mirror of
https://github.com/samvallad33/vestige.git
synced 2026-07-26 23:51:02 +02:00
Completes the launch-polish lane Codex started (rate-limited mid-wiring): Trust boundary (was: dashboard API/WS unauthenticated): - Token middleware on all /api/* and /ws, reusing the persisted Vestige auth token with constant-time compare (subtle); Sec-Fetch-Site + exact-Origin checks - Token delivered via URL fragment (never sent to server / logged), installed into localStorage on app load — WIRES installDashboardTokenFromLocation() into the root +layout onMount BEFORE websocket.connect()/any fetch (the missing piece that otherwise 401s the dashboard against its own API) Fail-closed memory governance: - Dashboard delete/suppress pre-gate through Memory PRs in Risk-Gated/Paranoid (Fast still mutates directly); decision-before-mutation; replay -> 409 - Duplicate pending-PR reuse; PR content redacted to preview+hash at the API layer Black Box / receipts: - Live refresh of run list + receipts on real TraceEvents (trace-before-receipt race handled via retry); synthetic events excluded from proof counters Fixes on top of Codex's work: - websocket.ts: source 'synthetic' -> `as const` (TS error, blocked pnpm check) - memories: scoped a11y-ignore on the non-interactive review-notice - collapsed sanitize_memory_pr_json (clippy collapsible_if); rustfmt the 7 touched Rust files Gates: pnpm check 0/0 (905 files); vestige-mcp 453 tests; core trace/review/ receipt 67 tests; clippy -D warnings clean. All green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
Vestige MCP Server
Local cognitive memory for MCP-compatible AI agents.
This crate provides the vestige-mcp stdio MCP server plus the vestige CLI.
The cognitive engine lives in vestige-core; this crate owns protocol handling,
tool dispatch, optional dashboard serving, backups, restore, update, and
portable import/export commands.
Install
For normal users, prefer the release package:
npm install -g vestige-mcp-server
For local development:
cargo build --release -p vestige-mcp
Register With An MCP Client
Use the command vestige-mcp in any stdio MCP client:
{
"mcpServers": {
"vestige": {
"command": "vestige-mcp"
}
}
}
Examples:
claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp
Transports
- Default: JSON-RPC 2.0 over stdio.
- Optional: MCP-over-HTTP on
/mcp, enabled only with--http,--http-port, orVESTIGE_HTTP_ENABLED=1. - Dashboard:
vestige dashboardorVESTIGE_DASHBOARD_ENABLED=1.
HTTP and dashboard bearer tokens are generated locally; see
docs/CONFIGURATION.md.
Current Tool Surface
The server exposes the current unified MCP tools from
src/server.rs, including:
session_contextsearch,smart_ingest,memory,codebase,intentiondeep_reference,cross_reference,contradictionsdream,explore_connections,predictmemory_health,memory_graph,composed_graph,system_statusimportance_score,find_duplicatesconsolidate,memory_timeline,memory_changelogbackup,export,restore,gc,suppress
See the root README.md and
docs/AGENT-MEMORY-PROTOCOL.md for
agent instructions.
License
AGPL-3.0-only