mucgpt

Run

# Start frontend with API mocking
# inside /mucgpt-frontend
npm run dev
# Start frontend using container stack for API
# inside /mucgpt-frontend
npm run dev-no-mock
# Start stack with local running services
# inside /stack
podman compose -f docker-compose.yml -f docker-compose.dev.yml up

Working with UV

Synchronize / Update Packages

In existing projects, the collected dependencies can be synchronized or updated with a single command.

# Synchronize packages
uv sync --all-extras

# Update packages
uv lock -U

Install pre-commit hooks

 uv run pre-commit install

Add Packages

Packages can be added using the following command

# Add  package
uv add pydantic

### Remove Packages

Packages can also be removed.

```bash
# Remove package
uv remove pydantic

Running tests

uv run pytest

Linting

uv run ruff check
# and fixing
uv run ruff check --fix

Build new images

First create a tag (decide which one is needed)

 git tag mucgpt-frontend-<version>
 git tag mucgpt-core-<version>
 git tag mucgpt-assistant-<version>
 git tag mucgpt-assistant-migrations-<version>

Then push to origin, one of the release workflows is then triggered

 git push origin mucgpt-frontend-<version>
 git push origin mucgpt-core-<version>
 git push origin mucgpt-assistant-<version>
 git push origin mucgpt-assistant-migrations-<version>

You can find the available versions under:

Note: A new frontend tag will also create a new github pages deployment with the actual version

MCP credential handling security note

MCP source credentials and auth overrides are modeled as secret types in configuration to reduce accidental plaintext exposure in config representation and normal app logging.

However, for outbound MCP calls the credentials are materialized into HTTP headers at runtime. This means the implementation does not guarantee secrecy against host/runtime inspection (e.g., process memory inspection, crash dumps, verbose HTTP client logging, reverse-proxy/request logging, or packet capture at TLS termination boundaries).

Treat this mechanism as log/config leak reduction, not full runtime confidentiality. For production, keep HTTP client logs non-verbose, avoid logging request objects, and restrict access to host-level observability and diagnostics.