mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
fix(ui): hide workspace isolation controls for managed hosts (#13907)
## Thinking Path > - Paperclip manages AI agents and their work. > - Workspace isolation keeps task checkouts separate. > - Managed hosts can enable isolation and hide its experimental toggles. > - Project, task, and routine forms still expose choices that override that policy. > - This pull request adds an operator visibility key for those controls. > - Workspace access stays available, and execution keeps its existing policy. ## Linked Issues or Issue Description **What existing behavior does this improve?** Operator control over workspace isolation settings in the UI. This follows the settings list cleanup in #13905. **Current behavior** Hiding the experimental isolation toggles leaves project policy editors, task selectors, routine and pipeline overrides, recovery actions, and workspace configuration visible. **Proposed behavior** Set `PAPERCLIP_HIDDEN_SETTINGS=workspaces.isolation` to hide these controls. Keep workspace navigation, status, files, and runtime access. Hide experimental toggles separately. Instances that do not set this key keep their controls. **Reason and benefit** Users on managed hosts should use the host's isolation default. A hidden form must not submit a stale draft that overrides it. ## What Changed - Add the UI-only `workspaces.isolation` key to the shared visibility registry. - Hide project workspace policy, task and subtask selectors, routine and pipeline overrides, and isolated re-issue actions. - Hide the workspace Configuration tab and redirect direct links to workspace issues. - Omit hidden new-task and routine overrides. Keep explicit task/subtask workspace launch context, saved policies, and automatic branch values for workspace routine runs. - Wait for the health visibility policy before showing controls. Keep workspace access and all execution APIs available. - Document the key and test visibility, form payloads, deep links, and unchanged workspace access. ## Verification - All 52 CI checks pass on `50cc770d33` (two expected skips). The branch is mergeable. Greptile is 5/5 with no unresolved comments. - `pnpm -r typecheck` passed. - `pnpm build` passed. - `pnpm check:token-gates` passed. - Targeted UI checks passed: 346 tests across 14 suites, including hidden project/task controls, stale task drafts, routine branch defaults, recovery actions, configuration deep links, and workspace access. - Shared settings-visibility tests passed: 11 tests. - `pnpm test:run` was run and stopped after reproducing five failures in unchanged server tests: two `chat-channels.integration` cases (linked-request provenance and direct external-chat finals) and three `company-skills-service` cases (runtime refresh, concurrent download, and explicit update). The earlier local run for #13905 showed the same failures. The full local suite is not claimed green. Targeted UI/shared checks pass. All PR CI shards, including the affected chat and skills suites, pass. - Reviewed the diff for secrets, private links, and run artifacts. ## Risks This key changes UI visibility only. It does not reject API calls or change feature values. Operators must enable isolation and its default through their existing policy mechanism. Older app versions ignore the new key until upgraded. Removing the key restores the controls. No schema changes. ## Model Used OpenAI GPT-6 (Codex), with reasoning, repository tools, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either linked existing issues or described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal ticket id - [x] I have run tests locally; targeted checks pass (full-suite limitation documented above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
1 parent
8ee8f1fd6e
commit
94a0aa7726
21 files changed
+336
-84
No files matched your search
@@ -2680,6 +2680,7 @@ export {
|
||||
HIDEABLE_GENERAL_SECTIONS,
|
||||
HIDEABLE_INSTANCE_PAGES,
|
||||
HIDEABLE_SETTING_KEYS,
|
||||
HIDEABLE_WORKSPACE_SECTIONS,
|
||||
SETTINGS_OPERATOR_MANAGED_ERROR_CODE,
|
||||
UI_ONLY_GENERAL_SECTIONS,
|
||||
experimentalSettingKey,
|
||||
@@ -2695,6 +2696,7 @@ export {
|
||||
type HideableGeneralSection,
|
||||
type HideableInstancePage,
|
||||
type HideableSettingKey,
|
||||
type HideableWorkspaceSection,
|
||||
type ParsedHiddenSettings,
|
||||
} from "./settings-visibility.js";
|
||||
export {
|
||||
|
||||
@@ -49,6 +49,11 @@ describe("hideable setting keys", () => {
|
||||
});
|
||||
|
||||
describe("parseHiddenSettingsList", () => {
|
||||
it("accepts workspace controls independently of experimental flags", () => {
|
||||
expect(parseHiddenSettingsList("workspaces.isolation")).toEqual({ hidden: ["workspaces.isolation"], unknown: [] });
|
||||
expect(hidesExperimentalSetting(new Set(["workspaces.isolation"]), "enableIsolatedWorkspaces")).toBe(false);
|
||||
});
|
||||
|
||||
it("returns nothing hidden for undefined or empty input", () => {
|
||||
expect(parseHiddenSettingsList(undefined)).toEqual({ hidden: [], unknown: [] });
|
||||
expect(parseHiddenSettingsList(" , ,")).toEqual({ hidden: [], unknown: [] });
|
||||
|
||||
@@ -99,7 +99,12 @@ export function experimentalSettingKey(key: InstanceFeatureKey): HideableExperim
|
||||
return `instance.experimental.${key}`;
|
||||
}
|
||||
|
||||
/** Workspace policy editors and selectors. UI-only; execution and APIs stay active. */
|
||||
export const HIDEABLE_WORKSPACE_SECTIONS = ["workspaces.isolation"] as const;
|
||||
export type HideableWorkspaceSection = (typeof HIDEABLE_WORKSPACE_SECTIONS)[number];
|
||||
|
||||
export type HideableSettingKey =
|
||||
| HideableWorkspaceSection
|
||||
| HideableInstancePage
|
||||
| HideableCompanyPage
|
||||
| HideableCompanySection
|
||||
@@ -108,6 +113,7 @@ export type HideableSettingKey =
|
||||
|
||||
/** Every key `PAPERCLIP_HIDDEN_SETTINGS` accepts. */
|
||||
export const HIDEABLE_SETTING_KEYS: readonly HideableSettingKey[] = [
|
||||
...HIDEABLE_WORKSPACE_SECTIONS,
|
||||
...HIDEABLE_INSTANCE_PAGES,
|
||||
...HIDEABLE_COMPANY_PAGES,
|
||||
...HIDEABLE_COMPANY_SECTIONS,
|
||||
|
||||
Reference in new issue
Block a user