pub struct Proxy {
pub auth_manager: Arc<RwLock<Option<Arc<AuthManager>>>>,
/* private fields */
}Expand description
The main proxy engine that manages the connection and authentication state.
Fields§
§auth_manager: Arc<RwLock<Option<Arc<AuthManager>>>>Shared authentication manager (lazy-loaded).
Implementations§
Source§impl Proxy
impl Proxy
Sourcepub fn new(
remote_url: &str,
user_id: &str,
oidc_config: OidcConfig,
vault: Vault,
protocol_version: &str,
auth_scheme: AuthScheme,
) -> Arc<Self> ⓘ
pub fn new( remote_url: &str, user_id: &str, oidc_config: OidcConfig, vault: Vault, protocol_version: &str, auth_scheme: AuthScheme, ) -> Arc<Self> ⓘ
Creates a new Proxy instance.
Sourcepub async fn handle_request(
&self,
payload: Value,
out: &Sender<String>,
) -> Result<()>
pub async fn handle_request( &self, payload: Value, out: &Sender<String>, ) -> Result<()>
Primary entry point for the stdio -> HTTP bridge.
Sends one JSON-RPC message to the remote server (attaching DPoP-bound
tokens and managing the Airlock) and writes every message the server
returns for it to out: a JSON body, or each event of a
text/event-stream response (MCP Streamable HTTP).
Sourcepub async fn call(&self, payload: Value) -> Result<Option<Value>>
pub async fn call(&self, payload: Value) -> Result<Option<Value>>
Sends one request and returns the server’s response to it.
Other messages the server streams back (e.g. progress notifications) are
dropped. Returns Ok(None) when nothing comes back, as for notifications.
Sourcepub async fn wait_for_legacy_session(&self)
pub async fn wait_for_legacy_session(&self)
Resolves once a POST to the remote server has succeeded (so the session Resolves once a legacy (2025-11-25 or earlier) session is established. Modern servers have no standalone GET stream, so for them this never resolves.
Sourcepub async fn trigger_reauth(
&self,
observed_gen: u64,
metadata_url: Option<&str>,
scopes: Option<Vec<String>>,
reason: ReauthReason,
) -> Result<()>
pub async fn trigger_reauth( &self, observed_gen: u64, metadata_url: Option<&str>, scopes: Option<Vec<String>>, reason: ReauthReason, ) -> Result<()>
Runs a re-authentication, or reuses the outcome of one that happened while waiting.
observed_gen is the credential generation used by the request that was
rejected. Requests rejected together share a single attempt: once one of
them re-authenticates, the others reuse its result (or its failure).
For ReauthReason::Unauthorized a silent refresh is tried before the
browser login. A token from a browser login that is rejected again right
away is reported as an authentication loop instead of opening yet
another login.
Sourcepub async fn listen_sse(
&self,
sse_url: &str,
stdout_tx: Sender<String>,
) -> Result<()>
pub async fn listen_sse( &self, sse_url: &str, stdout_tx: Sender<String>, ) -> Result<()>
Keeps the standalone GET event stream of a legacy server open,
reconnecting (with Last-Event-ID) and re-authenticating as needed,
and writes its messages to stdout_tx. Returns when the server
doesn’t offer the stream (405).