Under gateway.multiplex_profiles, os.environ holds the DEFAULT profile's .env; a
secondary profile's values exist only in the per-turn secret scope. Every reader
below still read os.environ/os.getenv at call time, so a secondary profile's turn
silently used the default profile's value.
Credentials (F6): FIRECRAWL_API_KEY (read_file hosted OCR), OPENVIKING_API_KEY,
mem0-OSS OPENAI_API_KEY, MODAL_TOKEN_ID/SECRET and BROWSER_USE_API_KEY presence
gates, and the xAI video plugin's os.getenv("XAI_API_KEY") fallback AFTER the
scoped resolver had already missed — the exact fallback-after-miss shape
gateway/AGENTS.md forbids. Deleted, not re-scoped: the resolver is the scope.
Identity / tenant (F7): MEM0_USER_ID/AGENT_ID/HOST/MODE, SUPERMEMORY_CONTAINER_TAG,
RETAINDB_PROJECT, OPENVIKING_ACCOUNT/USER/AGENT (and the whole layered() env
read), HINDSIGHT_BANK_ID/MODE/retain shaping, HERMES_HONCHO_HOST. A raw read
put a secondary profile's memories into the default profile's account/bank/
project/tenant and recalled them back into the default's turns. Each now uses
get_secret with the provider's own per-profile default on a miss.
Endpoints (F8): OPENAI_BASE_URL (aux custom runtime + direct-alias expansion),
XAI_BASE_URL/HERMES_XAI_BASE_URL (aux OAuth), NOUS_INFERENCE_BASE_URL (#65941,
both the aux builder and hermes_cli.auth_nous._nous_inference_env_override),
GATEWAY_PROXY_URL (same UnscopedSecretError-only fallback shape as
GATEWAY_PROXY_KEY three lines below), FIRECRAWL_API_URL, BROWSERBASE_BASE_URL,
SUPERMEMORY/RETAINDB/HONCHO/HINDSIGHT URLs. The keys beside them were already
scoped, so a secondary's key was sent to the default profile's proxy or host.
Targets / display (F11): WEIXIN_HOME_CHANNEL (message posted into the default's
chat), HERMES_LANGUAGE, and agent/i18n's process-wide lru_cache of
display.language — now keyed by HERMES_HOME.
Outbound webhooks: hooks.outbound[].secret_env resolved from os.environ while
the gateway registers each profile's targets inside that profile's scope, so a
secondary's deliveries were signed with the default's secret or left unsigned.
Agent-cache eviction: _spawn_release_thread started a bare threading.Thread, so
commit_memory_session -> provider on_session_end ran with an EMPTY context. The
thread now runs copy_context() and, for the unscoped housekeeping sweep, enters
the owning profile's _profile_runtime_scope resolved from the session key
(agent:<profile>:...). The pressure batch does the same per key.
session_search (#82903): agent/inline_tool_executors.py::_session_search
forwarded every schema argument except `profile`, so a gateway agent could
never select a named profile's store. Forwarded; the ownership-scoping design
in #87779/#87847 is a separate design call and is not attempted here.
Live repro (/tmp/mux_audit/fix-tool-memory-reads/repro.py): 28 FAIL on
origin/main -> 0 FAIL with this change; 10 new invariant tests red on base.
Fixes #82903
Fixes #65941
Fixes #99121
Addresses #87779
Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com>
Co-authored-by: Michael Versluis (Berry) <michael@wve.nl>
94 lines
3.7 KiB
Python
94 lines
3.7 KiB
Python
"""Firecrawl cloud browser (``/v2/browser`` only; the web plugin under ``plugins/web/firecrawl/``
|
|
shares ``FIRECRAWL_API_KEY``). Config ``browser.cloud_provider: "firecrawl"`` (explicit only — not
|
|
in the legacy auto-detect walk). Env: ``FIRECRAWL_API_KEY``, ``FIRECRAWL_API_URL`` (default
|
|
https://api.firecrawl.dev), ``FIRECRAWL_BROWSER_TTL`` (default 300 s)."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
import os
|
|
from typing import Any, Dict, Optional
|
|
|
|
from agent.secret_scope import get_secret
|
|
from plugins.browser._common import CloudBrowserProvider
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
_BASE_URL = "https://api.firecrawl.dev"
|
|
|
|
|
|
class FirecrawlBrowserProvider(CloudBrowserProvider):
|
|
"""Firecrawl (https://firecrawl.dev) cloud browser backend."""
|
|
|
|
provider_id = "firecrawl"
|
|
label = "Firecrawl"
|
|
release_method = "delete"
|
|
release_path = "/v2/browser/{session_id}"
|
|
create_label_suffix = " browser"
|
|
setup_tag = "Cloud browser with remote execution"
|
|
setup_env_vars = [
|
|
{"key": "FIRECRAWL_API_KEY", "prompt": "Firecrawl API key", "url": "https://firecrawl.dev"},
|
|
]
|
|
|
|
def _api_url(self) -> str:
|
|
# Per-profile like the key: the scoped key must not be sent to the default profile's endpoint.
|
|
return get_secret("FIRECRAWL_API_URL", "") or _BASE_URL
|
|
|
|
def _get_config_or_none(self) -> Optional[Dict[str, Any]]:
|
|
return {"base_url": self._api_url()} if get_secret("FIRECRAWL_API_KEY") else None
|
|
|
|
def _get_config(self) -> Dict[str, Any]:
|
|
# Never raises: a missing key surfaces from _headers() inside the request try-block, so
|
|
# close_session logs it as an exception (legacy behaviour).
|
|
return {"base_url": self._api_url()}
|
|
|
|
def _headers(self, config: Optional[Dict[str, Any]] = None) -> Dict[str, str]:
|
|
api_key = get_secret("FIRECRAWL_API_KEY")
|
|
if not api_key:
|
|
raise ValueError(
|
|
"FIRECRAWL_API_KEY environment variable is required. "
|
|
"Get your key at https://firecrawl.dev")
|
|
return {"Content-Type": "application/json", "Authorization": f"Bearer {api_key}"}
|
|
|
|
def create_session(self, task_id: str) -> Dict[str, object]:
|
|
try:
|
|
ttl = int(os.environ.get("FIRECRAWL_BROWSER_TTL", "300"))
|
|
except (ValueError, TypeError):
|
|
ttl = 300
|
|
|
|
response = self._post_create(f"{self._api_url()}/v2/browser", self._headers(), {"ttl": ttl})
|
|
self._check_created(response)
|
|
data = response.json()
|
|
session_name = self._session_name(task_id)
|
|
logger.info("Created Firecrawl browser session %s", session_name)
|
|
return {
|
|
"session_name": session_name,
|
|
"bb_session_id": data["id"],
|
|
"cdp_url": data["cdpUrl"],
|
|
"features": {"firecrawl": True},
|
|
}
|
|
|
|
|
|
# ---- BEGIN PLUGIN-COMPAT (revert-scheduled; see COMPAT_MANIFEST.md) ----
|
|
# Names external plugins imported from this module before the Sep 2026 decomposition.
|
|
# Internal code MUST NOT use these (scripts/check_compat_pointers.py fails CI if it does).
|
|
# The whole block is removed by reverting the commit that added it.
|
|
import requests # noqa: F401,E402
|
|
import uuid # noqa: F401,E402
|
|
|
|
|
|
_PLUGIN_COMPAT_LAZY = {
|
|
'BrowserProvider': ('agent.browser_provider', 'BrowserProvider'),
|
|
}
|
|
|
|
|
|
def __getattr__(name): # PEP 562 — lazy so no import cycles
|
|
target = _PLUGIN_COMPAT_LAZY.get(name)
|
|
if target is None:
|
|
raise AttributeError(f"module {__name__!r} has no attribute {name!r}")
|
|
import importlib
|
|
from hermes_cli.plugin_compat import warn_once
|
|
warn_once(__name__, name, *target)
|
|
return getattr(importlib.import_module(target[0]), target[1])
|
|
# ---- END PLUGIN-COMPAT ----
|