feat(dashboard): plot MCP tool calls on the request timeline - #13941
Conversation
|
Arrumei o changelog; duas pendências de produto ficam para o dono. Movi a linha do Pendência 1 — a metade MCP é morta em dashboard via túnel. Pendência 2 — o filtro por chave é inerte. Menor: Os testes são bons — |
1a81a32 to
cc7726c
Compare
|
Rebased onto Tunnel poll. GET Per-key filter. CI failures on this branch still match the inherited set (API Route Typecheck, Docs Gates, Fast Quality Gates, four unit shards). Merge integrity, Vitest, and ESLint stayed green on the previous head. |
cc7726c to
d46d12b
Compare
|
Rebased onto current Seven locale files conflicted; reviewed translations stayed, MCP timeline keys were re-applied. Tests 43/43. |
d46d12b to
c4613e5
Compare
|
Rebased onto current |
The request timeline only showed LLM call-logs, so MCP tool invocations were invisible and there was no per-key slice. Merge mcp_tool_audit as a distinct row kind and reuse the logs-grid API-key filter. A failed MCP fetch leaves the LLM path unchanged. Related to diegosouzapw#13898. diegosouzapw#13898 stays open. Signed-off-by: Minxi Hou <houminxi@gmail.com>
Name-only dropdown values must not be sent as MCP apiKeyId. A failed LLM or MCP fetch must keep the other source's bars, and a filtered poll must not wipe previously seen keys from the dropdown. Signed-off-by: Minxi Hou <houminxi@gmail.com>
GET /api/mcp/audit and /stats join the existing GET exemption set so a dashboard served through a tunnel can plot MCP bars. SSE and stream stay loopback-only. The handlers still require management auth. logToolCall now stamps the HTTP caller's API-key id (stdio falls back to the env-key lookup) instead of OMNIROUTE_API_KEY_ID, which is unset on almost every install and made the per-key filter drop every MCP bar. Signed-off-by: Minxi Hou <houminxi@gmail.com>
c4613e5 to
8d3693c
Compare
|
The MCP-on-timeline mapping is a solid addition, and closing the two product gaps from |
The pinned-membership test asks every new exemption to carry its reason next to the list; add it for /api/mcp/audit and /api/mcp/audit/stats.
77ec7c1
into
diegosouzapw:release/v3.8.51
Related to #13898. #13898 stays open.
The request timeline only plotted LLM rows from
/api/usage/call-logs. MCP tool calls already live inmcp_tool_audit; they never showed on the same axis.What this PR does
mcp_tool_auditrows onto the timeline askind: mcp(mcp:<id>so they do not collide with call-log ids).mcpOk); it does not wipe them.?apiKey=; MCP rows through?apiKeyId=only when the selected value is a known key id. A name-only filter skips the MCP fetch instead of asking for a null id.Follow-ups already on this branch (the two product holes from review)
/api/mcp/auditand/api/mcp/audit/statsare inLOCAL_ONLY_API_GET_EXEMPTIONS. POST and the rest of/api/mcp/*stay local-only. Without that, a tunnel-served dashboard 403s the poll forever.logToolCallno longer writesprocess.env.OMNIROUTE_API_KEY_ID. It usesresolveMcpCallerApiKeyId(HTTP headers first, then the env key lookup used by stdio). Selecting a dashboard key no longer drops every MCP bar.Changelog lives in
changelog.d/features/13941-mcp-timeline.md.Maintainer rework (merge-batch 2026-09-24)
release/v3.8.51tip (clean, no conflicts).routeGuard.tschange line by line: the exemption is exact-match on/api/mcp/auditand/api/mcp/audit/statsonly, GET/HEAD/OPTIONS only;/api/mcp/audit/extra,/api/mcp/sse,/api/mcp/streamand POST stay local-only (covered by the tests). Both handlers are GET-only and still gated byrequireManagementAuth.route-guard-version-get-exemption.test.ts, as that test asks for.request-timeline-mcp-audit,route-guard-version-get-exemption,mcp-audit-caller-key43/43 pass; eslint (with the frozen suppressions) clean on touched files;typecheck:coreandcheck:open-sse-typecheckshow only the inherited base errors (cliproxyAccountHealth.ts,auggie.ts); file-size OK.