Skip to content

Add theme setting management tools - #10

Merged
ruibaby merged 6 commits into
mainfrom
feat/theme-setting-tools
Sep 2, 2026
Merged

ruibaby merged 6 commits into
mainfrom
feat/theme-setting-tools

Conversation

@ruibaby

@ruibaby ruibaby commented Sep 1, 2026 •

Copy link
Copy Markdown
Member

What

  • Add tools to list, read, and update active-theme setting groups.
  • Add tools to recursively list and safely read active-theme HTML templates.
  • Apply version-checked JSON Merge Patch updates and accept ConfigMap version 0.
  • Preserve exact numeric tool arguments and add the localized Theme category.

Security

  • Reuse the MCP authorization boundary and tool allowlists.
  • Require the active theme name and expected ConfigMap version before writes.
  • Restrict template reads to the theme templates directory, reject traversal and symlink escapes, and enforce file-count and size limits.
  • Treat theme-provided metadata, FormKit schemas, stored values, and template source as untrusted data.

Validation

  • ./gradlew check --no-daemon --console=plain
  • All backend tests and 35 UI unit tests pass.

Closes #9

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-02T07:24:01.676359Z 53bef6f New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

# Conflicts:
#	src/test/java/run/halo/mcpserver/tools/BuiltInToolsTest.java

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6f2733d3fd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/main/java/run/halo/mcpserver/tools/ToolSupport.java Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4fc9a77262

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/main/java/run/halo/mcpserver/tools/ToolSupport.java Outdated
Updates the THEME category display label from “主题设置” to “主题” in `ui/src/utils/tool.ts`, and adjusts the corresponding unit test expectation to keep behavior and tests aligned.
@ruibaby
ruibaby merged commit a30ceab into main Sep 2, 2026
1 check passed
@ruibaby
ruibaby deleted the feat/theme-setting-tools branch September 2, 2026 07:20

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 53bef6fa9c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

static final String GET_TEMPLATE = "halo_get_theme_template";
static final int MAX_TEMPLATE_BYTES = 256 * 1024;
private static final int MAX_TEMPLATE_COUNT = 2_000;
private static final JsonMapper JSON_MAPPER = JsonMapper.shared();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve precision when parsing stored setting values

When a stored group contains a high-precision decimal such as 1.0000000000000000000001, this shared mapper parses it as a binary floating-point node because it does not enable USE_BIG_DECIMAL_FOR_FLOATS. Consequently, getGroup can return a rounded value, and updating an unrelated field serializes that rounded value back into the ConfigMap, corrupting the existing setting. Configure this mapper for decimal preservation as well, not only the protocol mapper.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

请教一下,该MCP如何能否让Agent修改主题的配置

1 participant