Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/golden-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,13 +50,21 @@ jobs:
ref: 881b1006b67afc24d35d17b82cd32d16a5593a44
path: build/client-source
persist-credentials: false
- name: Check out the independent webservices plugin under test
uses: actions/checkout@v7
with:
repository: joomengine/mcp_webservices
ref: 7853f864d70ff8aea43c488bc3a93bd6e5724623
path: build/webservices-source
persist-credentials: false
- name: Install the client dependencies for the remote acceptance scenario
working-directory: build/client-source
run: composer install --no-interaction --prefer-dist --no-progress
- name: Install the component into the JCB golden image and exercise native Joomla
env:
COMPOSE_PROJECT_NAME: mcp-${{ github.run_id }}-${{ github.run_attempt }}
MCP_PLUGIN_SOURCE: ${{ github.workspace }}/build/plugin-source
MCP_WEBSERVICES_SOURCE: ${{ github.workspace }}/build/webservices-source
MCP_CLIENT_SOURCE: ${{ github.workspace }}/build/client-source
run: bash tests/golden-image/run.sh
- name: Preserve redacted installation and execution evidence
Expand Down
10 changes: 10 additions & 0 deletions .github/workflows/integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,13 @@ jobs:
ref: fe387b962dab605191ef18efe4d5cb94821165d9
path: build/plugin-source
persist-credentials: false
- name: Check out the independent webservices plugin under test
uses: actions/checkout@v7
with:
repository: joomengine/mcp_webservices
ref: 7853f864d70ff8aea43c488bc3a93bd6e5724623
path: build/webservices-source
persist-credentials: false
- name: Check out the remote client bridge under test
uses: actions/checkout@v7
with:
Expand All @@ -74,6 +81,7 @@ jobs:
run: |
mkdir -p build/evidence
git -C build/plugin-source rev-parse HEAD > build/evidence/console-plugin-source.txt
git -C build/webservices-source rev-parse HEAD > build/evidence/webservices-plugin-source.txt
git -C build/client-source rev-parse HEAD > build/evidence/client-source.txt
- name: Validate committed runtime files and native manifests
run: |
Expand All @@ -89,6 +97,7 @@ jobs:
MCP_TEST_DB_PASS: disposable-test-password
MCP_TEST_DB_NAME: mcp_fixture
MCP_PLUGIN_SOURCE: ${{ github.workspace }}/build/plugin-source
MCP_WEBSERVICES_SOURCE: ${{ github.workspace }}/build/webservices-source
MCP_CLIENT_SOURCE: ${{ github.workspace }}/build/client-source
run: bash tests/integration/run.sh
- name: Preserve redacted evidence and the tested source ZIPs
Expand All @@ -100,5 +109,6 @@ jobs:
build/evidence/
build/component-source.zip
build/console-plugin-source.zip
build/webservices-plugin-source.zip
if-no-files-found: error
retention-days: 7
278 changes: 44 additions & 234 deletions .github/workflows/release.yml

Large diffs are not rendered by default.

34 changes: 19 additions & 15 deletions .octojpack
Original file line number Diff line number Diff line change
Expand Up @@ -14,36 +14,40 @@
"copyright": "Copyright (C) 2026 Vast Development Method. All rights reserved.",
"copyright_year": "2026",
"license": "GNU General Public License version 3 or later; see LICENSE",
"license_file": "LICENSE",
"license_file": "https://raw.githubusercontent.com/joomengine/mcp_component/main/LICENSE",
"author": "Llewellyn van der Merwe",
"author_email": "joomla@vdm.io",
"author_url": "https://dev.vdm.io/",
"description": "JoomEngine MCP component, webservices routing, and local console server.",
"version_id": "com_joomengine_mcp",
"version": "0.1.1",
"update_servers": "[[[PACKAGE_UPDATE_SERVER]]]",
"changelog_servers": "[[[PACKAGE_CHANGELOG_SERVER]]]"
"update_servers": "https://raw.githubusercontent.com/joomengine/mcp_component/main/joomengine_mcp_update_server.xml",
"changelog_servers": "https://raw.githubusercontent.com/joomengine/mcp_component/main/changelog.xml"
},
"repository": {
"owner": "[[[PACKAGE_OWNER]]]",
"repo": "[[[PACKAGE_REPOSITORY]]]",
"branch": "[[[PACKAGE_BRANCH]]]"
"owner": "joomengine",
"repo": "mcp_package",
"branch": "main"
},
"files": [
{
"owner": "[[[SOURCE_OWNER]]]",
"repo": "[[[SOURCE_REPOSITORY]]]",
"owner": "joomengine",
"repo": "mcp_component",
"id": "com_joomengine_mcp",
"type": "component",
"mode": "[[[COMPONENT_TAG]]]"
"type": "component"
},
{
"owner": "[[[CONSOLE_OWNER]]]",
"repo": "[[[CONSOLE_REPOSITORY]]]",
"owner": "joomengine",
"repo": "mcp_plugin",
"id": "joomengine_mcp",
"type": "plugin",
"group": "console",
"mode": "[[[CONSOLE_TAG]]]"
"group": "console"
},
{
"owner": "joomengine",
"repo": "mcp_webservices",
"id": "joomengine_mcp",
"type": "plugin",
"group": "webservices"
}
],
"languages": [
Expand Down
8 changes: 4 additions & 4 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,14 +31,14 @@ PHP style authority: https://github.com/extension-builder/joomla/blob/main/docs/

## Source installation and release contract

- This is exclusively the component repository. A GitHub source ZIP of any reviewed branch or tag must install directly in Joomla, with every manifest file, production Composer dependency, licence, routing plugin and seed already tracked. No downstream Composer run, staging, compilation or packaging is allowed.
- This is exclusively the component repository. A GitHub source ZIP of any reviewed branch or tag must install directly in Joomla, with every manifest file, production Composer dependency, licence and seed already tracked. No downstream Composer run, staging, compilation or packaging is allowed.
- Keep production dependencies in `admin/vendor` and the installation seed in `admin/data`. When changing dependencies, run Composer as a maintainer, commit the lock and complete resolved runtime, and verify its autoload paths after relocation to Joomla's administrator component directory. Never hand-edit third-party vendor source.
- Preserve SQL installation/schema updates and the JSON-driven customization-preserving seed updater. They are approved installation mechanisms; do not replace them merely to change the release process.
- OctoJPack alone combines extensions using `.octojpack` and writes to a separate configured package repository. Package manifests, package update feeds, assembly scripts and bundled console copies do not belong here. Improve shared Octo tools upstream instead of copying their implementation into this repository.
- The manual Release workflow takes the next version. It freezes metadata, creates the immutable tag, adds that tag archive to the native component feed, runs OctoShoom synchronously and verifies its committed checksum, then invokes OctoJPack. A failed hash stage must prevent packaging. Never move an existing tag. Keep destination repositories, tool refs and credentials in documented GitHub variables/secrets.
- OctoJPack alone combines `mcp_component`, `mcp_plugin` (console) and `mcp_webservices` (HTTP routing), then writes to `joomengine/mcp_package` on `main`. Every plugin belongs in its own repository. Component installation, update and uninstall must never install, change or remove either plugin. The generated package manifest and assembly belong in the package repository. The package update feed `joomengine_mcp_update_server.xml` and shared `changelog.xml` deliberately remain in this component repository, as requested by the maintainer. Keep `.octojpack` concrete and usable from any machine: hardcode stable source/destination repositories, branch, raw GitHub update/changelog URLs and the raw licence URL. Use native latest-tag selection and `version_id`; do not render placeholders or rewrite the configuration during releases. Never change the shared Octo engines without an explicit request.
- The manual Release workflow takes the next version and freezes component metadata before creating its tag. Call `octoleo/git-user@v2` once, then `octoleo/octojpack@master` with `.octojpack`, update the package feed with the published version, and call `octoleo/octoshoom@master`. Hashing must follow package publication because the feed downloads the package ZIP. Both actions inherit the same Git setup and environment. The feed contains the current `pkg_joomengine_mcp` / `package` / client `site` entry, downloads only `mcp_package` tag archives, and uses the component version. Clear the previous archive checksum when advancing the feed; OctoShoom supplies the new one. Keep credentials in GitHub secrets. Do not duplicate authentication, hashing, archive checks, packaging, configuration rendering or repository preflight logic locally. Local release code only edits the component version, changelogs and package update entry. Never move a released tag.
- Update **both** `CHANGELOG.md` and `changelog.xml` with every meaningful change. Put pending entries under the exact literal `[[[NEXT_VERSION]]]`; create a new pending section after the previous one is released. Do not invent a version or modify historical released entries. The workflow replaces this marker with its input version in both files.
- Joomla changelog identity is `com_joomengine_mcp` / `component`. Use native categories `security`, `fix`, `language`, `addition`, `change`, `remove`, and `note`, each containing `item` children. Use matching human headings in Markdown. Record compatibility warnings under Note, errors fixed under Fix, and security fixes under Security. Keep both changelogs consistent and the manifest's `changelogurl` valid.
- Workflow changes require positive/negative metadata and ordering checks; source installation checks must inspect the tracked source archive. Do not restore package builders to make a test pass. See `docs/RELEASE.md` for the configuration and retry contract.
- Check workflow syntax and changed metadata behavior. Source installation checks inspect the tracked source archive. Do not copy upstream action tests or restore package builders to make a test pass. See `docs/RELEASE.md`.

## Verification

Expand Down
17 changes: 11 additions & 6 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,22 +11,27 @@

### Addition

- Add a manual version release workflow that freezes both changelogs, creates an immutable tag, updates the Joomla feed and waits for OctoShoom before invoking OctoJPack.
- Document GitHub variables/secrets, release retries and the source-installation contract for future agents.
- Add a manual version release workflow that freezes both changelogs, creates an immutable tag, publishes the package with OctoJPack, updates the package feed and runs OctoShoom against the published package.
- Document GitHub secrets and the source-installation contract for future agents.

### Change

- Delegate combined Joomla package assembly exclusively to OctoJPack and a separate package repository.
- Follow the Octoleo quick starts: set up Git once, let OctoJPack read `.octojpack` directly, then let OctoShoom hash the package download.

- Publish combined Joomla packages to `joomengine/mcp_package`; keep the package feed and shared changelog here, with the package version derived from the component.
- Extract webservices routing into its own `mcp_webservices` repository and include it as a separate OctoJPack extension.
- Verify tracked source archives in component and console installation tests.

### Remove

- Remove repository-local ZIP/package builders, distribution locks and package update metadata.
- Remove repository-local ZIP/package builders, distribution locks and generated package manifests.
- Remove component-installer ownership of the webservices plugin.
- Remove temporary action checkouts, configuration rendering, custom SSH setup, duplicate hash verification and package repository checks.

### Note

- Release the console plugin first and select its immutable tag in the component release configuration.
- Configure the variables and secrets in docs/RELEASE.md before the first release. OctoJPack must include GitHub tag-archive support.
- Tag the independent console and webservices plugin releases before releasing the component; OctoJPack selects their latest tags.
- Configure the secrets documented in docs/RELEASE.md before the first release.

## 0.1.1 — development baseline

Expand Down
10 changes: 5 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,21 +9,21 @@ An installable PHP MCP server for Joomla 6.1–6.x, with database-defined tools,

## Repository boundary

This repository owns the installable component: catalogue, administrator MVC/forms, HTTP endpoint/routing glue, Joomla token/ACL integration, shared API/native execution, durable state and jobs. Its locked production dependencies are committed under `admin/vendor`; Composer is a maintainer tool, never an installation step. External MCP connection code, remote stdio bridging, client documentation and client releases belong exclusively to `mcp_client`.
This repository owns the installable component: catalogue, administrator MVC/forms, HTTP endpoint controllers, Joomla token/ACL integration, shared API/native execution, durable state and jobs. Its locked production dependencies are committed under `admin/vendor`; Composer is a maintainer tool, never an installation step. External MCP connection code, remote stdio bridging, client documentation and client releases belong exclusively to `mcp_client`.

The component's outbound Joomla API transport is implemented in `admin/src/Http`. See [client separation and handoff](docs/CLIENT-HANDOFF.md).

## Download and install

Download this repository using **Code → Download ZIP**, or download a release tag's source ZIP, and upload it in Joomla's extension installer. The source tree already contains its production PHP dependencies, installation data and owned webservices routing plugin. No build, Composer run or repacking is required. The supported host is Joomla 6.1–6.x with PHP 8.3 or later and the extensions listed in `composer.json`.
Download this repository using **Code → Download ZIP**, or download a release tag's source ZIP, and upload it in Joomla's extension installer. The source tree already contains its production PHP dependencies and installation data. No build, Composer run or repacking is required. The supported host is Joomla 6.1–6.x with PHP 8.3 or later and the extensions listed in `composer.json`.

Configure the canonical site API URL and Joomla permissions under **Components → JoomEngine MCP → Options**. The authenticated MCP endpoint is `/api/index.php/v1/joomengine-mcp`, relative to the Joomla installation. For direct local console commands, install the separate [console plugin](https://github.com/joomengine/mcp_plugin), or use the combined Joomla package published by OctoJPack in the configured package repository.
Configure the canonical site API URL and Joomla permissions under **Components → JoomEngine MCP → Options**. The authenticated MCP endpoint is `/api/index.php/v1/joomengine-mcp`, relative to the Joomla installation. HTTP route registration comes from the separate [webservices plugin](https://github.com/joomengine/mcp_webservices); local console commands come from the [console plugin](https://github.com/joomengine/mcp_plugin). Install the [combined package](https://github.com/joomengine/mcp_package) to get all three extensions together.

For native JCB background jobs, provide a PHP CLI executable compatible with the installed Joomla version, with `pcntl_fork`, `posix_setsid` and `proc_open` available. Select its absolute path in the component's **PHP CLI binary** setting when it differs from the automatically detected PHP executable. The web-server account must be able to launch it and write the private artifact directory outside the served Joomla tree. Worker prerequisites are checked before a write is claimed. The golden-image Dockerfile demonstrates the required CLI extension setup; ordinary Joomla API operations remain available without that job runtime.

Remote AI applications can use the independent client's [Docker Compose launcher](https://github.com/joomengine/mcp_client/blob/feature/standalone-php-client/docs/DOCKER.md). Supply the HTTPS Joomla installation URL and native API token; the client discovers capabilities from this component. The console plugin is required for direct local Joomla MCP commands, while the remote client connects to the component's authenticated HTTP endpoint.

The combined package is built exclusively by [OctoJPack](https://github.com/octoleo/octojpack), using `.octojpack`, and published to a separate package repository. Run the manual **Release** workflow with the next version to freeze both changelogs, create the tag, update the Joomla feed, wait for OctoShoom to commit its checksums, and then invoke OctoJPack. [Release instructions](docs/RELEASE.md) list the repository variables and secrets to configure.
The combined package is built exclusively by [OctoJPack](https://github.com/octoleo/octojpack), using the fixed `.octojpack` configuration, and published to [mcp_package](https://github.com/joomengine/mcp_package). The component version determines the package version. Run the manual **Release** workflow to freeze the changelogs, tag the component, publish the package, update the package feed here, and let OctoShoom hash that package ZIP. [Release instructions](docs/RELEASE.md) list the required secrets.

## Required capabilities

Expand All @@ -47,7 +47,7 @@ Joomla core remains usable without JCB. Remote HTTP and stdio clients retain the

## Current status

Native administration, installed core tests, JCB synchronization and job/artifact runtime are implemented. [Implementation status](docs/IMPLEMENTATION.md) separates historical installed Joomla/JCB evidence from verification of the current source and release changes. Published tags identify component releases; package publication belongs to the configured package repository.
Native administration, installed core tests, JCB synchronization and job/artifact runtime are implemented. [Implementation status](docs/IMPLEMENTATION.md) separates historical installed Joomla/JCB evidence from verification of the current source and release changes. Published tags identify component releases; package publication belongs to `joomengine/mcp_package`.

The original migration source is pinned at `joomengine/joomla-mcp@2cff50f4f6b440da3c684f9995a77efad32e1a36`. It remains unchanged. Joomla 6 native contracts are authoritative; repository/MVC/XML placement follows JCB's extension-root layout. This is hand-authored JCB-aligned source, not an already imported JCB blueprint.

Expand Down
Loading
Loading