Files
OpenViking/pyproject.toml
T
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00

302 lines
7.3 KiB
TOML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
[build-system]
requires = [
"setuptools>=61.0",
"setuptools-scm>=8.0",
"cmake>=3.15",
"maturin>=1.0,<2.0",
"wheel",
]
build-backend = "setuptools.build_meta"
[project]
name = "openviking"
dynamic = ["version"]
description = "An Agent-native context database"
readme = "README.md"
requires-python = ">=3.10"
authors = [
{name = "ByteDance", email = "noreply@bytedance.com"}
]
license = "AGPL-3.0"
classifiers = [
"Development Status :: 3 - Alpha",
"Intended Audience :: Developers",
"Topic :: Scientific/Engineering :: Artificial Intelligence",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.14",
]
dependencies = [
"openviking-sdk>=0.1.1",
"pydantic>=2.0.0",
"typing-extensions>=4.5.0",
"pyyaml>=6.0",
"httpx>=0.25.0",
"pdfplumber>=0.10.0",
"scrapy>=2.11.0",
"trafilatura>=1.12.0",
"feedparser>=6.0.0",
"defusedxml>=0.7.1",
"openai>=1.0.0",
"requests>=2.33.0",
"charset-normalizer>=3.4,<4",
"python-docx>=1.0.0",
"olefile>=0.47",
"xlrd>=2.0.1",
"python-pptx>=1.0.0",
"openpyxl>=3.0.0",
"ebooklib>=0.18.0",
"json-repair>=0.25.0",
"apscheduler>=3.11.0",
"volcengine>=1.0.216",
"volcengine-python-sdk[ark]>=5.0.3",
"fastapi>=0.128.0",
"uvicorn>=0.39.0",
"xxhash>=3.0.0",
"jinja2>=3.1.6",
"tabulate>=0.9.0",
"urllib3>=2.7.0",
"protobuf>=6.33.5",
"pdfminer-six>=20251230",
"typer>=0.12.0",
"litellm>=1.83.7,<1.91.2",
"python-multipart>=0.0.31",
"tree-sitter>=0.23.0",
"tree-sitter-python>=0.23.0",
"tree-sitter-javascript>=0.23.0",
"tree-sitter-typescript>=0.23.0",
"tree-sitter-java>=0.23.0",
"tree-sitter-cpp>=0.23.0",
"tree-sitter-rust>=0.23.0",
"tree-sitter-go>=0.23.0",
"tree-sitter-c-sharp>=0.23.0",
"tree-sitter-php>=0.23.0",
"tree-sitter-lua>=0.1.0",
# OpenTelemetry
"opentelemetry-api>=1.14",
"opentelemetry-sdk>=1.14",
"opentelemetry-exporter-otlp-proto-grpc>=1.14",
"opentelemetry-exporter-otlp-proto-http>=1.14",
"opentelemetry-instrumentation-asyncio>=0.61b0",
"loguru>=0.7.3",
"cryptography>=48.0.1",
"argon2-cffi>=23.0.0",
"lark-oapi>=1.5.3",
"mcp>=1.27,<2",
"pathspec>=1.1.1",
"grep-ast>=0.9.0",
"tree-sitter-language-pack>=1.12,<2.0",
]
[project.optional-dependencies]
test = [
"pytest>=7.0.0",
"pytest-asyncio>=0.21.0",
"pytest-xdist>=3.5.0",
"boto3>=1.42.44",
"pytest-cov>=4.0.0",
"ragas>=0.1.0",
"datasets>=2.0.0",
"pandas>=2.0.0",
"diff-match-patch>=20200713",
"hvac>=2.0.0",
]
auth = [
"python-jose[cryptography]>=3.3.0",
"httpx>=0.25.0",
"python-ldap>=3.4.0",
]
opengauss = [
"psycopg2-binary>=2.9",
]
dev = [
"mypy>=1.0.0",
"ruff>=0.1.0",
"setuptools_scm>=10.0.0",
]
doc = [
"sphinx>=7.0.0",
"sphinx-rtd-theme>=1.3.0",
"myst-parser>=2.0.0",
]
eval = [
"ragas>=0.1.0",
"datasets>=2.0.0",
"pandas>=2.0.0",
]
gemini = [
"google-genai>=1.0.0",
]
gemini-async = [
"google-genai>=1.0.0",
"anyio>=4.0.0",
]
ocr = [
"pytesseract>=0.3.10",
]
build = [
"setuptools>=61.0",
"setuptools-scm>=8.0",
"cmake>=3.15",
"wheel",
"build",
]
# vikingbot - all features included
bot = [
"pydantic-settings>=2.0.0",
"websockets>=12.0",
"websocket-client>=1.6.0",
"httpx[socks]>=0.25.0",
"readability-lxml>=0.8.0",
"rich>=13.0.0",
"croniter>=2.0.0",
"socksio>=1.0.0",
"python-socketio>=5.16.2",
"python-engineio>=4.13.2",
"msgpack>=1.0.8",
"python-socks[asyncio]>=2.4.0",
"prompt-toolkit>=3.0.0",
"pygments>=2.16.0",
"html2text>=2020.1.16",
"beautifulsoup4>=4.12.0",
"ddgs>=9.0.0",
"tavily-python>=0.5.0",
"gradio>=6.6.0",
"py-machineid>=1.0.0",
"mcp>=1,<2",
# All optional features included by default
"langfuse>=3.0.0",
"python-telegram-bot[socks]>=21.0",
"lark-oapi>=1.0.0",
"dingtalk-stream>=0.4.0",
"slack-sdk>=3.26.0",
"qq-botpy>=1.0.0",
"opensandbox>=0.1.0",
"opensandbox-server>=0.1.0",
"agent-sandbox>=0.0.23",
"fusepy>=3.0.1",
"opencode-ai>=0.1.0a0",
# Auth dependencies
"python-jose[cryptography]>=3.3.0",
]
benchmark = [
"langchain>=1.0.0",
"langchain-core>=1.0.0",
"langchain-openai>=1.0.0",
"tiktoken>=0.5.0",
"datasets>=2.0.0",
"pandas>=2.0.0",
]
local-embed = [
"llama-cpp-python>=0.3.0",
]
[project.urls]
Homepage = "https://github.com/volcengine/openviking"
Documentation = "https://openviking.ai"
Repository = "https://github.com/volcengine/openviking"
Issues = "https://github.com/volcengine/openviking/issues"
[project.scripts]
ov = "openviking_cli.rust_cli:main" # Rust CLI 入口(极简包装器)
openviking = "openviking_cli.rust_cli:main" # Rust CLI 入口(放弃 python CLI)
openviking-server = "openviking_cli.server_bootstrap:main" # also: `openviking-server ingest ...`
vikingbot = "vikingbot.cli.commands:app"
[tool.setuptools_scm]
write_to = "openviking/_version.py"
local_scheme = "no-local-version"
tag_regex = "^v(?P<version>[0-9]+(?:\\.[0-9]+)*)$"
git_describe_command = "git describe --dirty --tags --long --match v[0-9]*"
[tool.setuptools.packages.find]
where = [".", "bot"]
include = ["openviking*", "vikingbot*"]
exclude = ["tests*", "docs*", "examples*"]
[tool.setuptools.package-data]
openviking = [
"prompts/templates/**/*.yaml",
"server/static/**/*",
"web_studio/dist/**/*",
"lib/ragfs_python*.so",
"lib/ragfs_python*.pyd",
"bin/ov",
"bin/ov.exe",
"storage/vectordb/engine/*.abi3.so",
"storage/vectordb/engine/*.pyd",
]
vikingbot = [
"**/*.mjs",
"skills/**/*.md",
"skills/**/*.sh",
"workspace/**/*",
"bridge/**/*",
]
[tool.mypy]
python_version = "3.10"
warn_return_any = false
warn_unused_configs = true
disallow_untyped_defs = false
disallow_incomplete_defs = false
check_untyped_defs = true
no_implicit_optional = false
warn_redundant_casts = true
warn_unused_ignores = true
ignore_missing_imports = true
[tool.pytest.ini_options]
testpaths = ["tests"]
python_files = ["test_*.py"]
python_classes = ["Test*"]
python_functions = ["test_*"]
asyncio_mode = "auto"
markers = [
"integration: tests that require external services or real model configuration",
]
addopts = "-v --cov=openviking --cov-report=term-missing"
[tool.ruff]
line-length = 100
exclude = ["third_party"]
target-version = "py310"
[tool.ruff.lint]
select = [
"E", # pycodestyle errors
"W", # pycodestyle warnings
"F", # pyflakes
"I", # isort
"C", # flake8-comprehensions
"B", # flake8-bugbear
]
ignore = [
"E501", # line too long (handled by black)
"B008", # do not perform function calls in argument defaults
"C901", # too complex
"B006", # Do not use mutable data structures for argument defaults
"B904", # Within an `except` clause, raise exceptions with `raise ... from err`
"E741", # Ambiguous variable name
"E722", # Do not use bare `except`
"B027", # empty method in an abstract base class
]
[tool.ruff.lint.per-file-ignores]
"__init__.py" = ["F401"] # Allow unused imports in __init__.py
[tool.ruff.format]
quote-style = "double"
indent-style = "space"
skip-magic-trailing-comma = false
line-ending = "auto"
[dependency-groups]
dev = [
"pytest>=9.0.2",
]