth-protected-resource`.
|
||||||
|
|
||||||
## Обслуживание
|
## Обслуживание
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -110,4 +131,4 @@ docker compose exec postgres pg_dump -U miem miem_workers > backup.sql
|
|||||||
docker compose down
|
docker compose down
|
||||||
```
|
```
|
||||||
|
|
||||||
Версия сервиса: `0.2.6`. Админка всегда показывает версии backend и frontend в footer.
|
Версия сервиса: `0.3.0`. Админка всегда показывает версии backend и frontend в footer.
|
||||||
|
|||||||
@@ -108,7 +108,7 @@ def directory(
|
|||||||
"has_email": has_email or "",
|
"has_email": has_email or "",
|
||||||
"sort": sort,
|
"sort": sort,
|
||||||
"direction": direction,
|
"direction": direction,
|
||||||
"limit": limit,
|
"limit": page["limit"],
|
||||||
"offset": offset,
|
"offset": offset,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -1,5 +1,7 @@
|
|||||||
from functools import lru_cache
|
from functools import lru_cache
|
||||||
from pydantic import Field
|
from typing import Literal
|
||||||
|
|
||||||
|
from pydantic import Field, field_validator
|
||||||
from pydantic_settings import BaseSettings, SettingsConfigDict
|
from pydantic_settings import BaseSettings, SettingsConfigDict
|
||||||
|
|
||||||
|
|
||||||
@@ -18,6 +20,27 @@ class Settings(BaseSettings):
|
|||||||
admin_password: str = "admin"
|
admin_password: str = "admin"
|
||||||
session_secret: str = Field(default="dev-session-secret", min_length=8)
|
session_secret: str = Field(default="dev-session-secret", min_length=8)
|
||||||
mcp_token: str = "dev-mcp-token"
|
mcp_token: str = "dev-mcp-token"
|
||||||
|
mcp_auth_mode: Literal["token", "oauth"] = "oauth"
|
||||||
|
mcp_resource_url: str = "http://localhost:8001/mcp"
|
||||||
|
mcp_oauth_issuer: str = ""
|
||||||
|
mcp_oauth_audience: str = ""
|
||||||
|
mcp_oauth_jwks_url: str = ""
|
||||||
|
mcp_oauth_required_scope: str = "mcp:tools"
|
||||||
|
|
||||||
|
@field_validator("crawl_limit", mode="before")
|
||||||
|
@classmethod
|
||||||
|
def empty_crawl_limit_as_none(cls, value):
|
||||||
|
if value == "":
|
||||||
|
return None
|
||||||
|
return value
|
||||||
|
|
||||||
|
def oauth_jwks_url(self) -> str:
|
||||||
|
if self.mcp_oauth_jwks_url:
|
||||||
|
return self.mcp_oauth_jwks_url
|
||||||
|
issuer = self.mcp_oauth_issuer.rstrip("/")
|
||||||
|
if not issuer:
|
||||||
|
return ""
|
||||||
|
return f"{issuer}/.well-known/jwks.json"
|
||||||
|
|
||||||
|
|
||||||
@lru_cache
|
@lru_cache
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ from fastapi.staticfiles import StaticFiles
|
|||||||
from app.admin import router as admin_router
|
from app.admin import router as admin_router
|
||||||
from app.api import router as api_router
|
from app.api import router as api_router
|
||||||
from app.db import init_db
|
from app.db import init_db
|
||||||
|
from app.mcp import metadata_router as mcp_metadata_router
|
||||||
from app.mcp import router as mcp_router
|
from app.mcp import router as mcp_router
|
||||||
from app.version import BACKEND_VERSION
|
from app.version import BACKEND_VERSION
|
||||||
|
|
||||||
@@ -12,6 +13,7 @@ app.mount("/static", StaticFiles(directory="app/static"), name="static")
|
|||||||
app.include_router(api_router)
|
app.include_router(api_router)
|
||||||
app.include_router(admin_router)
|
app.include_router(admin_router)
|
||||||
app.include_router(mcp_router)
|
app.include_router(mcp_router)
|
||||||
|
app.include_router(mcp_metadata_router)
|
||||||
|
|
||||||
|
|
||||||
@app.on_event("startup")
|
@app.on_event("startup")
|
||||||
|
|||||||
10
app/mcp.py
10
app/mcp.py
@@ -7,9 +7,10 @@ from sqlalchemy.orm import Session
|
|||||||
from app.config import Settings, get_settings
|
from app.config import Settings, get_settings
|
||||||
from app.db import get_db
|
from app.db import get_db
|
||||||
from app.models import CrawlRun, Employee
|
from app.models import CrawlRun, Employee
|
||||||
from app.security import require_mcp_token
|
from app.security import mcp_protected_resource_metadata, require_mcp_auth
|
||||||
|
|
||||||
router = APIRouter(prefix="/mcp")
|
router = APIRouter(prefix="/mcp")
|
||||||
|
metadata_router = APIRouter()
|
||||||
|
|
||||||
|
|
||||||
TOOLS = [
|
TOOLS = [
|
||||||
@@ -55,7 +56,7 @@ async def mcp_http(
|
|||||||
db: Session = Depends(get_db),
|
db: Session = Depends(get_db),
|
||||||
settings: Settings = Depends(get_settings),
|
settings: Settings = Depends(get_settings),
|
||||||
) -> dict:
|
) -> dict:
|
||||||
require_mcp_token(request, settings)
|
require_mcp_auth(request, settings)
|
||||||
payload = await request.json()
|
payload = await request.json()
|
||||||
method = payload.get("method")
|
method = payload.get("method")
|
||||||
request_id = payload.get("id")
|
request_id = payload.get("id")
|
||||||
@@ -168,3 +169,8 @@ def _run_payload(run: CrawlRun) -> dict:
|
|||||||
|
|
||||||
def _tool_response(data: object) -> dict:
|
def _tool_response(data: object) -> dict:
|
||||||
return {"content": [{"type": "text", "text": json.dumps(data, ensure_ascii=False, default=str)}]}
|
return {"content": [{"type": "text", "text": json.dumps(data, ensure_ascii=False, default=str)}]}
|
||||||
|
|
||||||
|
|
||||||
|
@metadata_router.get("/.well-known/oauth-protected-resource")
|
||||||
|
def oauth_protected_resource(settings: Settings = Depends(get_settings)) -> dict:
|
||||||
|
return mcp_protected_resource_metadata(settings)
|
||||||
|
|||||||
@@ -164,6 +164,7 @@ def parse_person_profile(
|
|||||||
header = extract_person_header(soup, normalized_url)
|
header = extract_person_header(soup, normalized_url)
|
||||||
tabs = extract_person_tabs(soup, normalized_url)
|
tabs = extract_person_tabs(soup, normalized_url)
|
||||||
sections = extract_sections(soup, normalized_url)
|
sections = extract_sections(soup, normalized_url)
|
||||||
|
sections = enrich_sections_from_hse_widgets(session, soup, normalized_url, headers, timeout, sections)
|
||||||
internal_links = [tab["href"] for tab in tabs if tab.get("href")]
|
internal_links = [tab["href"] for tab in tabs if tab.get("href")]
|
||||||
|
|
||||||
return {
|
return {
|
||||||
@@ -183,6 +184,25 @@ def parse_person_profile(
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def enrich_sections_from_hse_widgets(
|
||||||
|
session: Session,
|
||||||
|
soup: BeautifulSoup,
|
||||||
|
source_url: str,
|
||||||
|
headers: dict[str, str],
|
||||||
|
timeout: int,
|
||||||
|
sections: list[dict],
|
||||||
|
) -> list[dict]:
|
||||||
|
enriched = list(sections)
|
||||||
|
publications = _load_widget_publications(session, soup, headers, timeout)
|
||||||
|
if publications:
|
||||||
|
enriched = _upsert_publications_section(enriched, publications)
|
||||||
|
|
||||||
|
theses = _load_widget_graduation_theses(session, soup, source_url, headers, timeout)
|
||||||
|
if theses:
|
||||||
|
enriched = _upsert_graduation_theses_section(enriched, theses)
|
||||||
|
return enriched
|
||||||
|
|
||||||
|
|
||||||
def _render_with_playwright(source_url: str, fallback_html: str) -> str:
|
def _render_with_playwright(source_url: str, fallback_html: str) -> str:
|
||||||
try:
|
try:
|
||||||
from playwright.sync_api import sync_playwright
|
from playwright.sync_api import sync_playwright
|
||||||
@@ -206,6 +226,89 @@ def _render_with_playwright(source_url: str, fallback_html: str) -> str:
|
|||||||
return fallback_html
|
return fallback_html
|
||||||
|
|
||||||
|
|
||||||
|
def _load_widget_publications(session: Session, soup: BeautifulSoup, headers: dict[str, str], timeout: int) -> list[dict]:
|
||||||
|
script = soup.select_one('script[data-widget-name="AuthorSearch"][data-author]')
|
||||||
|
if not script:
|
||||||
|
return []
|
||||||
|
author_id = normalize_ws(script.get("data-author"))
|
||||||
|
if not author_id:
|
||||||
|
return []
|
||||||
|
|
||||||
|
publications = []
|
||||||
|
page_id = 1
|
||||||
|
per_page = 100
|
||||||
|
while page_id <= 20:
|
||||||
|
payload = {
|
||||||
|
"type": "ANY",
|
||||||
|
"filterParams": (
|
||||||
|
f'"acceptLanguage":"ru"|"fullTextPublicEnabled": 1|'
|
||||||
|
f'"pubsAuthor": {author_id}|"widgetName": "AuthorSearch"'
|
||||||
|
),
|
||||||
|
"paginationParams": {
|
||||||
|
"publsSort": ["TITLE_ASC"],
|
||||||
|
"publsCount": per_page,
|
||||||
|
"pageId": page_id,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
try:
|
||||||
|
response = session.post(
|
||||||
|
"https://publications.hse.ru/api/searchPubs",
|
||||||
|
json=payload,
|
||||||
|
headers=headers,
|
||||||
|
timeout=timeout,
|
||||||
|
)
|
||||||
|
response.raise_for_status()
|
||||||
|
data = response.json()
|
||||||
|
except Exception:
|
||||||
|
return publications
|
||||||
|
|
||||||
|
result = data.get("result") if isinstance(data, dict) else {}
|
||||||
|
items = result.get("items") if isinstance(result, dict) else []
|
||||||
|
if not isinstance(items, list) or not items:
|
||||||
|
break
|
||||||
|
publications.extend(_normalize_publication_item(item) for item in items if isinstance(item, dict))
|
||||||
|
|
||||||
|
total = int(result.get("total") or 0)
|
||||||
|
if not result.get("more") and len(publications) >= total:
|
||||||
|
break
|
||||||
|
page_id += 1
|
||||||
|
return _dedupe_publications(publications)
|
||||||
|
|
||||||
|
|
||||||
|
def _load_widget_graduation_theses(
|
||||||
|
session: Session,
|
||||||
|
soup: BeautifulSoup,
|
||||||
|
source_url: str,
|
||||||
|
headers: dict[str, str],
|
||||||
|
timeout: int,
|
||||||
|
) -> list[dict]:
|
||||||
|
script = soup.select_one('script[src*="/n/stat/vkr/app.js"][data-person-id]')
|
||||||
|
if not script:
|
||||||
|
return []
|
||||||
|
person_id = normalize_ws(script.get("data-person-id"))
|
||||||
|
api_url = normalize_ws(script.get("data-api-url")) or "/n/vkr/api/"
|
||||||
|
if not person_id:
|
||||||
|
return []
|
||||||
|
|
||||||
|
request_headers = {**headers, "x-portal-language": "ru"}
|
||||||
|
try:
|
||||||
|
response = session.get(
|
||||||
|
urljoin(source_url, api_url),
|
||||||
|
params={"supervisorId": person_id},
|
||||||
|
headers=request_headers,
|
||||||
|
timeout=timeout,
|
||||||
|
)
|
||||||
|
response.raise_for_status()
|
||||||
|
data = response.json()
|
||||||
|
except Exception:
|
||||||
|
return []
|
||||||
|
|
||||||
|
items = data.get("data") if isinstance(data, dict) else []
|
||||||
|
if not isinstance(items, list):
|
||||||
|
return []
|
||||||
|
return [_normalize_vkr_item(item, source_url) for item in items if isinstance(item, dict)]
|
||||||
|
|
||||||
|
|
||||||
def _collect_between_h2(start_h2: Tag) -> list[Tag | NavigableString | str]:
|
def _collect_between_h2(start_h2: Tag) -> list[Tag | NavigableString | str]:
|
||||||
nodes = []
|
nodes = []
|
||||||
for sibling in start_h2.next_siblings:
|
for sibling in start_h2.next_siblings:
|
||||||
@@ -353,6 +456,122 @@ def _parse_vkr_items(nodes: list) -> list[str]:
|
|||||||
return [item for item in dict.fromkeys(items) if item]
|
return [item for item in dict.fromkeys(items) if item]
|
||||||
|
|
||||||
|
|
||||||
|
def _normalize_publication_item(item: dict) -> dict:
|
||||||
|
publication_id = str(item.get("id") or "").strip()
|
||||||
|
title = _html_to_text(item.get("title"))
|
||||||
|
year = item.get("year")
|
||||||
|
publication_type = str(item.get("type") or "").strip() or None
|
||||||
|
description = item.get("description") if isinstance(item.get("description"), dict) else {}
|
||||||
|
short_description = _localized_value(description.get("short")) or _localized_value(description.get("shortLeft"))
|
||||||
|
text = normalize_ws(" ".join(part for part in [title, str(year or ""), short_description] if part))
|
||||||
|
return {
|
||||||
|
"id": publication_id or None,
|
||||||
|
"title": title or publication_id,
|
||||||
|
"year": year,
|
||||||
|
"type": publication_type,
|
||||||
|
"url": f"https://publications.hse.ru/view/{publication_id}" if publication_id else None,
|
||||||
|
"text": text or title or publication_id,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def _normalize_vkr_item(item: dict, source_url: str) -> dict:
|
||||||
|
thesis_id = item.get("id")
|
||||||
|
program = item.get("learnProgram") if isinstance(item.get("learnProgram"), dict) else {}
|
||||||
|
org_unit = item.get("orgUnit") if isinstance(item.get("orgUnit"), dict) else {}
|
||||||
|
supervisors = []
|
||||||
|
for supervisor in item.get("supervisors") or []:
|
||||||
|
if not isinstance(supervisor, dict):
|
||||||
|
continue
|
||||||
|
name = normalize_ws(supervisor.get("name"))
|
||||||
|
url = normalize_ws(supervisor.get("url"))
|
||||||
|
if name or url:
|
||||||
|
supervisors.append({"name": name or url, "url": url or None})
|
||||||
|
return {
|
||||||
|
"id": thesis_id,
|
||||||
|
"student": normalize_ws(item.get("student")),
|
||||||
|
"title": normalize_ws(item.get("title")),
|
||||||
|
"defense_year": item.get("year"),
|
||||||
|
"level": normalize_ws(item.get("level")),
|
||||||
|
"rating": item.get("rating"),
|
||||||
|
"project_url": urljoin(source_url, f"/edu/vkr/{thesis_id}") if thesis_id else None,
|
||||||
|
"program": normalize_ws(program.get("title")),
|
||||||
|
"program_url": urljoin(source_url, program.get("url")) if program.get("url") else None,
|
||||||
|
"org_unit": normalize_ws(org_unit.get("title")),
|
||||||
|
"org_unit_url": urljoin(source_url, org_unit.get("url")) if org_unit.get("url") else None,
|
||||||
|
"supervisors": supervisors,
|
||||||
|
"text": normalize_ws(" ".join(str(part) for part in [item.get("student"), item.get("title"), item.get("year")] if part)),
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def _upsert_publications_section(sections: list[dict], publications: list[dict]) -> list[dict]:
|
||||||
|
merged = []
|
||||||
|
inserted = False
|
||||||
|
for section in sections:
|
||||||
|
if section.get("type") != "publications":
|
||||||
|
merged.append(section)
|
||||||
|
continue
|
||||||
|
existing = section.get("publications") or []
|
||||||
|
section = {
|
||||||
|
**section,
|
||||||
|
"publications_count": max(section.get("publications_count") or 0, len(publications)),
|
||||||
|
"publications": _dedupe_publications([*existing, *publications]),
|
||||||
|
}
|
||||||
|
section["items"] = [item["text"] for item in section["publications"] if item.get("text")]
|
||||||
|
merged.append(section)
|
||||||
|
inserted = True
|
||||||
|
if not inserted:
|
||||||
|
merged.append(
|
||||||
|
{
|
||||||
|
"title": "Публикации и исследования",
|
||||||
|
"slug": "publikacii_i_issledovaniya",
|
||||||
|
"type": "publications",
|
||||||
|
"raw_text": "",
|
||||||
|
"paragraphs": [],
|
||||||
|
"items": [item["text"] for item in publications if item.get("text")],
|
||||||
|
"links": [],
|
||||||
|
"publications_count": len(publications),
|
||||||
|
"publications": publications,
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return merged
|
||||||
|
|
||||||
|
|
||||||
|
def _upsert_graduation_theses_section(sections: list[dict], theses: list[dict]) -> list[dict]:
|
||||||
|
section = {
|
||||||
|
"title": "Выпускные квалификационные работы студентов НИУ ВШЭ",
|
||||||
|
"slug": "vypusknye_kvalifikacionnye_raboty_studentov_niu_vshe",
|
||||||
|
"type": "graduation_theses",
|
||||||
|
"raw_text": "",
|
||||||
|
"paragraphs": [],
|
||||||
|
"items": [item["text"] for item in theses if item.get("text")],
|
||||||
|
"links": [{"text": item["title"], "url": item["project_url"]} for item in theses if item.get("title") and item.get("project_url")],
|
||||||
|
"theses_count": len(theses),
|
||||||
|
"theses": theses,
|
||||||
|
}
|
||||||
|
return [item for item in sections if item.get("type") != "graduation_theses"] + [section]
|
||||||
|
|
||||||
|
|
||||||
|
def _dedupe_publications(items: list[dict]) -> list[dict]:
|
||||||
|
seen = set()
|
||||||
|
unique = []
|
||||||
|
for item in items:
|
||||||
|
key = item.get("id") or item.get("url") or item.get("title")
|
||||||
|
if key and key not in seen:
|
||||||
|
seen.add(key)
|
||||||
|
unique.append(item)
|
||||||
|
return unique
|
||||||
|
|
||||||
|
|
||||||
|
def _html_to_text(value: object) -> str:
|
||||||
|
return normalize_ws(BeautifulSoup(str(value or ""), "html.parser").get_text(" ", strip=True))
|
||||||
|
|
||||||
|
|
||||||
|
def _localized_value(value: object) -> str:
|
||||||
|
if isinstance(value, dict):
|
||||||
|
return normalize_ws(value.get("ru") or value.get("publ") or value.get("en"))
|
||||||
|
return normalize_ws(str(value or ""))
|
||||||
|
|
||||||
|
|
||||||
def _slugify(value: str) -> str:
|
def _slugify(value: str) -> str:
|
||||||
cleaned = re.sub(r"[^\w\s-]", "", value.lower(), flags=re.UNICODE)
|
cleaned = re.sub(r"[^\w\s-]", "", value.lower(), flags=re.UNICODE)
|
||||||
return re.sub(r"[-\s]+", "_", cleaned).strip("_") or "section"
|
return re.sub(r"[-\s]+", "_", cleaned).strip("_") or "section"
|
||||||
|
|||||||
@@ -3,7 +3,10 @@ import hashlib
|
|||||||
import hmac
|
import hmac
|
||||||
import json
|
import json
|
||||||
import time
|
import time
|
||||||
|
from functools import lru_cache
|
||||||
|
|
||||||
|
import jwt
|
||||||
|
from jwt import PyJWKClient, PyJWTError
|
||||||
from fastapi import HTTPException, Request, status
|
from fastapi import HTTPException, Request, status
|
||||||
|
|
||||||
from app.config import Settings
|
from app.config import Settings
|
||||||
@@ -46,7 +49,91 @@ def require_admin(request: Request, settings: Settings) -> str:
|
|||||||
return username
|
return username
|
||||||
|
|
||||||
|
|
||||||
def require_mcp_token(request: Request, settings: Settings) -> None:
|
def require_mcp_auth(request: Request, settings: Settings) -> None:
|
||||||
auth = request.headers.get("authorization", "")
|
auth = request.headers.get("authorization", "")
|
||||||
if not auth.startswith("Bearer ") or not hmac.compare_digest(auth.removeprefix("Bearer ").strip(), settings.mcp_token):
|
if not auth.startswith("Bearer "):
|
||||||
raise HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, detail="Invalid MCP token")
|
raise _mcp_unauthorized(settings, "Missing bearer token")
|
||||||
|
|
||||||
|
token = auth.removeprefix("Bearer ").strip()
|
||||||
|
if _mcp_static_token_allowed(settings) and hmac.compare_digest(token, settings.mcp_token):
|
||||||
|
return
|
||||||
|
if _mcp_oauth_allowed(settings):
|
||||||
|
_validate_mcp_oauth_token(token, settings)
|
||||||
|
return
|
||||||
|
raise _mcp_unauthorized(settings, "Invalid MCP token")
|
||||||
|
|
||||||
|
|
||||||
|
def require_mcp_token(request: Request, settings: Settings) -> None:
|
||||||
|
require_mcp_auth(request, settings)
|
||||||
|
|
||||||
|
|
||||||
|
def mcp_protected_resource_metadata(settings: Settings) -> dict:
|
||||||
|
authorization_servers = [settings.mcp_oauth_issuer.rstrip("/")] if settings.mcp_oauth_issuer else []
|
||||||
|
return {
|
||||||
|
"resource": settings.mcp_resource_url,
|
||||||
|
"authorization_servers": authorization_servers,
|
||||||
|
"bearer_methods_supported": ["header"],
|
||||||
|
"scopes_supported": [settings.mcp_oauth_required_scope],
|
||||||
|
"resource_documentation": settings.mcp_resource_url,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def _mcp_static_token_allowed(settings: Settings) -> bool:
|
||||||
|
return settings.mcp_auth_mode == "token"
|
||||||
|
|
||||||
|
|
||||||
|
def _mcp_oauth_allowed(settings: Settings) -> bool:
|
||||||
|
return settings.mcp_auth_mode == "oauth"
|
||||||
|
|
||||||
|
|
||||||
|
def _validate_mcp_oauth_token(token: str, settings: Settings) -> None:
|
||||||
|
if not settings.mcp_oauth_issuer or not settings.mcp_oauth_audience or not settings.oauth_jwks_url():
|
||||||
|
raise _mcp_unauthorized(settings, "MCP OAuth is not configured")
|
||||||
|
try:
|
||||||
|
signing_key = _get_mcp_oauth_signing_key(token, settings).key
|
||||||
|
claims = jwt.decode(
|
||||||
|
token,
|
||||||
|
signing_key,
|
||||||
|
algorithms=["RS256", "RS384", "RS512", "ES256", "ES384", "ES512"],
|
||||||
|
audience=settings.mcp_oauth_audience,
|
||||||
|
issuer=settings.mcp_oauth_issuer.rstrip("/"),
|
||||||
|
)
|
||||||
|
except PyJWTError as exc:
|
||||||
|
raise _mcp_unauthorized(settings, "Invalid OAuth access token") from exc
|
||||||
|
if not _claims_have_scope(claims, settings.mcp_oauth_required_scope):
|
||||||
|
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail="Missing required MCP OAuth scope")
|
||||||
|
|
||||||
|
|
||||||
|
def _claims_have_scope(claims: dict, required_scope: str) -> bool:
|
||||||
|
scopes: set[str] = set()
|
||||||
|
scope = claims.get("scope")
|
||||||
|
if isinstance(scope, str):
|
||||||
|
scopes.update(scope.split())
|
||||||
|
scp = claims.get("scp")
|
||||||
|
if isinstance(scp, str):
|
||||||
|
scopes.update(scp.split())
|
||||||
|
elif isinstance(scp, list):
|
||||||
|
scopes.update(str(item) for item in scp)
|
||||||
|
return required_scope in scopes
|
||||||
|
|
||||||
|
|
||||||
|
@lru_cache(maxsize=16)
|
||||||
|
def _get_jwk_client(jwks_url: str) -> PyJWKClient:
|
||||||
|
return PyJWKClient(jwks_url)
|
||||||
|
|
||||||
|
|
||||||
|
def _get_mcp_oauth_signing_key(token: str, settings: Settings):
|
||||||
|
return _get_jwk_client(settings.oauth_jwks_url()).get_signing_key_from_jwt(token)
|
||||||
|
|
||||||
|
|
||||||
|
def _mcp_unauthorized(settings: Settings, detail: str) -> HTTPException:
|
||||||
|
headers = {}
|
||||||
|
if _mcp_oauth_allowed(settings):
|
||||||
|
headers["WWW-Authenticate"] = f'Bearer resource_metadata="{_mcp_metadata_url(settings)}"'
|
||||||
|
return HTTPException(status_code=status.HTTP_401_UNAUTHORIZED, detail=detail, headers=headers)
|
||||||
|
|
||||||
|
|
||||||
|
def _mcp_metadata_url(settings: Settings) -> str:
|
||||||
|
resource_url = settings.mcp_resource_url.rstrip("/")
|
||||||
|
base_url = resource_url[: -len("/mcp")] if resource_url.endswith("/mcp") else resource_url
|
||||||
|
return f"{base_url}/.well-known/oauth-protected-resource"
|
||||||
|
|||||||
@@ -112,7 +112,7 @@ def list_employees_page(
|
|||||||
limit: int = 50,
|
limit: int = 50,
|
||||||
offset: int = 0,
|
offset: int = 0,
|
||||||
) -> dict[str, Any]:
|
) -> dict[str, Any]:
|
||||||
limit = max(1, min(limit, 200))
|
limit = limit if limit in {25, 50, 100} else 50
|
||||||
offset = max(0, offset)
|
offset = max(0, offset)
|
||||||
base_stmt = build_employee_query(
|
base_stmt = build_employee_query(
|
||||||
status=status,
|
status=status,
|
||||||
@@ -281,6 +281,8 @@ def _normalize_section(section: Any) -> dict[str, Any]:
|
|||||||
"year_entries": _normalize_year_entries(section.get("year_entries")),
|
"year_entries": _normalize_year_entries(section.get("year_entries")),
|
||||||
"publications": _normalize_publications(section.get("publications")),
|
"publications": _normalize_publications(section.get("publications")),
|
||||||
"publications_count": section.get("publications_count"),
|
"publications_count": section.get("publications_count"),
|
||||||
|
"theses": _normalize_theses(section.get("theses")),
|
||||||
|
"theses_count": section.get("theses_count"),
|
||||||
"academic_year": section.get("academic_year"),
|
"academic_year": section.get("academic_year"),
|
||||||
"courses": _normalize_courses(section.get("courses")),
|
"courses": _normalize_courses(section.get("courses")),
|
||||||
"table": _normalize_table(section.get("table")),
|
"table": _normalize_table(section.get("table")),
|
||||||
@@ -349,6 +351,35 @@ def _normalize_courses(items: Any) -> list[dict[str, str | None]]:
|
|||||||
return normalized
|
return normalized
|
||||||
|
|
||||||
|
|
||||||
|
def _normalize_theses(items: Any) -> list[dict[str, Any]]:
|
||||||
|
normalized = []
|
||||||
|
if not isinstance(items, list):
|
||||||
|
return normalized
|
||||||
|
for item in items:
|
||||||
|
if not isinstance(item, dict):
|
||||||
|
continue
|
||||||
|
title = str(item.get("title") or "").strip()
|
||||||
|
student = str(item.get("student") or "").strip()
|
||||||
|
if not title and not student:
|
||||||
|
continue
|
||||||
|
normalized.append(
|
||||||
|
{
|
||||||
|
"id": item.get("id"),
|
||||||
|
"student": student,
|
||||||
|
"title": title,
|
||||||
|
"defense_year": item.get("defense_year") or item.get("year"),
|
||||||
|
"level": str(item.get("level") or "").strip(),
|
||||||
|
"rating": item.get("rating"),
|
||||||
|
"project_url": str(item.get("project_url") or "").strip() or None,
|
||||||
|
"program": str(item.get("program") or "").strip(),
|
||||||
|
"program_url": str(item.get("program_url") or "").strip() or None,
|
||||||
|
"org_unit": str(item.get("org_unit") or "").strip(),
|
||||||
|
"org_unit_url": str(item.get("org_unit_url") or "").strip() or None,
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return normalized
|
||||||
|
|
||||||
|
|
||||||
def _normalize_table(table: Any) -> dict[str, Any] | None:
|
def _normalize_table(table: Any) -> dict[str, Any] | None:
|
||||||
if not isinstance(table, dict):
|
if not isinstance(table, dict):
|
||||||
return None
|
return None
|
||||||
|
|||||||
@@ -270,6 +270,18 @@
|
|||||||
line-height: 1.55;
|
line-height: 1.55;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.employee-section__meta {
|
||||||
|
display: flex;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
gap: 8px 12px;
|
||||||
|
color: #4b5563;
|
||||||
|
font-size: 13px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.employee-section__meta-item {
|
||||||
|
line-height: 1.4;
|
||||||
|
}
|
||||||
|
|
||||||
.employee-section__table-wrap {
|
.employee-section__table-wrap {
|
||||||
overflow-x: auto;
|
overflow-x: auto;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -33,6 +33,12 @@
|
|||||||
<option value="asc" {% if filters.direction == "asc" %}selected{% endif %}>По возрастанию</option>
|
<option value="asc" {% if filters.direction == "asc" %}selected{% endif %}>По возрастанию</option>
|
||||||
<option value="desc" {% if filters.direction == "desc" %}selected{% endif %}>По убыванию</option>
|
<option value="desc" {% if filters.direction == "desc" %}selected{% endif %}>По убыванию</option>
|
||||||
</select>
|
</select>
|
||||||
|
<select class="directory__input" name="limit" onchange="this.form.offset.value = 0; this.form.submit()">
|
||||||
|
{% for value in [25, 50, 100] %}
|
||||||
|
<option value="{{ value }}" {% if filters.limit == value %}selected{% endif %}>На странице: {{ value }}</option>
|
||||||
|
{% endfor %}
|
||||||
|
</select>
|
||||||
|
<input type="hidden" name="offset" value="{{ filters.offset }}">
|
||||||
<button class="button" type="submit">Применить</button>
|
<button class="button" type="submit">Применить</button>
|
||||||
</form>
|
</form>
|
||||||
|
|
||||||
|
|||||||
@@ -138,6 +138,34 @@
|
|||||||
</li>
|
</li>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
</ul>
|
</ul>
|
||||||
|
{% elif section.type == "graduation_theses" and section.theses %}
|
||||||
|
{% if section.theses_count %}<p class="employee-section__note">Всего: {{ section.theses_count }}</p>{% endif %}
|
||||||
|
<ul class="employee-card__list">
|
||||||
|
{% for thesis in section.theses %}
|
||||||
|
<li class="employee-card__list-item">
|
||||||
|
{% if thesis.student %}<strong>{{ thesis.student }}</strong>{% endif %}
|
||||||
|
{% if thesis.title %}
|
||||||
|
<div class="employee-section__text">
|
||||||
|
{% if thesis.project_url %}
|
||||||
|
<a class="admin__link" href="{{ thesis.project_url }}">{{ thesis.title }}</a>
|
||||||
|
{% else %}
|
||||||
|
{{ thesis.title }}
|
||||||
|
{% endif %}
|
||||||
|
</div>
|
||||||
|
{% endif %}
|
||||||
|
<div class="employee-section__meta">
|
||||||
|
{% if thesis.defense_year %}<span class="employee-section__meta-item">Год защиты: {{ thesis.defense_year }}</span>{% endif %}
|
||||||
|
{% if thesis.level %}<span class="employee-section__meta-item">{{ thesis.level }}</span>{% endif %}
|
||||||
|
{% if thesis.rating is not none %}<span class="employee-section__meta-item">Оценка: {{ thesis.rating }}</span>{% endif %}
|
||||||
|
{% if thesis.program %}
|
||||||
|
<span class="employee-section__meta-item">
|
||||||
|
{% if thesis.program_url %}<a class="admin__link" href="{{ thesis.program_url }}">{{ thesis.program }}</a>{% else %}{{ thesis.program }}{% endif %}
|
||||||
|
</span>
|
||||||
|
{% endif %}
|
||||||
|
</div>
|
||||||
|
</li>
|
||||||
|
{% endfor %}
|
||||||
|
</ul>
|
||||||
{% elif section.type == "table" and section.table %}
|
{% elif section.type == "table" and section.table %}
|
||||||
<div class="employee-section__table-wrap">
|
<div class="employee-section__table-wrap">
|
||||||
<table class="employee-section__table">
|
<table class="employee-section__table">
|
||||||
@@ -170,7 +198,7 @@
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
{% if section.links and section.type not in ["courses_by_year"] %}
|
{% if section.links and section.type not in ["courses_by_year", "graduation_theses"] %}
|
||||||
<div class="employee-section__links">
|
<div class="employee-section__links">
|
||||||
{% for link in section.links %}
|
{% for link in section.links %}
|
||||||
<a class="employee-section__link" href="{{ link.url }}">{{ link.text }}</a>
|
<a class="employee-section__link" href="{{ link.url }}">{{ link.text }}</a>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
APP_VERSION = "0.2.6"
|
APP_VERSION = "0.3.0"
|
||||||
FRONTEND_VERSION = "0.2.6"
|
FRONTEND_VERSION = "0.3.0"
|
||||||
BACKEND_VERSION = "0.2.6"
|
BACKEND_VERSION = "0.3.0"
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[project]
|
[project]
|
||||||
name = "miem-workers"
|
name = "miem-workers"
|
||||||
version = "0.2.6"
|
version = "0.3.0"
|
||||||
description = "MIEM employees parser, admin API, and MCP server"
|
description = "MIEM employees parser, admin API, and MCP server"
|
||||||
requires-python = ">=3.11"
|
requires-python = ">=3.11"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
@@ -12,6 +12,7 @@ dependencies = [
|
|||||||
"lxml>=5.2.0",
|
"lxml>=5.2.0",
|
||||||
"psycopg[binary]>=3.2.0",
|
"psycopg[binary]>=3.2.0",
|
||||||
"pydantic-settings>=2.4.0",
|
"pydantic-settings>=2.4.0",
|
||||||
|
"PyJWT[crypto]>=2.9.0",
|
||||||
"python-multipart>=0.0.9",
|
"python-multipart>=0.0.9",
|
||||||
"requests>=2.32.0",
|
"requests>=2.32.0",
|
||||||
"sqlalchemy>=2.0.32",
|
"sqlalchemy>=2.0.32",
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ jinja2>=3.1.4
|
|||||||
lxml>=5.2.0
|
lxml>=5.2.0
|
||||||
psycopg[binary]>=3.2.0
|
psycopg[binary]>=3.2.0
|
||||||
pydantic-settings>=2.4.0
|
pydantic-settings>=2.4.0
|
||||||
|
PyJWT[crypto]>=2.9.0
|
||||||
python-multipart>=0.0.9
|
python-multipart>=0.0.9
|
||||||
requests>=2.32.0
|
requests>=2.32.0
|
||||||
sqlalchemy>=2.0.32
|
sqlalchemy>=2.0.32
|
||||||
|
|||||||
@@ -85,6 +85,19 @@ def test_employee_detail_payload_normalizes_human_readable_sections(db_session):
|
|||||||
"academic_year": "2025/2026",
|
"academic_year": "2025/2026",
|
||||||
"courses": [{"title": "Course", "url": "https://example.test/course"}],
|
"courses": [{"title": "Course", "url": "https://example.test/course"}],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"title": "ВКР",
|
||||||
|
"type": "graduation_theses",
|
||||||
|
"theses_count": 1,
|
||||||
|
"theses": [
|
||||||
|
{
|
||||||
|
"student": "Student Name",
|
||||||
|
"title": "Thesis title",
|
||||||
|
"defense_year": 2025,
|
||||||
|
"project_url": "https://www.hse.ru/edu/vkr/1",
|
||||||
|
}
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"title": "Fallback",
|
"title": "Fallback",
|
||||||
"type": "generic",
|
"type": "generic",
|
||||||
@@ -102,7 +115,8 @@ def test_employee_detail_payload_normalizes_human_readable_sections(db_session):
|
|||||||
assert payload["sections"][0]["year_entries"][0]["text"] == "Master degree"
|
assert payload["sections"][0]["year_entries"][0]["text"] == "Master degree"
|
||||||
assert payload["sections"][1]["publications"][0]["title"] == "Paper"
|
assert payload["sections"][1]["publications"][0]["title"] == "Paper"
|
||||||
assert payload["sections"][2]["courses"][0]["title"] == "Course"
|
assert payload["sections"][2]["courses"][0]["title"] == "Course"
|
||||||
assert payload["sections"][3]["paragraphs"] == ["Fallback text"]
|
assert payload["sections"][3]["theses"][0]["student"] == "Student Name"
|
||||||
|
assert payload["sections"][4]["paragraphs"] == ["Fallback text"]
|
||||||
|
|
||||||
|
|
||||||
def test_employee_payloads_tolerate_malformed_current_data(db_session):
|
def test_employee_payloads_tolerate_malformed_current_data(db_session):
|
||||||
@@ -155,6 +169,7 @@ def test_list_employees_page_filters_sorts_and_paginates(db_session):
|
|||||||
|
|
||||||
assert page["total"] == 1
|
assert page["total"] == 1
|
||||||
assert page["employees"][0]["full_name"] == "Alpha"
|
assert page["employees"][0]["full_name"] == "Alpha"
|
||||||
|
assert page["limit"] == 50
|
||||||
|
|
||||||
|
|
||||||
def test_stats_payload_uses_latest_run_new_count(db_session):
|
def test_stats_payload_uses_latest_run_new_count(db_session):
|
||||||
|
|||||||
@@ -18,6 +18,8 @@ def test_directory_template_is_russian_and_uses_display_dates():
|
|||||||
assert "Сотрудники" in template
|
assert "Сотрудники" in template
|
||||||
assert "Колонки" in template
|
assert "Колонки" in template
|
||||||
assert "Применить" in template
|
assert "Применить" in template
|
||||||
|
assert "На странице: {{ value }}" in template
|
||||||
|
assert "{% for value in [25, 50, 100] %}" in template
|
||||||
assert "Найдено:" in template
|
assert "Найдено:" in template
|
||||||
assert "employee.first_seen_display" in template
|
assert "employee.first_seen_display" in template
|
||||||
assert "employee.last_seen_display" in template
|
assert "employee.last_seen_display" in template
|
||||||
|
|||||||
@@ -1,10 +1,15 @@
|
|||||||
|
import time
|
||||||
from datetime import datetime, timezone
|
from datetime import datetime, timezone
|
||||||
|
from types import SimpleNamespace
|
||||||
|
|
||||||
|
import jwt
|
||||||
from fastapi.testclient import TestClient
|
from fastapi.testclient import TestClient
|
||||||
|
from cryptography.hazmat.primitives.asymmetric import rsa
|
||||||
from sqlalchemy import create_engine
|
from sqlalchemy import create_engine
|
||||||
from sqlalchemy.orm import sessionmaker
|
from sqlalchemy.orm import sessionmaker
|
||||||
from sqlalchemy.pool import StaticPool
|
from sqlalchemy.pool import StaticPool
|
||||||
|
|
||||||
|
import app.security as security
|
||||||
from app.config import Settings, get_settings
|
from app.config import Settings, get_settings
|
||||||
from app.db import Base, get_db
|
from app.db import Base, get_db
|
||||||
from app.main import app
|
from app.main import app
|
||||||
@@ -18,7 +23,7 @@ def test_health_returns_versions():
|
|||||||
response = client.get("/api/health")
|
response = client.get("/api/health")
|
||||||
|
|
||||||
assert response.status_code == 200
|
assert response.status_code == 200
|
||||||
assert response.json()["backend_version"] == "0.2.6"
|
assert response.json()["backend_version"] == "0.3.0"
|
||||||
|
|
||||||
|
|
||||||
def test_mcp_requires_token_and_lists_tools():
|
def test_mcp_requires_token_and_lists_tools():
|
||||||
@@ -38,7 +43,9 @@ def test_mcp_requires_token_and_lists_tools():
|
|||||||
session.close()
|
session.close()
|
||||||
|
|
||||||
app.dependency_overrides[get_db] = override_db
|
app.dependency_overrides[get_db] = override_db
|
||||||
app.dependency_overrides[get_settings] = lambda: Settings(mcp_token="secret", session_secret="session-secret")
|
app.dependency_overrides[get_settings] = lambda: Settings(
|
||||||
|
mcp_auth_mode="token", mcp_token="secret", session_secret="session-secret"
|
||||||
|
)
|
||||||
client = TestClient(app)
|
client = TestClient(app)
|
||||||
|
|
||||||
unauthorized = client.post("/mcp", json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}})
|
unauthorized = client.post("/mcp", json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}})
|
||||||
@@ -88,7 +95,9 @@ def test_mcp_search_employees_returns_matching_employee():
|
|||||||
db.close()
|
db.close()
|
||||||
|
|
||||||
app.dependency_overrides[get_db] = override_db
|
app.dependency_overrides[get_db] = override_db
|
||||||
app.dependency_overrides[get_settings] = lambda: Settings(mcp_token="secret", session_secret="session-secret")
|
app.dependency_overrides[get_settings] = lambda: Settings(
|
||||||
|
mcp_auth_mode="token", mcp_token="secret", session_secret="session-secret"
|
||||||
|
)
|
||||||
client = TestClient(app)
|
client = TestClient(app)
|
||||||
|
|
||||||
response = client.post(
|
response = client.post(
|
||||||
@@ -108,6 +117,148 @@ def test_mcp_search_employees_returns_matching_employee():
|
|||||||
app.dependency_overrides.clear()
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_oauth_rejects_static_token():
|
||||||
|
engine = create_engine(
|
||||||
|
"sqlite:///:memory:",
|
||||||
|
connect_args={"check_same_thread": False},
|
||||||
|
poolclass=StaticPool,
|
||||||
|
)
|
||||||
|
Base.metadata.create_all(engine)
|
||||||
|
Session = sessionmaker(bind=engine)
|
||||||
|
|
||||||
|
def override_db():
|
||||||
|
session = Session()
|
||||||
|
try:
|
||||||
|
yield session
|
||||||
|
finally:
|
||||||
|
session.close()
|
||||||
|
|
||||||
|
settings = Settings(
|
||||||
|
mcp_auth_mode="oauth",
|
||||||
|
mcp_token="secret",
|
||||||
|
session_secret="session-secret",
|
||||||
|
mcp_oauth_issuer="https://auth.example.com",
|
||||||
|
mcp_oauth_audience="miem-mcp",
|
||||||
|
mcp_oauth_jwks_url="https://auth.example.com/.well-known/jwks.json",
|
||||||
|
)
|
||||||
|
app.dependency_overrides[get_db] = override_db
|
||||||
|
app.dependency_overrides[get_settings] = lambda: settings
|
||||||
|
client = TestClient(app)
|
||||||
|
|
||||||
|
response = client.post(
|
||||||
|
"/mcp",
|
||||||
|
headers={"Authorization": "Bearer secret"},
|
||||||
|
json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}},
|
||||||
|
)
|
||||||
|
|
||||||
|
assert response.status_code == 401
|
||||||
|
assert response.headers["www-authenticate"] == (
|
||||||
|
'Bearer resource_metadata="http://localhost:8001/.well-known/oauth-protected-resource"'
|
||||||
|
)
|
||||||
|
|
||||||
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_oauth_missing_auth_returns_metadata_challenge():
|
||||||
|
settings = Settings(
|
||||||
|
mcp_auth_mode="oauth",
|
||||||
|
mcp_resource_url="https://api.example.com/mcp",
|
||||||
|
mcp_oauth_issuer="https://auth.example.com",
|
||||||
|
mcp_oauth_audience="miem-mcp",
|
||||||
|
mcp_oauth_jwks_url="https://auth.example.com/.well-known/jwks.json",
|
||||||
|
)
|
||||||
|
app.dependency_overrides[get_settings] = lambda: settings
|
||||||
|
client = TestClient(app)
|
||||||
|
|
||||||
|
response = client.post("/mcp", json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}})
|
||||||
|
|
||||||
|
assert response.status_code == 401
|
||||||
|
assert response.headers["www-authenticate"] == (
|
||||||
|
'Bearer resource_metadata="https://api.example.com/.well-known/oauth-protected-resource"'
|
||||||
|
)
|
||||||
|
|
||||||
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_accepts_valid_oauth_jwt(monkeypatch):
|
||||||
|
public_key, token = _oauth_key_and_token()
|
||||||
|
monkeypatch.setattr(security, "_get_mcp_oauth_signing_key", lambda _token, _settings: SimpleNamespace(key=public_key))
|
||||||
|
app.dependency_overrides[get_settings] = lambda: _oauth_settings()
|
||||||
|
client = TestClient(app)
|
||||||
|
|
||||||
|
response = client.post(
|
||||||
|
"/mcp",
|
||||||
|
headers={"Authorization": f"Bearer {token}"},
|
||||||
|
json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}},
|
||||||
|
)
|
||||||
|
|
||||||
|
assert response.status_code == 200
|
||||||
|
assert response.json()["result"]["tools"][0]["name"] == "search_employees"
|
||||||
|
|
||||||
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_rejects_invalid_oauth_jwts(monkeypatch):
|
||||||
|
public_key, expired_token = _oauth_key_and_token(exp=int(time.time()) - 60)
|
||||||
|
_, wrong_issuer_token = _oauth_key_and_token(issuer="https://other.example.com")
|
||||||
|
_, wrong_audience_token = _oauth_key_and_token(audience="other-audience")
|
||||||
|
_, bad_signature_token = _oauth_key_and_token(public_key=public_key)
|
||||||
|
monkeypatch.setattr(security, "_get_mcp_oauth_signing_key", lambda _token, _settings: SimpleNamespace(key=public_key))
|
||||||
|
app.dependency_overrides[get_settings] = lambda: _oauth_settings()
|
||||||
|
client = TestClient(app)
|
||||||
|
|
||||||
|
for token in [expired_token, wrong_issuer_token, wrong_audience_token, bad_signature_token]:
|
||||||
|
response = client.post(
|
||||||
|
"/mcp",
|
||||||
|
headers={"Authorization": f"Bearer {token}"},
|
||||||
|
json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}},
|
||||||
|
)
|
||||||
|
|
||||||
|
assert response.status_code == 401
|
||||||
|
|
||||||
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_rejects_oauth_jwt_without_required_scope(monkeypatch):
|
||||||
|
public_key, token = _oauth_key_and_token(scope="profile")
|
||||||
|
monkeypatch.setattr(security, "_get_mcp_oauth_signing_key", lambda _token, _settings: SimpleNamespace(key=public_key))
|
||||||
|
app.dependency_overrides[get_settings] = lambda: _oauth_settings()
|
||||||
|
client = TestClient(app)
|
||||||
|
|
||||||
|
response = client.post(
|
||||||
|
"/mcp",
|
||||||
|
headers={"Authorization": f"Bearer {token}"},
|
||||||
|
json={"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": {}},
|
||||||
|
)
|
||||||
|
|
||||||
|
assert response.status_code == 403
|
||||||
|
|
||||||
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_protected_resource_metadata_uses_settings():
|
||||||
|
settings = Settings(
|
||||||
|
mcp_resource_url="https://api.example.com/mcp",
|
||||||
|
mcp_oauth_issuer="https://auth.example.com/",
|
||||||
|
mcp_oauth_required_scope="mcp:tools",
|
||||||
|
)
|
||||||
|
app.dependency_overrides[get_settings] = lambda: settings
|
||||||
|
client = TestClient(app)
|
||||||
|
|
||||||
|
response = client.get("/.well-known/oauth-protected-resource")
|
||||||
|
|
||||||
|
assert response.status_code == 200
|
||||||
|
assert response.json() == {
|
||||||
|
"resource": "https://api.example.com/mcp",
|
||||||
|
"authorization_servers": ["https://auth.example.com"],
|
||||||
|
"bearer_methods_supported": ["header"],
|
||||||
|
"scopes_supported": ["mcp:tools"],
|
||||||
|
"resource_documentation": "https://api.example.com/mcp",
|
||||||
|
}
|
||||||
|
|
||||||
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
def test_api_employees_and_stats_require_admin_session():
|
def test_api_employees_and_stats_require_admin_session():
|
||||||
engine = create_engine(
|
engine = create_engine(
|
||||||
"sqlite:///:memory:",
|
"sqlite:///:memory:",
|
||||||
@@ -157,3 +308,35 @@ def test_api_employees_and_stats_require_admin_session():
|
|||||||
assert stats.json()["new_in_last_run"] == 1
|
assert stats.json()["new_in_last_run"] == 1
|
||||||
|
|
||||||
app.dependency_overrides.clear()
|
app.dependency_overrides.clear()
|
||||||
|
|
||||||
|
|
||||||
|
def _oauth_settings() -> Settings:
|
||||||
|
return Settings(
|
||||||
|
mcp_auth_mode="oauth",
|
||||||
|
mcp_resource_url="https://api.example.com/mcp",
|
||||||
|
mcp_oauth_issuer="https://auth.example.com",
|
||||||
|
mcp_oauth_audience="miem-mcp",
|
||||||
|
mcp_oauth_jwks_url="https://auth.example.com/.well-known/jwks.json",
|
||||||
|
session_secret="session-secret",
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def _oauth_key_and_token(
|
||||||
|
*,
|
||||||
|
issuer: str = "https://auth.example.com",
|
||||||
|
audience: str = "miem-mcp",
|
||||||
|
scope: str = "mcp:tools",
|
||||||
|
exp: int | None = None,
|
||||||
|
public_key=None,
|
||||||
|
):
|
||||||
|
private_key = rsa.generate_private_key(public_exponent=65537, key_size=2048)
|
||||||
|
claims = {
|
||||||
|
"iss": issuer,
|
||||||
|
"aud": audience,
|
||||||
|
"scope": scope,
|
||||||
|
"sub": "mcp-client",
|
||||||
|
"iat": int(time.time()),
|
||||||
|
"exp": exp or int(time.time()) + 300,
|
||||||
|
}
|
||||||
|
token = jwt.encode(claims, private_key, algorithm="RS256", headers={"kid": "test-key"})
|
||||||
|
return public_key or private_key.public_key(), token
|
||||||
|
|||||||
21
tests/test_config.py
Normal file
21
tests/test_config.py
Normal file
@@ -0,0 +1,21 @@
|
|||||||
|
import pytest
|
||||||
|
from pydantic import ValidationError
|
||||||
|
|
||||||
|
from app.config import Settings
|
||||||
|
|
||||||
|
|
||||||
|
def test_empty_crawl_limit_is_treated_as_none():
|
||||||
|
settings = Settings(crawl_limit="")
|
||||||
|
|
||||||
|
assert settings.crawl_limit is None
|
||||||
|
|
||||||
|
|
||||||
|
def test_numeric_crawl_limit_is_parsed():
|
||||||
|
settings = Settings(crawl_limit="25")
|
||||||
|
|
||||||
|
assert settings.crawl_limit == 25
|
||||||
|
|
||||||
|
|
||||||
|
def test_mcp_auth_mode_rejects_oauth_or_token_fallback():
|
||||||
|
with pytest.raises(ValidationError):
|
||||||
|
Settings(mcp_auth_mode="oauth_or_token")
|
||||||
@@ -14,6 +14,8 @@ def test_employee_detail_template_is_human_readable():
|
|||||||
assert "Основная информация" in template
|
assert "Основная информация" in template
|
||||||
assert "Контакты" in template
|
assert "Контакты" in template
|
||||||
assert "Разделы профиля" in template
|
assert "Разделы профиля" in template
|
||||||
|
assert "graduation_theses" in template
|
||||||
|
assert "Год защиты" in template
|
||||||
assert "Parser version" not in template
|
assert "Parser version" not in template
|
||||||
assert "First seen" not in template
|
assert "First seen" not in template
|
||||||
assert "Last seen" not in template
|
assert "Last seen" not in template
|
||||||
|
|||||||
@@ -1,9 +1,69 @@
|
|||||||
from bs4 import BeautifulSoup
|
from bs4 import BeautifulSoup
|
||||||
|
|
||||||
from app.parser.profile import extract_person_tabs
|
from app.parser.profile import enrich_sections_from_hse_widgets, extract_person_tabs
|
||||||
from app.parser.profile_url import normalize_profile_url, parse_profile_identity
|
from app.parser.profile_url import normalize_profile_url, parse_profile_identity
|
||||||
|
|
||||||
|
|
||||||
|
class FakeResponse:
|
||||||
|
def __init__(self, payload):
|
||||||
|
self.payload = payload
|
||||||
|
|
||||||
|
def raise_for_status(self):
|
||||||
|
return None
|
||||||
|
|
||||||
|
def json(self):
|
||||||
|
return self.payload
|
||||||
|
|
||||||
|
|
||||||
|
class FakeSession:
|
||||||
|
def __init__(self):
|
||||||
|
self.posts = []
|
||||||
|
self.gets = []
|
||||||
|
|
||||||
|
def post(self, url, **kwargs):
|
||||||
|
self.posts.append((url, kwargs))
|
||||||
|
return FakeResponse(
|
||||||
|
{
|
||||||
|
"status": "ok",
|
||||||
|
"result": {
|
||||||
|
"more": False,
|
||||||
|
"total": 1,
|
||||||
|
"items": [
|
||||||
|
{
|
||||||
|
"id": "888959076",
|
||||||
|
"type": "ARTICLE",
|
||||||
|
"title": "Дублирование пакетов",
|
||||||
|
"year": 2023,
|
||||||
|
"description": {"short": {"ru": "Информационные процессы. 2023."}},
|
||||||
|
}
|
||||||
|
],
|
||||||
|
},
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
|
def get(self, url, **kwargs):
|
||||||
|
self.gets.append((url, kwargs))
|
||||||
|
return FakeResponse(
|
||||||
|
{
|
||||||
|
"lang": "ru",
|
||||||
|
"success": True,
|
||||||
|
"data": [
|
||||||
|
{
|
||||||
|
"id": 1045750164,
|
||||||
|
"year": 2025,
|
||||||
|
"level": "Бакалавриат",
|
||||||
|
"title": "Аппаратно-программный комплекс защиты сети",
|
||||||
|
"rating": 8,
|
||||||
|
"student": "Лесняк Владислав Евгеньевич",
|
||||||
|
"learnProgram": {"title": "Информатика и вычислительная техника", "url": "https://hse.ru/ba/isct/"},
|
||||||
|
"orgUnit": {"title": "МИЭМ", "url": "https://www.hse.ru/org/url/59315150"},
|
||||||
|
"supervisors": [{"url": "https://www.hse.ru/org/persons/803294906", "name": "Борисов Сергей Петрович"}],
|
||||||
|
}
|
||||||
|
],
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
def test_normalize_profile_url_supports_staff_and_org_persons():
|
def test_normalize_profile_url_supports_staff_and_org_persons():
|
||||||
assert normalize_profile_url("/staff/avsergeev#sci") == "https://www.hse.ru/staff/avsergeev"
|
assert normalize_profile_url("/staff/avsergeev#sci") == "https://www.hse.ru/staff/avsergeev"
|
||||||
assert normalize_profile_url("https://www.hse.ru/org/persons/123/") == "https://www.hse.ru/org/persons/123"
|
assert normalize_profile_url("https://www.hse.ru/org/persons/123/") == "https://www.hse.ru/org/persons/123"
|
||||||
@@ -26,3 +86,34 @@ def test_extract_person_tabs_prefers_person_menu_addition():
|
|||||||
|
|
||||||
assert [tab["title"] for tab in tabs] == ["Домашняя страница", "Публикации"]
|
assert [tab["title"] for tab in tabs] == ["Домашняя страница", "Публикации"]
|
||||||
assert tabs[1]["href"] == "https://www.hse.ru/staff/avsergeev#sci"
|
assert tabs[1]["href"] == "https://www.hse.ru/staff/avsergeev#sci"
|
||||||
|
|
||||||
|
|
||||||
|
def test_enrich_sections_from_hse_widgets_loads_publications_and_vkr():
|
||||||
|
soup = BeautifulSoup(
|
||||||
|
"""
|
||||||
|
<script src="/n/stat/publications/dist-w/publs.js" data-author="568398853" data-widget-name="AuthorSearch"></script>
|
||||||
|
<script src="/n/stat/vkr/app.js" data-api-url="/n/vkr/api/" data-person-id="803294906"></script>
|
||||||
|
""",
|
||||||
|
"html.parser",
|
||||||
|
)
|
||||||
|
session = FakeSession()
|
||||||
|
|
||||||
|
sections = enrich_sections_from_hse_widgets(
|
||||||
|
session,
|
||||||
|
soup,
|
||||||
|
"https://www.hse.ru/org/persons/803294906",
|
||||||
|
{"User-Agent": "test"},
|
||||||
|
10,
|
||||||
|
[],
|
||||||
|
)
|
||||||
|
|
||||||
|
publications = next(section for section in sections if section["type"] == "publications")
|
||||||
|
theses = next(section for section in sections if section["type"] == "graduation_theses")
|
||||||
|
|
||||||
|
assert publications["publications_count"] == 1
|
||||||
|
assert publications["publications"][0]["url"] == "https://publications.hse.ru/view/888959076"
|
||||||
|
assert theses["theses_count"] == 1
|
||||||
|
assert theses["theses"][0]["student"] == "Лесняк Владислав Евгеньевич"
|
||||||
|
assert theses["theses"][0]["project_url"] == "https://www.hse.ru/edu/vkr/1045750164"
|
||||||
|
assert session.posts[0][0] == "https://publications.hse.ru/api/searchPubs"
|
||||||
|
assert session.gets[0][1]["params"] == {"supervisorId": "803294906"}
|
||||||
|
|||||||
Reference in New Issue
Block a user