Commit Graph
13 Commits
Author SHA1 Message Date
Tom Flux 90239baada fix service group 2026-06-23 21:29:12 +01:00
Tom Flux a0c54bbc9f mcp group to uv 2026-06-23 21:27:35 +01:00
Tom FluxandClaude Opus 4.8 9efc4adcd4 Fix bulk-pantry-add crash on null unit (found in live MCP testing)
End-to-end testing (MCP client -> FastMCP -> Django) surfaced a 500:
adding an item with an explicit `unit: null` (as add_to_pantry sends
for items without a unit) hit a NOT NULL violation, because
`item_data.get("unit", "items")` returns None when the key is present.

- views.bulk_pantry_add: `item_data.get("unit") or "items"` — tolerate
  null/empty unit.
- mcp_server add_to_pantry: omit quantity/unit from the payload when
  unset, so the API applies its own defaults.
- test: bulk-add with unit/quantity = null returns 201 (25 pass).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 21:24:09 +01:00
Tom FluxandClaude Opus 4.8 44de784f70 Phase 3b: FastMCP "ai service" for claude.ai cooking mode
A standalone MCP server (no Django import) exposing 7 tools over
Streamable HTTP, backed by the Django REST API via the caine token.

- mcp_server/: client.py (httpx wrapper over /api/), server.py (the
  tools + FastMCP app + main), __main__.py, tests.py.
- Tools: get_pantry, set_item_state, add_to_pantry, what_can_i_cook,
  get_recipes, log_cook (suggests, never mutates), create_meta_recipe
  (brainstorm -> commit). Each description says when to call it.
- deploy/food-mcp.service: systemd unit (own process, runs .venv python
  -m mcp_server, loads /var/lib/food/.env).
- deploy/food.tomflux.xyz.nginx: current config + an authless
  /mcp/<secret>/ location proxying to 127.0.0.1:8765 (the URL secret is
  the credential; SSE-friendly buffering/timeout).
- pyproject: [dependency-groups] mcp = [fastmcp, httpx]; deploy with
  `uv sync --group mcp`.

Verified: 7 tools register on fastmcp 3.x, run() accepts transport/
host/port/path, 6 FoodClient unit tests pass (httpx MockTransport).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 21:16:30 +01:00
Tom FluxandClaude Opus 4.8 7255c9302c Phase 3a: close the Django API gaps for the MCP server
Backend prerequisites for the FastMCP service (mcp.md §6) — no model
changes, no migration.

- log_cook: accepts `rating`, validates via full_clean (enforces the
  exactly-one-recipe rule), and returns `used_ingredients` as a
  suggestion set instead of mutating the pantry. Auto-deduct path and
  _deduct_ingredient removed — pantry state changes only via set-state
  after the user confirms.
- New POST /api/pantry/set-state/ — set in/low/out by ingredient name
  (alias-aware), optional location; registered before the router so the
  pantry detail route doesn't capture "set-state" as a pk.
- what_can_i_cook: presence-based (exclude 'out', tolerate null
  quantity) so the API matcher agrees with the web one.
- bulk-pantry-add: restocks an existing ingredient+location row to 'in'
  instead of duplicating; quantity is an optional int.

Tests cover all four + that pantry `state` is serialized (24 pass).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 21:07:18 +01:00
Tom FluxandClaude Opus 4.8 50dcaca1e8 Add MCP server spec; mark phases 1-2 done in plan
mcp.md specs the Phase 3 FastMCP "ai service": tools, the Django API
gaps to close, authless-connector + URL-secret auth, and the
brainstorm->commit path for meta-recipes and cook logs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 21:02:26 +01:00
Tom FluxandClaude Opus 4.8 ba1f792826 auth: trust nginx HTTPS proxy for CSRF (SECURE_PROXY_SSL_HEADER + CSRF_TRUSTED_ORIGINS)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 20:45:46 +01:00
Tom FluxandClaude Opus 4.8 6bad2a2ad1 Phase 2: session auth for the web UI
Require login for /app/, with a long sliding session so you log in
once per device and effectively stay in.

- AppLoginRequiredMiddleware gates only /app/; /api/ keeps DRF token
  auth and /admin/ keeps its own login (a blanket LoginRequired would
  break token requests, whose user isn't resolved until the view runs).
- Login page (styled to the dark palette) via django.contrib.auth.urls;
  logout control in the nav.
- Session: ~1 year cookie, sliding (saved every request), survives
  browser close.
- Dropped every @csrf_exempt now that a real session + CSRF token are
  in place (HTMX already sends X-CSRFToken).
- SECRET_KEY and DEBUG now read from the environment (prod-safe
  defaults); systemd loads an optional /var/lib/food/.env.
- Tests authenticate, plus new coverage: /app/ redirects when logged
  out, login grants access, /api/ is not caught by the app gate.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 20:37:48 +01:00
Tom Flux 073ab85f30 move to uv 2026-06-23 20:16:23 +01:00
Tom FluxandClaude Opus 4.8 f42238344b Migrate dependency management to uv
Replace requirements.txt with pyproject.toml (direct deps only; uv
resolves the rest into uv.lock). Point the systemd unit at the
uv-managed .venv, and gitignore it.

Run `uv lock` to generate the lockfile and commit it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 19:55:42 +01:00
Tom FluxandClaude Opus 4.8 ce61a0a86f Phase 1: mobile-first pantry redesign with In/Low/Out state
Track presence (In/Low/Out) as the primary signal instead of exact
quantities; quantity becomes an optional integer, unit optional too
(migration 0003 backfills state from quantity: 0 -> out, else in).

- Pantry rebuilt as a phone-first card list: colored state rail,
  segmented In/Low/Out switch (server-driven HTMX), greyed out-items,
  live summary counts.
- Fast add: bottom add bar with type-ahead autocomplete, location
  picker, and quick-add chips for things you've run out of.
- Per-item menu (move / set expiry / delete); expiry is now an
  optional quiet pill, never required.
- New endpoints: pantry search + set-state; dropped the old
  edit-expiry/cancel flow and its partial.
- Recipes matcher made presence-based (have-it beats have-enough);
  state added to admin. Tests cover state, add/restock, search,
  presence matching, and page rendering.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 19:55:16 +01:00
Tom FluxandClaude Opus 4.8 25a09b08fc Add planning docs: research, requirements, redesign plan
Research of current state, requirements for the web-first pivot
(pantry polish -> auth -> MCP), and the phased implementation plan.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 19:55:16 +01:00
Tom Flux 173e74b4a9 Simplify from claude 2026-06-22 22:50:48 +01:00