mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
fix(connections): repair stale AI defaults from agent settings (#14916)
## Thinking Path > - Paperclip manages AI agents and controls the credentials used for their work. > - Managed AI connections resolve each responsible user's provider default. > - Agent settings created another account but kept the old default selected. > - A rejected provider test left the old account marked as connected. > - Claude ACP reported a typed login failure as a generic terminal-access error. > - This pull request repairs the selected account or selects the new login explicitly. > - Agents can save and run with the repaired credential, and failed logins request sign-in. ## Linked Issues or Issue Description - Fixes #14831. - Refs #13867. Environment failures remain separate from credential-health failures. ## What Changed - Add an agent-settings action to reconnect an unavailable personal default in place. Keep its connection, grant, default, and agent access. - State that a new account becomes the user's provider default. Select its returned grant before changing the agent binding. Keep the actual sign-in method. - Show default-update errors and allow retry without another provider login. - Show the agent-access choice. Connection managers start with company-wide access for their own tasks. Other members start with access for the current agent. - Use the server's connection-manager permission in the shared list response. This includes members with a custom management grant. - Mark credentials as needing attention after an explicit login rejection in Test or Save. This includes API-key 401 and 403 responses. Network, quota, and server failures keep the credential health unchanged. - Reuse the credential-generation check so an old failure cannot invalidate a newer reconnect. - Route Claude's typed provider `access` failure to the existing login-recovery flow. Replace its generic terminal-access fallback with a sign-in message. - Add regression tests and update the AI Connections documentation. ## Verification - Red: the UI tests failed on the missing reconnect action, unused returned grant, missing access choice, and lost default-update error. The server tests failed because rejected credentials stayed connected. The real ACP fixture returned `acpx_turn_failed` for typed login failures. - Green: 156 tests passed across the AI connection, hiring, agent field, and New Agent suites. All 37 environment-route tests passed. The Claude ACP authentication fixtures also passed. - `pnpm check:token-gates` passed. - `pnpm -r typecheck` passed. - `pnpm build` passed. - The full local `pnpm test:run` passed 707 files and 14,503 tests, then exited with an agent-conversation timeout and embedded PostgreSQL startup failures in unchanged suites. The isolated conversation and migration tests passed on rerun. Later local test groups did not run after this failure. - [All CI gates passed](https://github.com/paperclipai/paperclip/actions/runs/37012669356) on commit `38513dfe2`. This includes the full test matrix, browser tests, typecheck, build, Runner checks, and canary dry run. - Greptile reviewed commit `38513dfe2` and returned 5/5 with no open findings. - The regression tests use a real embedded database and a real ACP fixture process. Live provider sign-in requires a valid account and was not run. ## Risks - Connecting a new account from agent settings changes the user's provider default. The dialog states this before sign-in. - The displayed access choice can allow all company agents to use the account for its owner's tasks. Reconnect keeps the existing access. Server permissions still control installs. - Claude's typed `access` category maps to the provider's `auth_required` signal. Tool and workspace request failures retain their existing classification. - No database migration or provider credential format changes are required. ## Model Used - OpenAI GPT-6 through Codex. The exact served model identifier and context window are not exposed in this session. Capabilities used: reasoning, repository tools, code editing, and command execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
1 parent
408f70e69f
commit
e00d10d5d5
16 files changed
+407
-52
No files matched your search
@@ -59,6 +59,16 @@ The additive `ai_provider_defaults` table preserves the legacy per-method prefer
|
||||
Revocation retains the unavailable default; connecting another account does not
|
||||
silently replace it. Change it explicitly on the account detail page.
|
||||
|
||||
Agent settings offer **Reconnect account** when the current personal default
|
||||
needs attention. This repairs the same connection and keeps its default and
|
||||
agent access. **Connect another account** states that the new account will
|
||||
become the user's provider default. It selects the returned grant before
|
||||
adopting the binding and retains the actual sign-in method. A failed default
|
||||
update stays visible and can be retried without another login. New account
|
||||
setup shows an agent-access checkbox, enabled for all company agents by default
|
||||
for connection managers. The owner can limit access to the current agent. This access applies only to
|
||||
the owner's tasks. Reconnect never expands existing access.
|
||||
|
||||
## Storage and API
|
||||
|
||||
AI connections pair `connectionPurpose: ai` with `transport: runtime_auth`.
|
||||
@@ -77,8 +87,10 @@ and authentication paths are never account labels.
|
||||
|
||||
Company-scoped `/api/companies/:companyId/ai-connections` operations provide list,
|
||||
API-key creation/reconnect, personal defaults, completed login references, and
|
||||
active-run attribution. Existing Connections operations handle naming, access,
|
||||
and revocation. Mutation authorization is enforced server-side. OpenAPI documents the new board-only
|
||||
active-run attribution. The list includes `canManageConnections`, evaluated by
|
||||
the same server permission check as creation, including custom
|
||||
`tools:manage_connections` grants. Existing Connections operations handle naming,
|
||||
access, and revocation. Mutation authorization is enforced server-side. OpenAPI documents the new board-only
|
||||
operations. Agent-originated configuration and environment tests resolve the
|
||||
authenticated request’s responsible user; an agent ID is never a personal-account
|
||||
owner. A missing responsible identity blocks personal-default resolution.
|
||||
@@ -137,6 +149,13 @@ run results or logs. A historical generic terminal-limit message alone does not
|
||||
establish quota exhaustion.
|
||||
|
||||
`prepareManagedAiRuntime` is shared by runs, environment tests, and adoption.
|
||||
Test and Save mark the tested account as needing attention when its provider
|
||||
hello test rejects authentication or its API-key check returns 401 or 403.
|
||||
Network, quota, runtime, and environment failures
|
||||
do not change credential health. The same generation check protects a newer
|
||||
reconnect from a late test result. Claude ACP's typed `access` failure is its
|
||||
provider `auth_required` signal and enters the existing sign-in recovery path,
|
||||
including when only the generic terminal-access fallback message is available.
|
||||
Claude ACP validates working directories on the selected execution target. A
|
||||
sandbox directory does not need to exist on the Paperclip server. When the agent
|
||||
has no configured directory, the test uses the remote target's working directory.
|
||||
|
||||
Reference in new issue
Block a user