mirror of
https://github.com/hansjone/dsh-search-mcp.git
synced 2026-10-12 00:30:46 +08:00
Fallback to env proxy when dsh-http-proxy cannot resolve on link installs.
Use process HTTP_PROXY/HTTPS_PROXY and undici global dispatcher when the policy module import fails, so symlinked desktop plugins still egress through the corporate proxy. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
26a8c2ecee
commit
4b4a1e4460
5 changed files with 197 additions and 35 deletions
|
|
@ -5,16 +5,17 @@
|
|||
* link:/Desktop profiles can resolve it from the host graph without a local
|
||||
* `node_modules` copy of the legacy monolith SDK.
|
||||
*
|
||||
* HTTP egress follows web-fetch-http:
|
||||
* - When DSH installed a process proxy policy (`proxyRouteFor` → proxied),
|
||||
* reuse that dispatcher so HTTPS_PROXY / system proxy is inherited.
|
||||
* - Otherwise keep the DNS-pinned undici Agent (SSRF-safe direct dial).
|
||||
* HTTP egress:
|
||||
* 1. DSH policy (`proxyRouteFor`) when `@deepseek-ai/dsh-http-proxy` resolves.
|
||||
* 2. Else env + undici global dispatcher (DSH boot installs proxy from HTTP_PROXY).
|
||||
* 3. Else DNS-pinned direct dial (SSRF-safe).
|
||||
*/
|
||||
import { Client, StreamableHTTPClientTransport } from '@modelcontextprotocol/client';
|
||||
import { StdioClientTransport } from '@modelcontextprotocol/client/stdio';
|
||||
import { WebError } from '@deepseek-ai/dsh-web';
|
||||
import { Agent, fetch as undiciFetch } from 'undici';
|
||||
import { clampSearchResults } from './catalog.js';
|
||||
import { resolveEgressRoute } from './proxy-env.js';
|
||||
import {
|
||||
isNonPublicIpLiteral,
|
||||
parseHttpEndpoint,
|
||||
|
|
@ -32,7 +33,7 @@ export async function callMcpSearch(server, key, args, signal) {
|
|||
|
||||
let runtime;
|
||||
const client = new Client(
|
||||
{ name: 'dsh-search-mcp', version: '0.2.40' },
|
||||
{ name: 'dsh-search-mcp', version: '0.2.41' },
|
||||
{ capabilities: {}, versionNegotiation: { mode: 'auto' } },
|
||||
);
|
||||
try {
|
||||
|
|
@ -78,21 +79,7 @@ export async function callMcpSearch(server, key, args, signal) {
|
|||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Ask DSH's process-wide proxy policy how to send this URL.
|
||||
* Soft-import so missing peer does not kill plugin boot.
|
||||
*/
|
||||
async function resolveProxyRoute(url) {
|
||||
try {
|
||||
const mod = await import('@deepseek-ai/dsh-http-proxy');
|
||||
if (typeof mod.proxyRouteFor !== 'function') return { proxied: false };
|
||||
return mod.proxyRouteFor(url);
|
||||
} catch {
|
||||
return { proxied: false };
|
||||
}
|
||||
}
|
||||
|
||||
/** Build streamable-http transport: inherit proxy when installed, else DNS-pin. */
|
||||
/** Build streamable-http transport: proxy when policy/env says so, else DNS-pin. */
|
||||
async function httpRuntime(server, key, signal) {
|
||||
const parsed = parseHttpEndpoint(server.url);
|
||||
const url = new URL(parsed.url);
|
||||
|
|
@ -103,11 +90,9 @@ async function httpRuntime(server, key, signal) {
|
|||
else if (server.authStyle === 'header') headers[server.authParam] = value;
|
||||
}
|
||||
|
||||
// Proxied hops must not pin local DNS — that would dial the origin directly
|
||||
// and bypass the proxy (same rule as web-fetch-http).
|
||||
const route = await resolveProxyRoute(url);
|
||||
if (route.proxied && !isNonPublicIpLiteral(url.hostname)) {
|
||||
return buildTransport(url, headers, signal, route.dispatcher, async () => {});
|
||||
const route = await resolveEgressRoute(url, isNonPublicIpLiteral);
|
||||
if (route.proxied) {
|
||||
return buildTransport(url, headers, signal, route.dispatcher, route.close ?? (async () => {}));
|
||||
}
|
||||
|
||||
const validated = await validateHttpEndpoint(server.url, { signal });
|
||||
|
|
@ -126,12 +111,13 @@ function buildTransport(url, headers, signal, dispatcher, close) {
|
|||
if (requestUrl.origin !== expectedOrigin) {
|
||||
throw new Error('search-mcp URL policy: request origin changed after validation');
|
||||
}
|
||||
return undiciFetch(input, {
|
||||
const fetchOptions = {
|
||||
...init,
|
||||
dispatcher,
|
||||
redirect: 'error',
|
||||
...(signal !== undefined ? { signal: combineSignals(signal, init.signal) } : {}),
|
||||
});
|
||||
};
|
||||
if (dispatcher !== undefined) fetchOptions.dispatcher = dispatcher;
|
||||
return undiciFetch(input, fetchOptions);
|
||||
};
|
||||
|
||||
return {
|
||||
|
|
|
|||
108
lib/proxy-env.js
Normal file
108
lib/proxy-env.js
Normal file
|
|
@ -0,0 +1,108 @@
|
|||
/**
|
||||
* Proxy resolution for search-mcp HTTP egress.
|
||||
*
|
||||
* Primary: DSH's installed policy (`proxyRouteFor`) when the module resolves.
|
||||
* Fallback: process env + undici global dispatcher — covers link: installs where
|
||||
* `@deepseek-ai/dsh-http-proxy` is not reachable from the plugin source tree
|
||||
* even though DSH boot already installed proxy from the same env vars.
|
||||
*/
|
||||
|
||||
/** First non-empty proxy URL from standard env names. */
|
||||
export function readProxyEnv() {
|
||||
for (const name of [
|
||||
'HTTPS_PROXY', 'https_proxy',
|
||||
'HTTP_PROXY', 'http_proxy',
|
||||
'ALL_PROXY', 'all_proxy',
|
||||
]) {
|
||||
const value = process.env[name];
|
||||
if (typeof value === 'string' && value.trim().length > 0) return value.trim();
|
||||
}
|
||||
return undefined;
|
||||
}
|
||||
|
||||
/** Effective NO_PROXY list (may include CIDR entries we do not interpret). */
|
||||
export function readNoProxyEnv() {
|
||||
return (process.env.NO_PROXY ?? process.env.no_proxy ?? '').trim();
|
||||
}
|
||||
|
||||
/**
|
||||
* Suffix / host bypass — same rules as dsh-http-proxy (no CIDR matching).
|
||||
* @param {URL} url
|
||||
* @returns {boolean}
|
||||
*/
|
||||
export function bypassesEnvNoProxy(url) {
|
||||
const noProxy = readNoProxyEnv();
|
||||
if (noProxy.length === 0) return false;
|
||||
const host = url.hostname.replace(/^\[|\]$/g, '').replace(/\.$/, '').toLowerCase();
|
||||
const port = url.port !== '' ? url.port : url.protocol === 'https:' ? '443' : '80';
|
||||
for (const raw of noProxy.split(/[,\s]+/)) {
|
||||
const entry = raw.trim().toLowerCase();
|
||||
if (entry.length === 0) continue;
|
||||
if (entry === '*') return true;
|
||||
const colon = entry.lastIndexOf(':');
|
||||
let candidate = entry;
|
||||
let entryPort;
|
||||
if (colon > 0 && /^\d+$/.test(entry.slice(colon + 1))) {
|
||||
entryPort = entry.slice(colon + 1);
|
||||
candidate = entry.slice(0, colon);
|
||||
}
|
||||
if (entryPort !== undefined && entryPort !== port) continue;
|
||||
candidate = candidate.replace(/^\*?\./, '').replace(/\.$/, '');
|
||||
if (candidate.length === 0) continue;
|
||||
if (host === candidate || host.endsWith(`.${candidate}`)) return true;
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether this URL should use a proxy based on ambient env (fallback path).
|
||||
* @param {URL} url
|
||||
* @param {(host: string) => boolean} isNonPublicIpLiteral
|
||||
*/
|
||||
export function shouldUseProcessProxy(url, isNonPublicIpLiteral) {
|
||||
if (isNonPublicIpLiteral(url.hostname)) return false;
|
||||
if (readProxyEnv() === undefined) return false;
|
||||
return !bypassesEnvNoProxy(url);
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve egress: DSH policy module first, then env/global dispatcher fallback.
|
||||
* @param {URL} url
|
||||
* @param {(host: string) => boolean} isNonPublicIpLiteral
|
||||
* @returns {Promise<{ proxied: boolean, dispatcher?: import('undici').Dispatcher, close?: () => Promise<void> | void }>}
|
||||
*/
|
||||
export async function resolveEgressRoute(url, isNonPublicIpLiteral) {
|
||||
if (isNonPublicIpLiteral(url.hostname)) {
|
||||
return { proxied: false };
|
||||
}
|
||||
|
||||
try {
|
||||
const mod = await import('@deepseek-ai/dsh-http-proxy');
|
||||
if (typeof mod.proxyRouteFor === 'function') {
|
||||
const route = mod.proxyRouteFor(url);
|
||||
if (route.proxied && route.dispatcher) {
|
||||
return { proxied: true, dispatcher: route.dispatcher, close: async () => {} };
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
// link: source trees often cannot resolve this peer from D:\code\gpt\...
|
||||
}
|
||||
|
||||
if (!shouldUseProcessProxy(url, isNonPublicIpLiteral)) {
|
||||
return { proxied: false };
|
||||
}
|
||||
|
||||
const { ProxyAgent, getGlobalDispatcher } = await import('undici');
|
||||
// Prefer the dispatcher DSH installed at boot from the same env vars.
|
||||
try {
|
||||
const global = getGlobalDispatcher();
|
||||
if (global) {
|
||||
return { proxied: true, dispatcher: global, close: async () => {} };
|
||||
}
|
||||
} catch { /* undici unavailable */ }
|
||||
|
||||
const proxyUrl = readProxyEnv();
|
||||
if (proxyUrl === undefined) return { proxied: false };
|
||||
const agent = new ProxyAgent(proxyUrl);
|
||||
return { proxied: true, dispatcher: agent, close: () => agent.close() };
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue