ef1dbdfc86
CI & Build / Python lint (push) Successful in 3s
CI & Build / Python tests (push) Failing after 31s
CI & Build / TypeScript typecheck (push) Successful in 34s
CI & Build / integration (push) Successful in 34s
CI & Build / Build & push image (push) Has been skipped
Closes #2092 and the Knowledge-browse provenance gap. The two halves of a hybrid search disagreed: the keyword half honoured shares while the semantic half was pinned to NoteEmbedding.user_id, so a shared record was findable by wording and invisible by meaning — the case a semantic search exists to serve. semantic_search_notes now scopes on Note via a `scope` parameter, and each of its five callers declares which kind of act it is: mcp/tools/search.py read the agent asked routes/search.py read the user typed it knowledge.py (semantic) read matches the keyword half beside it plugin_context.py browse nobody asked; never a one-to-one share dedup.py own a verdict that blocks a write must not hinge on another person's notes That last one is the reason this isn't a single global widening: the dedup gate returns "update the existing one instead", so matching a stranger's record would refuse a legitimate create and point at something the caller can't edit. Scope defaults to "own" so a caller that forgets is wrong in the safe direction, and an unknown scope raises rather than falling back — a typo there would be a data-exposure bug. Auto-inject keeps the browse scope, which still admits a collaborator's note via a shared project. Its menu line is the only provenance an agent sees, so a foreign hit now reads: #12 "Title" (0.71) - shared by alex, treat as a suggestion. MCP and REST search results carry shared/owner too. Knowledge browse: the feed hydrates cards from /api/knowledge/batch rather than the list route, so both paths label rows now, and KnowledgeView shows "by <owner>" on records the viewer doesn't own. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RLwAaV4DQEmVyn496HnEvt
71 lines
2.4 KiB
Python
71 lines
2.4 KiB
Python
import time
|
|
|
|
from quart import Blueprint, jsonify, request
|
|
|
|
from scribe.auth import login_required, get_current_user_id
|
|
from scribe.services.access import owner_names_for
|
|
from scribe.services.embeddings import semantic_search_notes
|
|
from scribe.services.retrieval_telemetry import record_retrieval
|
|
|
|
# This route searches with a looser floor than the MCP tool default — it powers
|
|
# an interactive feed where loosely-related hits still have value.
|
|
_REST_SEARCH_THRESHOLD = 0.3
|
|
|
|
search_bp = Blueprint("search", __name__, url_prefix="/api/search")
|
|
|
|
|
|
def _content_type_to_is_task(content_type: str) -> bool | None:
|
|
"""Map content_type query param to semantic_search_notes is_task arg."""
|
|
if content_type == "note":
|
|
return False
|
|
if content_type == "task":
|
|
return True
|
|
return None # "all" or unknown → no filter
|
|
|
|
|
|
@search_bp.route("", methods=["GET"])
|
|
@login_required
|
|
async def search_route():
|
|
uid = get_current_user_id()
|
|
q = (request.args.get("q") or "").strip()
|
|
if not q:
|
|
return jsonify({"error": "q is required"}), 400
|
|
|
|
content_type = request.args.get("content_type", "all")
|
|
limit = min(request.args.get("limit", 10, type=int), 50)
|
|
is_task = _content_type_to_is_task(content_type)
|
|
|
|
t0 = time.perf_counter()
|
|
results = await semantic_search_notes(
|
|
uid, q, limit=limit, is_task=is_task, threshold=_REST_SEARCH_THRESHOLD,
|
|
# The user typed this, so it reaches everything they may read.
|
|
scope="read",
|
|
)
|
|
record_retrieval(
|
|
user_id=uid, source="rest_search", query=q,
|
|
threshold=_REST_SEARCH_THRESHOLD, limit=limit,
|
|
project_id=None, is_task=is_task, results=results,
|
|
duration_ms=(time.perf_counter() - t0) * 1000.0,
|
|
)
|
|
owners = await owner_names_for(
|
|
{int(note.user_id) for _s, note in results if note.user_id != uid}
|
|
)
|
|
return jsonify({
|
|
"results": [
|
|
{
|
|
"id": note.id,
|
|
"title": note.title,
|
|
"body": note.body or "",
|
|
"is_task": note.is_task,
|
|
"tags": note.tags or [],
|
|
"similarity": score,
|
|
**(
|
|
{"shared": True, "owner": owners.get(int(note.user_id))}
|
|
if note.user_id != uid else {}
|
|
),
|
|
}
|
|
for score, note in results # semantic_search_notes returns list[tuple[float, Note]]
|
|
],
|
|
"total": len(results),
|
|
})
|