1use std::borrow::ToOwned;
2use std::collections::BTreeMap;
3use std::fs;
4use std::path::{Path, PathBuf};
5
6use crate::json::JsonValue;
7use crate::sandbox::{FilesystemIsolationMode, SandboxConfig};
8
9use super::types::*;
10
11#[must_use]
12pub fn default_config_home() -> PathBuf {
13 std::env::var_os("CODINEER_CONFIG_HOME")
14 .map(PathBuf::from)
15 .or_else(|| crate::home_dir().map(|home| home.join(".codineer")))
16 .unwrap_or_else(|| PathBuf::from(".codineer"))
17}
18
19#[derive(Debug, Clone, PartialEq, Eq)]
20pub struct ConfigLoader {
21 cwd: PathBuf,
22 config_home: PathBuf,
23}
24
25impl ConfigLoader {
26 #[must_use]
27 pub fn new(cwd: impl Into<PathBuf>, config_home: impl Into<PathBuf>) -> Self {
28 Self {
29 cwd: cwd.into(),
30 config_home: config_home.into(),
31 }
32 }
33
34 #[must_use]
35 pub fn default_for(cwd: impl Into<PathBuf>) -> Self {
36 let cwd = cwd.into();
37 let config_home = default_config_home();
38 Self { cwd, config_home }
39 }
40
41 #[must_use]
42 pub fn config_home(&self) -> &Path {
43 &self.config_home
44 }
45
46 #[must_use]
47 pub fn discover(&self) -> Vec<ConfigEntry> {
48 let user_flat_config = self.config_home.parent().map_or_else(
49 || PathBuf::from(".codineer.json"),
50 |parent| parent.join(".codineer.json"),
51 );
52 vec![
53 ConfigEntry {
54 source: ConfigSource::User,
55 path: user_flat_config,
56 },
57 ConfigEntry {
58 source: ConfigSource::User,
59 path: self.config_home.join("settings.json"),
60 },
61 ConfigEntry {
62 source: ConfigSource::Project,
63 path: self.cwd.join(".codineer.json"),
64 },
65 ConfigEntry {
66 source: ConfigSource::Project,
67 path: self.cwd.join(".codineer").join("settings.json"),
68 },
69 ConfigEntry {
70 source: ConfigSource::Local,
71 path: self.cwd.join(".codineer").join("settings.local.json"),
72 },
73 ]
74 }
75
76 pub fn load(&self) -> Result<RuntimeConfig, ConfigError> {
77 let mut merged = BTreeMap::new();
78 let mut loaded_entries = Vec::new();
79 let mut mcp_servers = BTreeMap::new();
80
81 let mut config_warnings = Vec::new();
82 for entry in self.discover() {
83 let Some(value) = read_optional_json_object(&entry.path, &mut config_warnings)? else {
84 continue;
85 };
86 merge_mcp_servers(&mut mcp_servers, entry.source, &value, &entry.path)?;
87 deep_merge_objects(&mut merged, &value);
88 loaded_entries.push(entry);
89 }
90
91 let merged_value = JsonValue::Object(merged.clone());
92
93 let feature_config = RuntimeFeatureConfig {
94 hooks: parse_optional_hooks_config(&merged_value)?,
95 plugins: parse_optional_plugin_config(&merged_value)?,
96 mcp: McpConfigCollection {
97 servers: mcp_servers,
98 },
99 oauth: parse_optional_oauth_config(&merged_value, "merged settings.oauth")?,
100 model: parse_optional_model(&merged_value),
101 fallback_models: parse_optional_fallback_models(&merged_value),
102 permission_mode: parse_optional_permission_mode(&merged_value)?,
103 sandbox: parse_optional_sandbox_config(&merged_value)?,
104 providers: parse_optional_providers_config(&merged_value)?,
105 credentials: parse_optional_credentials_config(&merged_value)?,
106 };
107
108 for w in &config_warnings {
109 eprintln!("warning: {w}");
110 }
111
112 Ok(RuntimeConfig::new(merged, loaded_entries, feature_config))
113 }
114}
115
116fn read_optional_json_object(
117 path: &Path,
118 warnings: &mut Vec<String>,
119) -> Result<Option<BTreeMap<String, JsonValue>>, ConfigError> {
120 let is_flat_config = path.file_name().and_then(|name| name.to_str()) == Some(".codineer.json");
121 let contents = match fs::read_to_string(path) {
122 Ok(contents) => contents,
123 Err(error) if error.kind() == std::io::ErrorKind::NotFound => return Ok(None),
124 Err(error) => return Err(ConfigError::Io(error)),
125 };
126
127 if contents.trim().is_empty() {
128 return Ok(Some(BTreeMap::new()));
129 }
130
131 let parsed = match JsonValue::parse(&contents) {
132 Ok(parsed) => parsed,
133 Err(error) if is_flat_config => {
134 warnings.push(format!(
135 "ignoring malformed config '{}': {error}",
136 path.display()
137 ));
138 return Ok(None);
139 }
140 Err(error) => return Err(ConfigError::Parse(format!("{}: {error}", path.display()))),
141 };
142 let Some(object) = parsed.as_object() else {
143 if is_flat_config {
144 warnings.push(format!(
145 "ignoring config '{}': expected JSON object at top level",
146 path.display()
147 ));
148 return Ok(None);
149 }
150 return Err(ConfigError::Parse(format!(
151 "{}: top-level settings value must be a JSON object",
152 path.display()
153 )));
154 };
155 Ok(Some(object.clone()))
156}
157
158fn merge_mcp_servers(
159 target: &mut BTreeMap<String, ScopedMcpServerConfig>,
160 source: ConfigSource,
161 root: &BTreeMap<String, JsonValue>,
162 path: &Path,
163) -> Result<(), ConfigError> {
164 let Some(mcp_servers) = root.get("mcpServers") else {
165 return Ok(());
166 };
167 let servers = expect_object(mcp_servers, &format!("{}: mcpServers", path.display()))?;
168 for (name, value) in servers {
169 let parsed = parse_mcp_server_config(
170 name,
171 value,
172 &format!("{}: mcpServers.{name}", path.display()),
173 )?;
174 target.insert(
175 name.clone(),
176 ScopedMcpServerConfig {
177 scope: source,
178 config: parsed,
179 },
180 );
181 }
182 Ok(())
183}
184
185fn parse_optional_model(root: &JsonValue) -> Option<String> {
186 root.as_object()
187 .and_then(|object| object.get("model"))
188 .and_then(JsonValue::as_str)
189 .map(ToOwned::to_owned)
190}
191
192fn parse_optional_fallback_models(root: &JsonValue) -> Vec<String> {
193 root.as_object()
194 .and_then(|object| object.get("fallbackModels"))
195 .and_then(JsonValue::as_array)
196 .map(|arr| {
197 arr.iter()
198 .filter_map(JsonValue::as_str)
199 .map(ToOwned::to_owned)
200 .collect()
201 })
202 .unwrap_or_default()
203}
204
205fn parse_optional_providers_config(
206 root: &JsonValue,
207) -> Result<BTreeMap<String, CustomProviderConfig>, ConfigError> {
208 let Some(object) = root.as_object() else {
209 return Ok(BTreeMap::new());
210 };
211 let Some(providers_value) = object.get("providers") else {
212 return Ok(BTreeMap::new());
213 };
214 let providers_obj = expect_object(providers_value, "merged settings.providers")?;
215 let mut result = BTreeMap::new();
216 for (name, value) in providers_obj {
217 let ctx = format!("merged settings.providers.{name}");
218 let provider_obj = expect_object(value, &ctx)?;
219 let base_url = expect_string(provider_obj, "baseUrl", &ctx)?.to_string();
220 let api_key = optional_string(provider_obj, "apiKey", &ctx)?.map(str::to_string);
221 let api_key_env = optional_string(provider_obj, "apiKeyEnv", &ctx)?.map(str::to_string);
222 let models = optional_string_array(provider_obj, "models", &ctx)?.unwrap_or_default();
223 let default_model =
224 optional_string(provider_obj, "defaultModel", &ctx)?.map(str::to_string);
225 result.insert(
226 name.clone(),
227 CustomProviderConfig {
228 base_url,
229 api_key,
230 api_key_env,
231 models,
232 default_model,
233 },
234 );
235 }
236 Ok(result)
237}
238
239fn parse_optional_hooks_config(root: &JsonValue) -> Result<RuntimeHookConfig, ConfigError> {
240 let Some(object) = root.as_object() else {
241 return Ok(RuntimeHookConfig::default());
242 };
243 let Some(hooks_value) = object.get("hooks") else {
244 return Ok(RuntimeHookConfig::default());
245 };
246 let hooks = expect_object(hooks_value, "merged settings.hooks")?;
247 Ok(RuntimeHookConfig {
248 pre_tool_use: optional_string_array(hooks, "PreToolUse", "merged settings.hooks")?
249 .unwrap_or_default(),
250 post_tool_use: optional_string_array(hooks, "PostToolUse", "merged settings.hooks")?
251 .unwrap_or_default(),
252 })
253}
254
255fn parse_optional_plugin_config(root: &JsonValue) -> Result<RuntimePluginConfig, ConfigError> {
256 let Some(object) = root.as_object() else {
257 return Ok(RuntimePluginConfig::default());
258 };
259
260 let mut config = RuntimePluginConfig::default();
261 if let Some(enabled_plugins) = object.get("enabledPlugins") {
262 config.enabled_plugins = parse_bool_map(enabled_plugins, "merged settings.enabledPlugins")?;
263 }
264
265 let Some(plugins_value) = object.get("plugins") else {
266 return Ok(config);
267 };
268 let plugins = expect_object(plugins_value, "merged settings.plugins")?;
269
270 if let Some(enabled_value) = plugins.get("enabled") {
271 config.enabled_plugins = parse_bool_map(enabled_value, "merged settings.plugins.enabled")?;
272 }
273 config.external_directories =
274 optional_string_array(plugins, "externalDirectories", "merged settings.plugins")?
275 .unwrap_or_default();
276 config.install_root =
277 optional_string(plugins, "installRoot", "merged settings.plugins")?.map(str::to_string);
278 config.registry_path =
279 optional_string(plugins, "registryPath", "merged settings.plugins")?.map(str::to_string);
280 config.bundled_root =
281 optional_string(plugins, "bundledRoot", "merged settings.plugins")?.map(str::to_string);
282 Ok(config)
283}
284
285fn parse_optional_permission_mode(
286 root: &JsonValue,
287) -> Result<Option<ResolvedPermissionMode>, ConfigError> {
288 let Some(object) = root.as_object() else {
289 return Ok(None);
290 };
291 if let Some(mode) = object.get("permissionMode").and_then(JsonValue::as_str) {
292 return parse_permission_mode_label(mode, "merged settings.permissionMode").map(Some);
293 }
294 let Some(mode) = object
295 .get("permissions")
296 .and_then(JsonValue::as_object)
297 .and_then(|permissions| permissions.get("defaultMode"))
298 .and_then(JsonValue::as_str)
299 else {
300 return Ok(None);
301 };
302 parse_permission_mode_label(mode, "merged settings.permissions.defaultMode").map(Some)
303}
304
305fn parse_permission_mode_label(
306 mode: &str,
307 context: &str,
308) -> Result<ResolvedPermissionMode, ConfigError> {
309 match mode {
310 "default" | "plan" | "read-only" => Ok(ResolvedPermissionMode::ReadOnly),
311 "acceptEdits" | "auto" | "workspace-write" => Ok(ResolvedPermissionMode::WorkspaceWrite),
312 "dontAsk" | "danger-full-access" => Ok(ResolvedPermissionMode::DangerFullAccess),
313 other => Err(ConfigError::Parse(format!(
314 "{context}: unsupported permission mode {other}"
315 ))),
316 }
317}
318
319fn parse_optional_sandbox_config(root: &JsonValue) -> Result<SandboxConfig, ConfigError> {
320 let Some(object) = root.as_object() else {
321 return Ok(SandboxConfig::default());
322 };
323 let Some(sandbox_value) = object.get("sandbox") else {
324 return Ok(SandboxConfig::default());
325 };
326 let sandbox = expect_object(sandbox_value, "merged settings.sandbox")?;
327 let filesystem_mode = optional_string(sandbox, "filesystemMode", "merged settings.sandbox")?
328 .map(parse_filesystem_mode_label)
329 .transpose()?;
330 Ok(SandboxConfig {
331 enabled: optional_bool(sandbox, "enabled", "merged settings.sandbox")?,
332 namespace_restrictions: optional_bool(
333 sandbox,
334 "namespaceRestrictions",
335 "merged settings.sandbox",
336 )?,
337 network_isolation: optional_bool(sandbox, "networkIsolation", "merged settings.sandbox")?,
338 filesystem_mode,
339 allowed_mounts: optional_string_array(sandbox, "allowedMounts", "merged settings.sandbox")?
340 .unwrap_or_default(),
341 })
342}
343
344fn parse_filesystem_mode_label(value: &str) -> Result<FilesystemIsolationMode, ConfigError> {
345 match value {
346 "off" => Ok(FilesystemIsolationMode::Off),
347 "workspace-only" => Ok(FilesystemIsolationMode::WorkspaceOnly),
348 "allow-list" => Ok(FilesystemIsolationMode::AllowList),
349 other => Err(ConfigError::Parse(format!(
350 "merged settings.sandbox.filesystemMode: unsupported filesystem mode {other}"
351 ))),
352 }
353}
354
355fn parse_optional_oauth_config(
356 root: &JsonValue,
357 context: &str,
358) -> Result<Option<OAuthConfig>, ConfigError> {
359 let Some(oauth_value) = root.as_object().and_then(|object| object.get("oauth")) else {
360 return Ok(None);
361 };
362 let object = expect_object(oauth_value, context)?;
363 let client_id = expect_string(object, "clientId", context)?.to_string();
364 let authorize_url = expect_string(object, "authorizeUrl", context)?.to_string();
365 let token_url = expect_string(object, "tokenUrl", context)?.to_string();
366 let callback_port = optional_u16(object, "callbackPort", context)?;
367 let manual_redirect_url =
368 optional_string(object, "manualRedirectUrl", context)?.map(str::to_string);
369 let scopes = optional_string_array(object, "scopes", context)?.unwrap_or_default();
370 Ok(Some(OAuthConfig {
371 client_id,
372 authorize_url,
373 token_url,
374 callback_port,
375 manual_redirect_url,
376 scopes,
377 }))
378}
379
380fn parse_mcp_server_config(
381 server_name: &str,
382 value: &JsonValue,
383 context: &str,
384) -> Result<McpServerConfig, ConfigError> {
385 let object = expect_object(value, context)?;
386 let server_type = optional_string(object, "type", context)?.unwrap_or("stdio");
387 match server_type {
388 "stdio" => Ok(McpServerConfig::Stdio(McpStdioServerConfig {
389 command: expect_string(object, "command", context)?.to_string(),
390 args: optional_string_array(object, "args", context)?.unwrap_or_default(),
391 env: optional_string_map(object, "env", context)?.unwrap_or_default(),
392 })),
393 "sse" => Ok(McpServerConfig::Sse(parse_mcp_remote_server_config(
394 object, context,
395 )?)),
396 "http" => Ok(McpServerConfig::Http(parse_mcp_remote_server_config(
397 object, context,
398 )?)),
399 "ws" | "websocket" => Ok(McpServerConfig::Ws(McpWebSocketServerConfig {
400 url: expect_string(object, "url", context)?.to_string(),
401 headers: optional_string_map(object, "headers", context)?.unwrap_or_default(),
402 headers_helper: optional_string(object, "headersHelper", context)?.map(str::to_string),
403 })),
404 "sdk" => Ok(McpServerConfig::Sdk(McpSdkServerConfig {
405 name: expect_string(object, "name", context)?.to_string(),
406 })),
407 "claudeai-proxy" => Ok(McpServerConfig::ManagedProxy(McpManagedProxyServerConfig {
408 url: expect_string(object, "url", context)?.to_string(),
409 id: expect_string(object, "id", context)?.to_string(),
410 })),
411 other => Err(ConfigError::Parse(format!(
412 "{context}: unsupported MCP server type for {server_name}: {other}"
413 ))),
414 }
415}
416
417fn parse_mcp_remote_server_config(
418 object: &BTreeMap<String, JsonValue>,
419 context: &str,
420) -> Result<McpRemoteServerConfig, ConfigError> {
421 Ok(McpRemoteServerConfig {
422 url: expect_string(object, "url", context)?.to_string(),
423 headers: optional_string_map(object, "headers", context)?.unwrap_or_default(),
424 headers_helper: optional_string(object, "headersHelper", context)?.map(str::to_string),
425 oauth: parse_optional_mcp_oauth_config(object, context)?,
426 })
427}
428
429fn parse_optional_mcp_oauth_config(
430 object: &BTreeMap<String, JsonValue>,
431 context: &str,
432) -> Result<Option<McpOAuthConfig>, ConfigError> {
433 let Some(value) = object.get("oauth") else {
434 return Ok(None);
435 };
436 let oauth = expect_object(value, &format!("{context}.oauth"))?;
437 Ok(Some(McpOAuthConfig {
438 client_id: optional_string(oauth, "clientId", context)?.map(str::to_string),
439 callback_port: optional_u16(oauth, "callbackPort", context)?,
440 auth_server_metadata_url: optional_string(oauth, "authServerMetadataUrl", context)?
441 .map(str::to_string),
442 xaa: optional_bool(oauth, "xaa", context)?,
443 }))
444}
445
446fn expect_object<'a>(
447 value: &'a JsonValue,
448 context: &str,
449) -> Result<&'a BTreeMap<String, JsonValue>, ConfigError> {
450 value
451 .as_object()
452 .ok_or_else(|| ConfigError::Parse(format!("{context}: expected JSON object")))
453}
454
455fn expect_string<'a>(
456 object: &'a BTreeMap<String, JsonValue>,
457 key: &str,
458 context: &str,
459) -> Result<&'a str, ConfigError> {
460 object
461 .get(key)
462 .and_then(JsonValue::as_str)
463 .ok_or_else(|| ConfigError::Parse(format!("{context}: missing string field {key}")))
464}
465
466fn optional_string<'a>(
467 object: &'a BTreeMap<String, JsonValue>,
468 key: &str,
469 context: &str,
470) -> Result<Option<&'a str>, ConfigError> {
471 match object.get(key) {
472 Some(value) => value
473 .as_str()
474 .map(Some)
475 .ok_or_else(|| ConfigError::Parse(format!("{context}: field {key} must be a string"))),
476 None => Ok(None),
477 }
478}
479
480fn optional_bool(
481 object: &BTreeMap<String, JsonValue>,
482 key: &str,
483 context: &str,
484) -> Result<Option<bool>, ConfigError> {
485 match object.get(key) {
486 Some(value) => value
487 .as_bool()
488 .map(Some)
489 .ok_or_else(|| ConfigError::Parse(format!("{context}: field {key} must be a boolean"))),
490 None => Ok(None),
491 }
492}
493
494fn optional_u16(
495 object: &BTreeMap<String, JsonValue>,
496 key: &str,
497 context: &str,
498) -> Result<Option<u16>, ConfigError> {
499 match object.get(key) {
500 Some(value) => {
501 let Some(number) = value.as_i64() else {
502 return Err(ConfigError::Parse(format!(
503 "{context}: field {key} must be an integer"
504 )));
505 };
506 let number = u16::try_from(number).map_err(|_| {
507 ConfigError::Parse(format!("{context}: field {key} is out of range"))
508 })?;
509 Ok(Some(number))
510 }
511 None => Ok(None),
512 }
513}
514
515fn parse_bool_map(value: &JsonValue, context: &str) -> Result<BTreeMap<String, bool>, ConfigError> {
516 let Some(map) = value.as_object() else {
517 return Err(ConfigError::Parse(format!(
518 "{context}: expected JSON object"
519 )));
520 };
521 map.iter()
522 .map(|(key, value)| {
523 value
524 .as_bool()
525 .map(|enabled| (key.clone(), enabled))
526 .ok_or_else(|| {
527 ConfigError::Parse(format!("{context}: field {key} must be a boolean"))
528 })
529 })
530 .collect()
531}
532
533fn optional_string_array(
534 object: &BTreeMap<String, JsonValue>,
535 key: &str,
536 context: &str,
537) -> Result<Option<Vec<String>>, ConfigError> {
538 match object.get(key) {
539 Some(value) => {
540 let Some(array) = value.as_array() else {
541 return Err(ConfigError::Parse(format!(
542 "{context}: field {key} must be an array"
543 )));
544 };
545 array
546 .iter()
547 .map(|item| {
548 item.as_str().map(ToOwned::to_owned).ok_or_else(|| {
549 ConfigError::Parse(format!(
550 "{context}: field {key} must contain only strings"
551 ))
552 })
553 })
554 .collect::<Result<Vec<_>, _>>()
555 .map(Some)
556 }
557 None => Ok(None),
558 }
559}
560
561fn optional_string_map(
562 object: &BTreeMap<String, JsonValue>,
563 key: &str,
564 context: &str,
565) -> Result<Option<BTreeMap<String, String>>, ConfigError> {
566 match object.get(key) {
567 Some(value) => {
568 let Some(map) = value.as_object() else {
569 return Err(ConfigError::Parse(format!(
570 "{context}: field {key} must be an object"
571 )));
572 };
573 map.iter()
574 .map(|(entry_key, entry_value)| {
575 entry_value
576 .as_str()
577 .map(|text| (entry_key.clone(), text.to_string()))
578 .ok_or_else(|| {
579 ConfigError::Parse(format!(
580 "{context}: field {key} must contain only string values"
581 ))
582 })
583 })
584 .collect::<Result<BTreeMap<_, _>, _>>()
585 .map(Some)
586 }
587 None => Ok(None),
588 }
589}
590
591fn parse_optional_credentials_config(root: &JsonValue) -> Result<CredentialConfig, ConfigError> {
592 let Some(object) = root.as_object() else {
593 return Ok(CredentialConfig::default());
594 };
595 let Some(cred_value) = object.get("credentials") else {
596 return Ok(CredentialConfig::default());
597 };
598 let cred = expect_object(cred_value, "merged settings.credentials")?;
599
600 let default_source =
601 optional_string(cred, "defaultSource", "merged settings.credentials")?.map(str::to_string);
602 let auto_discover =
603 optional_bool(cred, "autoDiscover", "merged settings.credentials")?.unwrap_or(true);
604
605 let claude_code_enabled = cred
606 .get("claudeCode")
607 .and_then(JsonValue::as_object)
608 .and_then(|obj| obj.get("enabled").and_then(JsonValue::as_bool))
609 .unwrap_or(true);
610
611 Ok(CredentialConfig {
612 default_source,
613 auto_discover,
614 claude_code_enabled: auto_discover && claude_code_enabled,
615 })
616}
617
618fn deep_merge_objects(
619 target: &mut BTreeMap<String, JsonValue>,
620 source: &BTreeMap<String, JsonValue>,
621) {
622 for (key, value) in source {
623 match (target.get_mut(key), value) {
624 (Some(JsonValue::Object(existing)), JsonValue::Object(incoming)) => {
625 deep_merge_objects(existing, incoming);
626 }
627 _ => {
628 target.insert(key.clone(), value.clone());
629 }
630 }
631 }
632}