Skip to content

feat(plugin): axis-microsoft — additive Microsoft Graph tool via Axis (M2) - #3

Open
mcomageatlante wants to merge 1 commit into
mainfrom
feature/connectors-microsoft-plugin
Open

mcomageatlante wants to merge 1 commit into
mainfrom
feature/connectors-microsoft-plugin

Conversation

@mcomageatlante

Copy link
Copy Markdown

Contexte

Volet msgraph du chantier connecteurs (auth C4 = M1, NousResearch#58). Ici M2 : le harness gagne un
connecteur Microsoft 365 sans toucher le cœur (plugin, doctrine narrow-waist).

Ce que fait cette PR (M2)

Nouveau plugin plugins/axis_microsoft qui enregistre un seul tool, microsoft_graph, par
dessus
les tools bakés :

  • Proxy REST authentifié fin vers Microsoft Graph. À chaque appel, mint d'un access token
    délégué court
    auprès du service connecteurs Axis (POST /internal/connectors/microsoft/token,
    M1) → appel signé Bearer. Le sandbox ne détient aucun credential, le modèle ne voit jamais de
    token — Axis détient l'auth
    (client_secret OAuth + refresh token par-utilisateur restent en C4).
  • Additif & conditionnel : check_fn ne fait apparaître le tool que si le connecteur est
    provisionné (AXIS_CONNECTORS_URL + clé interne, injectés par le Timonier).
  • Cache de l'access token.

Tests

tests/plugins/test_axis_microsoft_plugin.py (7, sans réseau) : gating additif, surface
d'enregistrement, mint Bearer + réutilisation cache, surfaces d'erreur (non provisionné / path /
API / refus de mint).

Dépendances & suite

🤖 Generated with Claude Code

…Axis platform (M2)

New bundled plugin registering ONE tool, `microsoft_graph`, on top of the built-in
toolset (never overrides/removes — narrow-waist doctrine).

- Thin authenticated proxy to the Microsoft Graph REST API. Each call mints a
  short-lived DELEGATED access token from the Axis connectors service
  (C4 POST /internal/connectors/microsoft/token) and signs the call (Bearer).
  The sandbox holds no credential; the model never sees a token. Axis owns auth
  (OAuth client secret + per-user refresh token stay in the platform).
- Additive & conditional: check_fn surfaces the tool ONLY when the connector is
  provisioned for the run (AXIS_CONNECTORS_URL + internal key, injected by Timonier).
- Access token cache to avoid re-minting each call.

Tests (7, no network): additive gating, register surface, Bearer mint + token reuse,
error surfaces. Consumes C4 M1 endpoint (NousResearch#58). Enablement wiring = Timonier (M3).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LF5x35ogKS9ncccvuhf7nf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants