Security follow-ups from the per-PR review (non-blocking MEDIUMs): - Eager _get_token() at make_app build time so a missing AGENT_TEAM_API_TOKEN fails fast instead of serving requests first (matches the docstring contract). - Disable /docs, /redoc, /openapi.json (no auth dependency in FastAPI) — the API is VPN-only/127.0.0.1 and should not expose its schema unauthenticated. - Scrub raw exception text and subprocess stderr from 500 response bodies; log server-side instead (avoid internal-path/state disclosure). - Bound /orchestrator/invoke concurrency with a semaphore (429 over the cap) so an authenticated caller cannot exhaust the box via many 600s subprocesses. Also pin fastapi/uvicorn in requirements.txt (WS1 dep). With fastapi now installed in CI, the previously skip-guarded TestClient tests run for real; the importorskip guard stays as a no-op safety net. Tests: 23 pass (adds docs-disabled + concurrency-429 cases).
12 lines
407 B
Text
12 lines
407 B
Text
langgraph==1.2.6
|
|
# Durable SQLite checkpointer for the R720 agent-team Plane-2 pipeline (design D9).
|
|
langgraph-checkpoint-sqlite==3.1.0
|
|
langchain-anthropic==1.4.6
|
|
langchain-openai==1.3.2
|
|
langchain-google-genai==4.2.5
|
|
langchain-community==0.4.2
|
|
composio-langgraph==0.15.0
|
|
python-dotenv==1.2.2
|
|
# WS1 agent-team HTTP API (agent_team/api.py): FastAPI app + uvicorn ASGI server.
|
|
fastapi==0.136.1
|
|
uvicorn==0.46.0
|