2053 Commits
Author SHA1 Message Date
DottaandPaperclip 9f7057e122 feat(connections): configure custom model providers across agent harnesses (#14970)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents use a harness, a model, and a credential to run tasks.
> - Connections already store credentials and control who can use them.
> - Custom providers also need an endpoint and a supported API format.
> - A per-agent endpoint would duplicate credentials and access rules.
> - This pull request stores routing on the connection and projects it
into the harness.
> - Isolated credentials and protocol checks keep the selected
connection authoritative.

## Linked Issues or Issue Description

Refs #37, #13083, #14104, #14565, #12692.

#14016 is a reference only. This PR has its own schema, vault
persistence, routing validation, runtime projection, and tests. None of
the five commits in #14016 is an ancestor of this branch. We do not
depend on or plan to merge it. #14967 addresses task-pinned account
pools. #14422 addresses another provider integration.

This is the first of two linked PRs. Merge this connection change before
#15341, which refines agent setup and adds the qualification harness.
The split keeps each review below 100 changed files. Provider catalog
entries have usable setup forms in this PR. Local browser subscription
sign-in is included.

## What Changed

- Store non-secret routing metadata on AI connections. Vault provider
API keys, including Bedrock bearer API keys. Reject general AWS access
keys.
- Enforce company, owner, human audience, agent access, connection
status, and protocol checks before resolving credentials. Keep reconnect
destinations immutable and retain connection identity during key
rotation.
- Project OpenRouter and compatible custom endpoints into Codex, Claude,
OpenCode, and local Hermes. Carry these settings through both legacy and
native runner transports. Clear conflicting host credentials and redact
keys from diagnostics.
- Preserve older OpenRouter accounts and native personal defaults. Add
Google API-key accounts and migration `0306` for the two
provider-default constraints.
- Run local Claude and Codex subscription sign-in behind the existing
browser sign-in card. Use private attempt homes and owner-bound
completion instead of a copied terminal command.
- Seed isolated Gemini authentication and preserve OpenCode workspace
permissions. Keep the selected connection authoritative. The independent
Gemini and Grok workflow fixes are in #15341.
- Keep native OpenCode custom gateway keys in a runner-owned
selected-model proxy; the harness config contains only a session-scoped
capability. Honor runtime outgoing proxy and certificate settings.
Preserve streamed responses and revoke the proxy on close or startup
failure.
- Allow ordinary members to connect native personal accounts before an
agent exists.
- Repair routed accounts from task cards using the saved provider
destination, protocol, model aliases, and connection identity.
- Add provider catalog definitions, model discovery, pinned logos, and
complete native and routed setup forms. Allow a personal routed
connection before a new agent exists. Keep endpoint authentication keys
out of Hermes terminal children.
- Recover cancelled or restarted browser sign-in with a clear restart
action. Support no-auth endpoints without a vault credential. Add
isolation and recovery regressions and runtime documentation.

## Verification

- Updated with `origin/master` at `22a3ea341`. Migration `0306` follows
the new master migration and passes migration and snapshot checks.
- The integrated connection regressions passed 152 tests and 50 native
OpenCode driver tests, including key-free child-shell configuration
reads, authenticated/no-auth forwarding, streaming, model/path
restrictions, cancellation, outgoing proxy routing, and NO_PROXY bypass.
Provider setup has 14 passing tests. The pinned real OpenCode 1.18.34
executable also completed a turn through the proxy against a local
synthetic provider; the reusable key was absent from its config. A
second real-executable smoke passed with an HTTPS CONNECT proxy and
runtime-specific synthetic certificate trust. Certificate-file and
certificate-directory regressions pass.
- Task-card repair passed 48 tests, including OpenRouter, Bedrock, and
custom gateway reconnect cases. UI typecheck and token gates passed.
- The prior core regression set passed 133 tests across new-agent setup,
provider forms, browser sign-in, routing projection, and connection
authorization. Token gates and UI typecheck passed.
- Full workspace typecheck and production build passed again after the
latest integration and credential-proxy fix. The merged deterministic
runner E2E suite passed 1,400 Vitest tests and 128 Node tests.
- Full workspace typecheck passed on the prior linked combined
implementation. Production build, Storybook build, 1,316 browser-harness
Vitest tests, and 128 Node tests passed. Head `9d964c8d9` includes the
latest master integration and regenerated migration. This exact head
passed 54 remote checks with four expected skips and Greptile 5/5; no
review threads remain open. An unchanged server fixture had a random
six-character issue-prefix collision on its first attempt. All 245 tests
passed locally and the single CI retry passed.
- A provider-free terminal check used the cited supported Hermes source
and dummy keys. Gateway and OpenRouter terminal children could not read
the selected key.
- The broad local Vitest attempt passed 15,442 tests but was not green.
It had an embedded-Postgres startup failure, an HTTP logger timeout, an
origin socket error, and a browser cancellation wait timeout. The
cancellation wait was corrected. The relevant connection tests and the
full origin test file passed separately. Latest-head CI must pass before
merge.
- Prior credential-backed acceptance exercised task creation, tool use,
artifact delivery, completion, and context-dependent follow-up. Claude
legacy and native runners passed Bedrock with `us-east-1` and
`us.anthropic.claude-sonnet-4-6`.
- Historical local qualification retained 43 passing API/gateway cells
out of 46. Those attempts span earlier builds. They do not qualify this
exact commit or staging. All subscription combinations and staging
remain unqualified.
- Verify native subscription and API-key setup. Connect a regular
provider catalog row. Verify an incompatible harness and a changed
reconnect URL are rejected. Use #15341 for the complete browser
campaign.

## Risks

- Migration `0306` changes two check constraints. It preserves rows and
is safe to reapply. It takes normal constraint-change locks.
- Credential projection touches several harnesses. CLI upgrades can
change provider configuration and session behavior.
- The native OpenCode proxy adds a loopback hop, pins requests to the
selected model, limits request bodies to 16 MiB, rejects redirects, and
expires at session close. It prevents reusable keys in the child
configuration; it is not an OS isolation boundary against a process
debugger running as the same user.
- Custom endpoints must be reachable from the agent environment. Saving
a connection does not prove connectivity. Bedrock keys require rotation
before expiry.
- Gemini CLI 0.58.0 has an upstream ACP new-file error conversion
defect. Provider overloads and an unresolved follow-up timeout also
affect live Gemini qualification. We have not patched the installed CLI
or marked those cases as passing.
- OpenClaw Gateway, Hermes Gateway, Claude Managed, AWS AgentCore,
Process, HTTP, and legacy ACPX local are excluded. Vertex, ambient AWS
identity, arbitrary auth headers, and custom routing for other harnesses
are excluded.
- These PRs do not establish production or staging qualification for
every provider and login method.

## Model Used

OpenAI GPT-6 through Codex, with reasoning, repository tools, code
execution, and browser testing. The exact deployment model ID and
context window size were not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-06 13:29:03 -05:00
DottaandPaperclip 22a3ea3414 Invite assistants from Connections with scoped browser and device consent (#14933)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Public MCP lets people use their organization from an external
assistant.
> - Operators need a visible control for this experimental access.
> - Hosted users should select an organization once and then approve its
permissions.
> - This pull request adds the setting, invitation-first setup, and
browser or device consent.
> - Connections provides a copyable invitation with public instructions
that grant no access.
> - Users reach browser consent from their assistant and return to
inspect or revoke access.

## Linked Issues or Issue Description

Builds on merged foundation #14846. This PR now targets master. Related
settings convention: #13905.

**Current behavior**

The preview uses an environment variable to enable MCP. Hosted consent
repeats organization selection. Assistant access has no entry in
Connections, so users must already know the endpoint and how to reach
consent.

**Proposed behavior**

An administrator enables Settings → Experimental → Assistant connections
(MCP). A hosted connection shows the selected organization and its icon,
then asks for permissions. Requested write access starts checked when
the user’s role permits it; the user can opt out before connecting.
Direct instance connections show an organization picker with the first
available organization selected. The selection stays fixed across
refetches and still requires an explicit Connect action. Connections
includes Assistant Connection (MCP). Its setup page explains the
canonical endpoint, client configuration, browser authentication, and
connected access. It connects as the current person and does not select
or impersonate an agent.

**Reason and benefit**

Operators manage access with the other experiments. Users select one
organization, and both the UI and server enforce that choice.

**Breaking changes**

The old enable variable has no effect. Preview operators must enable the
setting once. Apply the additive consent-request migration before
deploying the tenant, then deploy the compatible Cloud broker. Existing
direct requests and grants keep their behavior.

## What Changed

- Simplify OAuth and device consent: show the Paperclip logo beside
“Connect {client} to Paperclip”, fall back to “your assistant”, and show
the identifying origin plus its favicon below, with the callback URL
also visible when different. Remove the hosted-organization creation
action. Default to the first available organization without silently
changing it on refetch; preserve company restrictions and write
opt-outs. Keep the button row contained on narrow screens.
- Make Copy invitation the primary action, using the shared animated
AgentSetupPrompt and a collapsed manual setup section with icon-labeled
line tabs. Remove redundant link actions, copy-status text, the extra
first-prompt well and revocation explanation from the setup page. Serve
shared version-aware HTML and Markdown instructions without private
organization data.
- Support guarded Client ID Metadata Documents alongside dynamic
registration, and include authorization response issuer identification.
- Add RFC 8628 device authorization with separately hashed codes,
expiry, shared request quotas, persistent polling backoff and atomic
redemption. Reuse human consent, role checks, scoped grants, audit and
revocation.
- Add CLI device login and a local stdio bridge. Store credentials
separately with private permissions and serialize rotating refreshes.
- Add device consent stories and five cold-start paid Product E2E cases
with independent grant, configuration and durable-work assertions.

- Add `enablePublicMcp` to the settings validator, normalizer, feature
catalog, and toggle UI. Check it live for OAuth, tools, subscriptions,
and event delivery. Keep connection management and revocation available
while disabled.
- Default the MCP origin to the existing auth public URL, with strict
validation and an explicit override.
- Persist the optional OAuth `company_id` restriction. Describe only
that company and reject approval for any other company, even if the
person belongs to both. Keep active-membership and role checks.
- Show the Paperclip icon and a large organization icon during consent.
Return the saved company logo through the company-scoped request
response and reuse the standard fallback icon. Use the requested concise
permission labels: “Read all of your Paperclip data” and “Allow write
access and creating tasks as me”. Use concise permission copy, retain a
compact client and callback-origin disclosure, and remove the footer
link.
- Default requested write access on for eligible roles. Preserve opt-out
across organization changes and refetch, reset defaults for a new
request, and submit read-only access when the request or role does not
allow writes. Align the shared checkbox with its label.
- Use organization wording in consent, management, settings, and
walkthroughs. Keep the organization fixed for hosted requests and retain
direct-instance choice.
- Add an Assistant Connection (MCP) card to the Connectors catalog, a
setup page in the app shell, and a return link from Experimental
settings. Include Codex, Claude Code, OpenCode, and generic remote MCP
instructions.
- Read the live gate and canonical server URL through authenticated
setup metadata. Show only the current person’s grants for the selected
organization, refresh after consent, and support revocation. Surface
catalog status failures with an explicit retry action; do not present
them as an empty connection list. Opening setup grants no authority.
- Start the eight guided chapters in Connections. Keep presenter notes
and chapter controls around real product pages in the app shell. Explain
the terminal, consent, delegation, retrieval, and revocation handoffs.
Mark conversation examples as illustrative. Cover first use, client
setup, connected, loading, and error states. Keep the existing consent
and management stories.
- Keep the paid-eval setup and browser helper aligned with the setting
and consent button.

## Verification

- Warm-standby integration fix `ec64ea05e`: public MCP ingress now
follows the Cloud claim guard; MCP and discovery paths return 503
instead of SPA HTML while unclaimed. Event polling checks the in-memory
claim before reading the persisted experimental setting. All 97 focused
OAuth/Cloud tests and server typecheck pass, including new request and
timer regressions for idle-before-claim and resume-after-claim behavior.
Fresh review is 5/5 with no unresolved threads, and all security scans
pass on this final head. All browser shards, typecheck, build, canary
installation and other test groups passed on the first attempt. The
unchanged Cursor sandbox default-command test timed out at 10 seconds;
the exact test passed locally without edits in 587 ms. The single
failed-job retry passed, with the original failure retained in workflow
37500711895. All 54 final-head checks pass on
`ec64ea05e9a03e2179d4e2f84c2de03761f7ce26` (two optional Storybook jobs
are intentionally skipped).

- Final master integration `8457828fc`: merged foundation #14846 and
current master, preserving the invitation changes and all 33 files from
the two newer upstream changes. No migration renumbering was required.
All 95 focused OAuth/Cloud integration tests, full recursive typecheck
and token gates pass. All CI gates passed on that integration head;
review identified the warm-standby issue fixed above.

- Security-review fix `8c1d0b696`: commit shared global/per-source
admission before outbound CIMD work, preserve failed-attempt receipts,
and validate resource/scope before fetching. Added migration
`0305_chubby_vin_gonzales.sql` and six concurrent/adversarial regression
cases. All 69 OAuth/metadata tests, 26 migration checks, full recursive
typecheck and production build pass. The security scanner passed that
commit. Follow-up `87f9658e7` limits only actual cache-miss fetches; 18
authorization requests sharing one proxy across two service instances
use just two fetches. All 70 OAuth/metadata tests and server typecheck
pass after that refinement. Final follow-up `8ebeae84c` reports
admission-storage failures as retryable HTTP 503 instead of invalid
client metadata. Its regression proves no outbound request before
admission and successful retry after storage recovers. All 71
OAuth/metadata tests and server typecheck pass. Final-head security
scanning passes; Greptile is 5/5 with no unresolved findings. CI passed
all browser shards, typecheck, build, token gates and canary
installation. One unchanged adapter-utils bridge test raced a
response-file write (expected a JSON error, received the safe
file-changed error). The exact test passed locally without edits. The
single failed-job retry passed; the original failure is retained in
workflow 37490609192. All 54 checks now pass on final head
`8ebeae84ca77c0cf7ac12c2006f0f8743fe50e0b`, with security scan and fresh
Greptile 5/5 and no unresolved threads. Foundation #14846 subsequently
merged as `e34abee670069cca84afb2efb86041bce7dccbec`; the final
integration above now targets master.

- Integration with current master: preserved the new Connections source
filters and pagination, kept all eval suites, and regenerated the
consent/device snapshots as migrations 0303/0304. All four MCP migration
SQL hashes are unchanged from the staging versions. Full recursive
typecheck and production build, 132 focused UI tests (including catalog
filtering), 89 server authorization/settings tests, 26 migration tests,
120 eval calibration tests and token gates pass. Review follow-up
`4820ce74c` also keeps active assistant grants in Installed, with
pending/error recovery and revocation/company-isolation coverage. All 76
setup/catalog tests, UI typecheck and token gates pass after that fix.
The unchanged signoff browser test timed out waiting for a heartbeat in
CI at `4820ce74c`; the exact test passed locally without code changes,
and the preceding CI head passed that shard. That same unchanged test
failed at the reviewer stage in the next CI run. All five signoff tests
passed three times locally (15/15), without test changes. All eight
browser shards pass at final head `8ebeae84c`; no browser-test edits or
failed-browser-job retries were needed.

- Setup-page refinement at `9ab009178`: all 17 focused setup/consent
tests pass, along with UI typecheck, production build, Storybook build
and token gates. Browser exercised the shared prompt preview and client
tab switching, and the updated InvitationCopied Storybook interaction
checks its clipboard fixture. All final-head CI checks pass at
`9ab009178`, with no unresolved review findings. Deployed successfully
to Butter in
https://github.com/paperclipai/paperclip-cloud/actions/runs/37475189524.
Verified the actual page, tab switching and line styling, removed
actions/copy, and successful native copy/paste of the complete Butter
invitation into a local-only test field. The existing Claude grant was
left intact.
- Consent follow-up at `dc8e9fd11`: all 10 consent tests and token gates
pass. UI typecheck and production build passed again at `4e4d5e4d9`;
Storybook build and eval-helper typecheck passed for `28101cf91`.
Follow-ups let the primary button wrap on narrow screens, preserve a
distinct callback URL, and use only bundled icons to avoid pre-consent
requests to client-selected sites. Browser-verified the real consent
component in desktop and 320px mobile stories, including default
selection, write access and preserved opt-out. Updated E2E
heading/default-selection helpers. All CI checks passed at `dc8e9fd11`,
with review 5/5 and no unresolved threads. The Butter preview
publication needed a retry because npm initially accepted the DB package
before making it visible; the retry succeeded and `dc8e9fd11` deployed.
Verified a fresh, unapproved native Codex CIMD request on Butter:
default organization/write selection, known-client heading and icon,
distinct callback origin, and removed creation action. No grant was
approved for this UI check. Prior paid runs below retain their exact
source provenance; this UI-only follow-up did not rerun paid
qualification.
- Source-pinned paid matrix at
`2992ef2710f47230e7f484c709c6ba02524f884c`: **15/15 passed**, five cases
each on GPT-5.4 Mini, Claude Haiku and Sonnet. Campaign
`local-2026-10-06T02-41-14-462Z`. Covers cold start, existing config,
unavailable host, denied consent and reconnect/later retrieval, with
independent configuration/grant/task/run/document assertions. Original
failures, transcripts, source fingerprints and billing remain retained.
- Final instruction follow-up `cda8178af`: **3/3 cold starts passed** on
Mini, Haiku and Sonnet. Campaign `local-2026-10-06T02-58-30-041Z`.
Latest `0637b9f1c` shares that same guidance across HTML, Markdown and
manual UI after review; generated Markdown is verified byte-identical to
the paid-evaluated version. Shared build, server/UI typechecks, token
gates and 63 auth/metadata tests passed again. Every CI gate passed at
prior HEAD `0637b9f1c`, with review 5/5 and no unresolved threads.
- Other focused checks: 11 CLI credential/refresh-lock tests, 120 eval
calibration tests, server/UI/eval typechecks, token gates and Storybook
build passed. Full recursive typecheck and production build passed
during implementation; CI also passed them at `2992ef271`.
- Local full-suite limitations: a large-file Git streaming test times
out on this Mac, and broader CLI/route runs hit DB hook timeouts. Fresh
MCP reruns passed, and the corresponding CI groups passed. No claim that
the local full suite is green.
- Actual clients: Codex 0.153.4 and Claude Code 2.1.245 reach CIMD
consent; device CLI reaches verification/consent. New grants await human
approval. Existing local OpenCode retrieved a saved result in a fresh
conversation through its previously approved grant.
- Fresh OpenCode 1.18.17 on Butter: started with no MCP config, received
the exact copied invitation, read public setup, configured its server
and started PKCE consent. Its shell command timed out; background retry
reached the client's own callback deadline while approval remained
pending. Latest instructions cover that handoff. **No completed Butter
read/delegation/result retrieval is claimed.**
- Cloud companion
https://github.com/paperclipai/paperclip-cloud/pull/672 passes
checks/review and deployed. Anonymous setup and device-protocol routing
verified. Core `2992ef271` deployed successfully and the actual Claude
web flow now reaches consent. Its extra JWT-bearer metadata is filtered
to implemented grants; unsupported token grants remain rejected. Final
`0637b9f1c` deployed successfully to Butter in
https://github.com/paperclipai/paperclip-cloud/actions/runs/37409195300;
live HTML and Markdown both contain the final guidance. The superseded
instruction-only build was canceled before deployment. This is a
core-only staging preview; private Cloud plugins are omitted. ChatGPT
web is signed out, so browser connector use is unverified.
- Screenshot gallery begins at Butter's dashboard and distinguishes real
setup/pending consent from local reuse and fixtures. It records the
timeout finding. New persistent access needs human confirmation before
the remaining actual-client acceptance work.
- Manual path: Connectors → Assistant Connection (MCP) → Copy invitation
→ paste into assistant → configure and start authorization → sign in and
approve → verify `paperclip_connection` → delegate → retrieve the saved
report later.
- Plan and instructions: `doc/plans/2026-10-05-assistant-invitations.md`
and `doc/public-mcp.md`.

## Risks

- Apply additive, replay-safe migration `0304_curvy_shadow_king.sql`
before using device authorization. The public setup link carries no
credential. Device codes and tokens stay private; neither sharing
instructions nor installing a plugin authorizes access.
- Apply additive migration `0305_chubby_vin_gonzales.sql` before
deploying the shared metadata admission gate. It retains at most 60
short-lived, hashed-source receipts per instance and rejects excess
attempts with 429.
- CIMD metadata fetching is a new external-input boundary. It requires
HTTPS, exact client ID and redirect validation, bounded responses and
guarded DNS/network access. Client names remain self-reported.
- Device support is per-instance. The central Cloud broker retains its
existing grant support. Host installation and tool reload capabilities
vary by client; instructions describe manual settings and restart
requirements.

- Consent names the registered client in its heading and displays its
identifying origin below. Known-origin icons are bundled; all other
origins show a neutral site icon without contacting client-selected
sites. Client names are self-reported; the callback origin is the
recipient check. The Cloud chooser also displays the original client and
receiving origin before tenant handoff.

- A user who accepts the preselected write permission can create tasks
and comments. Task creation and comments can start or wake agents and
use execution budget; the consent label uses the concise wording
explicitly requested by the maintainer. Scope requests, role checks, and
the final Connect action still apply.
- Migration `0303_supreme_garia.sql` adds one nullable UUID column with
`IF NOT EXISTS`. Requests without a company restriction keep the
direct-instance picker. The binding stays recorded if its company is
deleted; consent then fails closed.
- Deploy tenant support before the Cloud broker sends `company_id`.
Unknown or inaccessible organizations must never fall back to a
different company.
- The setting defaults off. Disabling access does not cancel work
already delegated. Existing tokens and unexpired subscriptions can
resume when enabled again; revocation remains separate.
- The catalog entry is visible for discovery while the feature is off.
Setup instructions, OAuth, and tool execution remain gated. No access is
granted by viewing the entry.
- Assistant sign-in starts in the external client so it owns PKCE and
callback state. Client command syntax can change and links to official
setup documentation are included.
- An authenticated instance and valid public URL are required. Hosting,
paid execution, and store publication remain separate rollout steps.

## Model Used

OpenAI GPT-6 in Codex, with tool use and code execution. The exact
serving model version and context window are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused checks pass;
unrelated local full-suite timeouts are explicitly recorded above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-06 12:35:16 -05:00
DottaandPaperclip e34abee670 feat(mcp): connect assistants to a team with user OAuth (#14846)
## Thinking Path

> - Paperclip gives teams durable tasks, agent execution, budgets, and
approvals.
> - People also use assistants in Codex, Claude, and other MCP clients.
> - Those assistants need a scoped connection that preserves the
person’s permissions and attribution.
> - Delegating a task must not turn the assistant into the assigned
agent.
> - This PR adds opt-in user OAuth, ten first-party tools, browser
consent, and workflow packages.
> - Paid product evals verify the resulting tasks, documents,
attribution, retries, and access boundaries.
> - The team keeps working after the assistant conversation ends.

## Linked Issues or Issue Description

**Problem or motivation**

A person cannot connect an external assistant to an existing team
through browser consent and safely delegate durable work as themselves.

**Proposed solution**

Expose an opt-in `/mcp/paperclip` endpoint with individually described
first-party operations. Bind every connection to a person, client,
company, resource, and scopes. Reuse domain authorization and
scheduling. Package shared team-review, delegation, and follow-up
workflows for OpenAI/Codex and Claude.

**Alternatives considered**

Related PRs #9393 and #12549 cover earlier remote MCP and board-operator
approaches. This change uses user OAuth and a bounded public catalog. It
does not expose a generic executor, operator administration, static
shared board credentials, or external agent execution. Registry listing
work in #9851 is a separate distribution step.

**Roadmap alignment**

This maintainer-requested implementation extends the governed MCP
gateway, activity attribution, durable work products, and hosted
deployment direction in `ROADMAP.md`. It implements the first release of
the saved design plan; external agent participation and granted
third-party tools remain later releases.

## What Changed

- Add MCP 2.0 discovery and task status/comment/document Events on the
same authenticated endpoint. Persist subscriptions and delivery
receipts, verify HTTPS callbacks, sign Standard Webhooks, encrypt
callback material, recheck permissions/Cloud membership, and bound
retries/expiry. Older MCP clients keep their existing tools.
- Add discovery, dynamic client registration, S256 PKCE, resource
validation, rotating refresh tokens, revocation, and company consent.
Store credentials as hashes and recheck membership at execution.
- Add tools for connection identity, agents/projects, task
search/read/create, human comments, documents/deliverables, and
pending-approval links. Preserve current domain permissions and
scheduling.
- Add durable mutation receipts across reconnects. Matching retries
replay results; uncertain outcomes keep the same request ID and require
inspection.
- Add consent and connection-management pages, OAuth log redaction,
shared plugin workflows, and separate OpenAI/Codex and Claude package
outputs.
- Add eight paid Product E2E cases across three models, independent
durable-state grading, usage evidence, cleanup, and report integration.
Add task-document guidance and regenerate the runner capability
inventories.
- Add migrations 0301 and 0302, the dated implementation plan, result
notes, and direct-client setup instructions in `doc/public-mcp.md`.

## Verification

- Merge integration `e180b1948`: resolved conflicts with current master,
preserved both eval registries, regenerated capability catalogs, and
regenerated migrations as 0301/0302 while keeping the original
replay-safe SQL byte-identical. Local migration safety/snapshot tests
(26), MCP/OAuth tests (38), redaction/OpenAPI tests (71), and eval
catalog/grading tests (198) pass. Token and capability gates pass. Full
recursive typecheck passed. Fresh Greptile review is 5/5 with no
unresolved findings. CI is green on this exact head (55 successes, two
intentional skips, one neutral result): one unchanged Cursor sandbox
test timed out at 10 seconds, then passed locally in 856 ms. A single
retry of that failed shard and the aggregate workflow passed. Merge
remains blocked on the repository code-owner approval rule.

Earlier checks passed at `6aa0962d4fb715f2190bb7bb22efacab2e58495d`: 55
successes, two intentional skips and one neutral result. [The earlier CI
run](https://github.com/paperclipai/paperclip/actions/runs/36901592350)
includes all test shards, browser tests, typecheck, build and canary dry
run. Greptile was 5/5 on that commit with no unresolved review threads.
GitHub still requires code-owner review under the repository merge
rules; passing checks do not bypass that approval. Paid source
fingerprints remain separate below and in the dated result note.

- Paid Events qualification passes **3/3**: GPT-5.4 Mini, Claude Haiku
4.5 and Claude Sonnet 4.6. Each uses a real public HTTPS callback,
signature verification and report retrieval in a fresh conversation. A
final Mini regression passes after the quota/status fixes. All evidence
validates. Bounded tunnel startup retries occur before provider calls
and remain visible; failed earlier attempts retain their original
grades.
- The earlier complete seven-case matrix passes **21/21**, with a
separate **3/3** delegation regression. Two preceding matrices also
passed 21/21 each. A complete 24-cell matrix including Events has not
been run. [The dated
results](doc/plans/2026-10-01-public-mcp-paid-eval-results.md) retain
exact source fingerprints, failures, model IDs and partial costs.
- Node 24: repository-wide `pnpm -r typecheck` and `pnpm build` pass
after merging master. Server typecheck passes after the final
quota/status changes. Eval typecheck and all 892 eval-support tests
pass.
- All 33 real MCP/OAuth tests pass. The preceding combined MCP,
redaction, private-address and DNS-rebinding run passed 129 tests; two
later MCP regressions cover quota reuse and unchanged-status
suppression. All 28 adjacent issue-tree/stale-lock route tests pass. CI
then found a null checkout result in the existing concurrent-workspace
path; logging now uses optional status access. All 12 closed-workspace
tests and all 33 MCP tests pass after that correction. The exact-start
event calibration exposed a timestamp gap; scanning now includes the
subscription start, with all 33 MCP tests and server typecheck passing.
These two narrow corrections follow the paid regression.
- A real Core → Cloud → Core authority round trip passes OAuth, MCP 2.0
subscription/delivery, current membership loss, unsubscribe, legacy SDK
tools, refresh and revocation. Its callback transport is a fixture with
independent HMAC verification. The paid Events campaigns separately
prove public HTTPS delivery.
- Earlier component qualification passed UI 7,117 tests, CLI 502, shared
832, skills catalog 20, database 160 and OpenAPI 10. Token gates, module
boundaries, migration order and plugin regeneration passed. CI covers
general/serialized suites, eight browser shards, runner checks,
typecheck, build and canary dry run.
- **Local full-suite limitation:** the earlier monolithic run was not
clean. It encountered overlapping schema rebuilding, Mac database
shared-memory limits and isolated CLI/fixture failures. Targeted reruns
passed. The existing >32 MiB Git filename stress test still hit its
300-second Mac timeout. The additional serialized sweep stopped after 62
passing suites once CI passed. Original failures and partial logs
remain; this PR does not claim a wholly green local monolithic run.
- Local Codex CLI and Claude Code OAuth login and MCP SDK
interoperability were verified. Public-store installation, actual
ChatGPT Work Cloud Events UI, staging HTTPS client behavior and hosted
newcomer provisioning remain release gates.

Enablement is moving to **Settings → Experimental → Assistant
connections (MCP)** in the stacked follow-up
[#14933](https://github.com/paperclipai/paperclip/pull/14933). Merge
both for the intended setup experience. This foundation branch alone
still uses `PAPERCLIP_PUBLIC_MCP_ENABLED=true`. After deployment, set
`PAPERCLIP_PUBLIC_URL` to the authenticated instance's HTTPS origin, and
connect to `/mcp/paperclip`. Select a team and allow writes in browser
consent. Configure an available agent and budget, then delegate and
retrieve results later. For Events, rescan the deployed plugin catalog
in ChatGPT Work Cloud; the host supplies its webhook credentials when
the user asks to watch a task. See [the setup
runbook](doc/public-mcp.md).

## Risks

- Events are at-least-once and may arrive out of order. No replay cursor
is advertised. Clients must refresh finite subscriptions, read current
state and avoid comment feedback loops. Callback material uses the
instance secrets master key; hosted subscriptions require the updated
Cloud broker and are bounded to five minutes/the access proof expiry.
- ChatGPT Work Cloud/dot event UI, plugin rescan and a hosted staging
subscription remain deployment gates. Local signed-webhook and paid
model evidence does not claim those surfaces have been exercised.
- Disabled by default. Merging adds schema and opt-in code; it does not
deploy a public endpoint, publish a store listing, create a team, or
start paid agents.
- Migrations 0301 and 0302 are additive and idempotent. Their SQL is
unchanged from the earlier preview numbers, so hash-aware upgrade
reconciliation preserves prior staging applications. Normal instance
upgrades must apply it before enabling MCP.
- Task creation and comments can schedule paid agent work. Consent and
tool descriptions disclose that effect. Revocation blocks future calls
but does not undo delegated work.
- Public deployments need edge rate limits and credential-safe logging.
Internal dispatch is restricted to the closed catalog and carries a
request-local verified actor.
- Hosted onboarding requires the companion Cloud broker, encryption-key
configuration, and tenant rollout. Self-hosted direct connections can
use this PR alone.
- Store acceptance and agent-mode participation are not claimed.
Checked-in plugin endpoints are development defaults; rebuild packages
for a real deployment before installation.

## Model Used

OpenAI GPT-6 in Codex, with reasoning, tool use, and code execution. A
more specific serving version and context-window size were not exposed
by the session. Paid eval models: `gpt-5.4-mini-2026-03-17`,
`claude-haiku-4-5-20251001`, and `claude-sonnet-4-6`.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (targeted/component checks;
full local-run limitations are recorded above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-06 11:48:53 -05:00
Devin FoleyandPaperclip 202c2d307e fix(server): leave unclaimed warm Cloud databases idle (#15314)
## Thinking Path

> - Paperclip manages work performed by AI agents.
> - Managed deployments prepare empty applications before an owner
claims them.
> - Those applications start database pollers even though no company can
have work.
> - Health probes also query SQL, so idle databases cannot remain
suspended.
> - This pull request adds an explicit standby marker for empty,
unclaimed Cloud apps.
> - The existing signed, durable claim resumes normal processing without
restarting the app.

## Linked Issues or Issue Description

**What happened?**

An empty, unclaimed warm application runs recurring chat, email, plugin,
heartbeat, cleanup, and reconciliation queries. Its health route also
opens the database. This prevents idle database compute from suspending.

**Expected behavior**

An explicitly marked unclaimed application should keep its HTTP process
and sandbox provider plugins ready while leaving the database idle. A
successful signed claim should resume normal API behavior and background
processing. Claimed and self-hosted instances should keep their current
behavior.

**Steps to reproduce**

Start an empty Cloud-managed application and leave it unclaimed. Observe
database activity while repeatedly requesting `/api/health`. Before this
change, periodic queries continue without company data.

Related: #15153 reduces allocation during chat polling. This change
suppresses polling only for explicitly marked, empty, unclaimed Cloud
apps.

## What Changed

- Add `PAPERCLIP_CLOUD_WARM_STANDBY=1`. Check company emptiness once
after restoring the persisted Cloud runtime identity. Missing Cloud
configuration, existing data, or a persisted claim leaves normal
processing active.
- Gate recurring database pollers with an in-memory predicate. Keep
startup preparation and sandbox provider plugin loading intact.
- Serve unclaimed health probes without session or database reads and
report `warmStandby: true`. Serve standby pages/assets directly from the
UI router, bypassing session, bearer, tenant, and dynamic handlers.
Refuse API requests and all WebSocket upgrades before authentication can
query SQL or seed company data.
- Exit standby after the existing signed identity assertion commits.
Normal timers resume at their next tick; a restart restores the claim
even with stale provider variables.
- Document the marker, readiness semantics, rollout checks, and
rollback.

## Verification

- `pnpm -r typecheck` passed. A final server typecheck also passed after
adding tests.
- `pnpm build` passed.
- Focused standby, signed claim, restart, health, static/Vite routing,
hostname, HMR, and live-events suites: 72 passed after the review fixes.
Includes real HTTP upgrade admission before/after claim.
- `pnpm test:run` was attempted locally; both superseded runs were
stopped after encountering checkout/platform failures. A clean-checkout
rerun eliminated ancestor skill-directory lookup failures. The
company-skills/runtime-cache families encounter macOS
read-only-directory rename failures (`EACCES`); all three company-skills
failures reproduce on unmodified base `bf14f803d5`. The initial full run
also reported one native runner API test failure; an isolated comparison
on both revisions was blocked by local embedded PostgreSQL startup
failures. The full [Linux CI
run](https://github.com/paperclipai/paperclip/actions/runs/37423263993)
passed on final commit `5016c415ea`, including all server and workspace
test shards, browser suites, typecheck, build, and release canary. This
is not a claim that the full local suite passed.
- Isolated full server with local PostgreSQL: after startup and
connection expiry, 70 health probes, 70 page requests carrying valid
synthetic tenant credentials, and 70 rejected WebSocket upgrades over 70
seconds observed zero app database connections. The signed claim
completed in 62 ms and normal polling resumed (475 database transactions
over 12 seconds). Restart with stale provider variables restored the
durable claim. The latency is local-only, not a provider wake
measurement.
- Apex review: **5/5** on `5016c415ea`, both earlier threads resolved,
no open recommendations.
- No live-provider test or production deployment was performed. An
actual database suspension/resume canary remains required before
enabling the control-plane switch.

## Risks

- Standby health reports HTTP readiness rather than current database
connectivity. The signed claim still requires a durable database write;
claimed health checks retain the SQL probe and 503 failure behavior.
- Pollers resume at their usual intervals. A suspended database may add
claim latency. Validate the real provider before enabling the marker.
- Startup preparation and sandbox plugins remain loaded. New plugins or
background loops must respect the same standby contract.
- The marker is off by default. Remove it or set it to `0` and restart
to roll back. No schema migration or claimed-workspace inactivity policy
changes.

## Model Used

OpenAI Codex, based on GPT-6. The exact serving snapshot and configured
context-window size are not exposed in this session. Assistance included
source review, TypeScript changes, command execution, and PostgreSQL
tests.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass — targeted tests pass; full
local suite limitations are documented above, and full Linux CI is green
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-06 09:11:25 -07:00
DottaandPaperclip f2715e02bb fix(native): surface model capacity errors and retry automatically (#15347)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Native runs preserve provider events and results, then decide task
state.
> - Codex can fail a turn because the selected model is temporarily at
capacity.
> - Paperclip displayed a generic native-session failure and left the
task in recovery.
> - A known capacity failure needs a clear message and a durable delayed
retry.
> - This pull request uses committed terminal evidence, the
status-effect ledger, and existing dispatch gates.
> - The task can continue automatically without an unbounded retry loop
or a model switch.

## Linked Issues or Issue Description

Related: #13993 adds launcher capacity deferrals before provider
startup. This change handles a committed native Codex `serverOverloaded`
terminal after provider work has started.

**What happened?**
A native Codex turn ended with `codexErrorInfo: serverOverloaded` and
“Selected model is at capacity. Please try a different model.” Paperclip
saved the result, showed a generic failure, and required recovery
instead of waiting and retrying.

**Expected behavior**
Show the capacity error directly. Schedule bounded retries after a short
delay. Preserve saved work and honor current execution gates.

**Steps to reproduce**
1. Run a native Codex task.
2. Commit a `turn.failed` event with `serverOverloaded`, then accept a
failed result for the same turn.
3. Inspect the task error and its recovery state. The regression test
reproduces this without a paid provider call.

**Paperclip version or commit**
Reproduced against master `16b7db35ffa0f9a95913c8cbdeea3d595435691f`.

## What Changed

- Classify capacity failures from committed runner events and the pinned
execution identity. Preserve accepted results and display the specific
capacity error.
- Atomically persist one scheduled successor with the status decision.
Retry after one minute, then two minutes. Share the existing failure
budget and stop after two automatic retries.
- Reuse dispatch gates for ownership, task holds, dependencies, budget,
and locks. Wait for predecessor execution, finalization, and cleanup
before claiming a retry.
- Preserve pending reviewer authority and suppress retries after
reassignment or a successor claim.
- Consume the failed run's resume receipt and delivered wake input.
Rebuild ordinary continuation from the failed run so explicitly resumed
tasks can retry without borrowing one-run authorization.
- Label scheduled retries “Model at capacity.” Add a Storybook example
and avoid duplicate punctuation in the existing retry card.
- Add regression coverage and document the runtime contract.

## Verification

- Targeted recovery and UI suites: 125 tests passed. Additional final
cleanup and lock regressions passed.
- Latest-head continuation and authorization regressions: 57 tests
passed, including all four capacity integration tests against an
isolated PostgreSQL database.
- Rechecked all four capacity integration tests with the full runner's
isolated `PAPERCLIP_HOME`, config, temporary directory, and serial fork
settings: passed.
- `pnpm -r typecheck`: passed. Final server typecheck passed.
- `pnpm build`: passed.
- `pnpm check:token-gates`: passed.
- Browser: checked the real Storybook card. It shows the capacity
message, automatic retry time, and existing Retry now action.
- `pnpm test:run`: attempted and restarted after an interruption. The
resumed run started before the final review correction and was stopped
after recorded workspace/native test failures and the five-minute Git
streaming timeout already documented on master. Exit 130; no complete
local full-suite pass is claimed. Current-head isolated capacity tests
and the complete CI suite pass.
- A combined local recovery-suite attempt also hit PostgreSQL
initialization failures at this macOS host's global shared-memory limit
(32 slots). The focused recovery suites passed separately; final-head
capacity tests also pass with the full runner's isolated environment
settings.
- Latest-head GitHub checks: all 56 checks green, including general and
serialized test shards, browser E2E, typecheck, build, Runner
verification, and canary dry run. No merge conflicts.
- Greptile: 5/5 on `813a470b8c18c05aeb7e31e63e573c3a3a2f5cac`, with zero
unresolved findings after fixing the resumed-task continuation issue.

## Risks

- Capacity retries can repeat a task turn after partial work. They start
a fresh provider session with task history and wait for predecessor
cleanup. They do not resume the failed turn.
- Retries retain the configured model unless an operator changes
configuration. Persistent overload consumes the existing failure budget
and then needs an explicit retry or model change.
- Only run-bound native Codex `serverOverloaded` failures qualify.
Usage-limit exhaustion, model/account incompatibility, unbound text, and
unknown provider failures retain their current recovery behavior.
- No schema migration is required.

## Model Used

- OpenAI GPT-6 through Codex. The exact model ID and context-window size
are not exposed to this session. Used reasoning, repository tools, code
execution, and browser verification. No subagents.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-06 10:59:18 -05:00
DottaandPaperclip 9b3fe260ba fix(tasks): surface Codex ChatGPT model rejection (#15299)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for work.
> - Native Runner runs report provider errors and can also save a structured failure result.
> - Codex rejects a model that the user's ChatGPT account cannot use.
> - Master now diagnoses this rejection, but the task's compact run data omits its message. The thread can still call it a generic run failure.
> - Users need the account restriction and a clear step to repair the model selection.
> - This pull request shows the existing diagnosis as “Model unavailable” on the task.

## Linked Issues or Issue Description

**What happened?**

Codex returns HTTP 400 with `invalid_request_error` and the message `The 'gpt-6.1-sol' model is not supported when using Codex with a ChatGPT account.` Master now stores an actionable diagnosis for this rejection. The task thread still labels it “Run failed” and does not receive its error text in compact run data.

**Expected behavior**

Show the account restriction on the task and in the run error. Tell the user to choose a supported model or clear the task's model override before retrying.

**Steps to reproduce**

1. Use a Native Runner Codex agent signed in with a ChatGPT account.
2. Select a model that produces the rejection above and start a task.
3. Let the runner save its generic failed result. Inspect the task's failure marker and recovery notice.

**Additional context**

Refs: #15304. That merged PR diagnoses the provider failure and preserves worker and review recovery rules. This PR adds its task-facing message and guidance without changing that diagnosis or those rules.

Refs: #13134. That PR improves model discovery for ChatGPT accounts. This PR exposes the rejection when a configured model still fails at execution time.

## What Changed

- Return a bounded model rejection message in compact issue-run data.
- Show “Model unavailable” and model-change guidance in the task thread and recovery notice.
- Add database and UI regression tests, including both the original rejection text and master's fixed diagnosis. Document the new failure message.

## Verification

- Focused merged-branch validation: 279 tests passed across activity service, native provider failure observation and PostgreSQL integration, TaskChatThread, and ExecutionBlockerNotice.
- `pnpm -r typecheck`, `pnpm build`, and `pnpm check:token-gates` passed on the merged source tree.
- Greptile reviewed conflict-resolution commit `1db39c4e636a92e2e76ba224b71c6f1e2f556c81` at 5/5 with no findings or inline comments.
- All 55 check runs completed without failure on that commit. The two optional Storybook jobs were skipped. The legacy Snyk status passed. The branch has no merge conflicts.
- UI regression assertion: the task's failure marker says “Model unavailable” and retains the account restriction. It no longer says that this failure happened after a final response.

## Risks

- Provider recognition and recovery are owned by the existing master implementation. This PR exposes only bounded error text for failed runs with `native_provider_model_rejected`.
- Historical runs with the generic `adapter_failed` code are not reclassified. No stored run is rewritten.
- Existing retry and reconciliation gates remain in place. No schema migration or model configuration change is required.

## Model Used

OpenAI Codex, based on GPT-6, with reasoning, code execution, and browser inspection. The exact deployment model ID and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context to this change
- [x] I have specified the model used (with version and capability details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before requesting merge

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-06 08:05:25 -05:00
Devin FoleyandPaperclip 858094ba81 Fix browser polling for unsaved agent chats (#15298)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agent Chat uses the shared task surface and browser panel.
> - An unsaved chat has a temporary ID instead of a stored task UUID.
> - The browser poll sent that ID to a PostgreSQL UUID query and
returned a server error.
> - This pull request waits for a saved task and validates task IDs
before the query.
> - Saved chats keep their browser tools and access checks.

## Linked Issues or Issue Description

Refs #14331. That report describes the same draft-ID problem in email
requests. This change covers the browser routes; it does not change
email behavior.

Opening an unsaved Agent Chat sends `chat:<agent-id>` to
`/issues/:issueId/browsers` every three seconds. PostgreSQL rejects this
as a task UUID. The draft is only a UI view model. The first send or
upload creates its stored task.

## What Changed

- Disable browser polling for unsaved chat IDs. Resume polling when the
chat has a task UUID.
- Return the existing task-not-found response for malformed task IDs
before database access. Keep board authentication first and company and
credential checks unchanged.
- Test all six task browser routes, draft-to-saved polling, normal
tasks, saved chats, and denied access. Keep canonical UUID v4, v7, and
nil values queryable.
- Document the draft and saved-chat browser contract.

## Verification

- `pnpm install --frozen-lockfile` passed with pnpm 9.15.4 and Node
24.21.0.
- `pnpm exec vitest run
server/src/__tests__/browser-use-route-scope.test.ts
server/src/__tests__/browser-use-connection.test.ts` passed all 35
tests.
- `pnpm exec vitest run ui/src/hooks/useTaskBrowsers.test.ts` passed all
5 tests.
- Independent review passed 14 hook and route tests plus both real task
and saved-chat authorization cases.
- `pnpm check:token-gates` and `git diff --check` passed.
- Full workspace `pnpm -r typecheck` and `pnpm build` passed.
- Full Linux CI passed on `dafff44a32`: 53 successful checks and two
intentional Storybook skips. This includes all general and serialized
test groups, UI and browser tests, typecheck, build, and the canary dry
run. No CI retries were needed.
- The full local `TMPDIR=/private/tmp pnpm test:run` started but did not
complete. It was stopped after full Linux CI passed. Before the stop,
three company-skills cache cases failed on macOS. A focused rerun
reproduced all three as `EACCES` while renaming immutable cache staging
directories. The test, company-skills service, and runtime cache files
are byte-identical to the baseline previously reproduced on `e99854249c`
for #15291. Other local groups were not reached; the full Linux CI run
provides aggregate coverage.
- Greptile scored the exact head `dafff44a32` 5/5 with no findings or
unresolved review threads.

## Risks

- Malformed task IDs now return 404 instead of reaching PostgreSQL and
returning 500. The route does not map draft IDs to agents or tasks.
- No schema, browser provider, task creation, or authorization policy
changes.

## Model Used

OpenAI GPT-6 through Codex, with reasoning, repository editing, code
execution, and independent agent review. The exact deployment model ID
and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub references)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused suites; full local
run limitations are reported above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 19:41:52 -07:00
DottaandPaperclip 81cd03b3b5 test(ui): keep initial reasoning with the saved reply (#15107)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - The issue thread shows saved replies and agent run history.
> - History that appears after the reply can move the page.
> - Master now waits for initial run history before it shows the thread
in #15228.
> - This pull request checks that reasoning and the saved reply appear
together in the first visible frame.
> - The test protects that behavior from a later change.

## Linked Issues or Issue Description

No public issue tracks this report. This is a bug regression test.

**What happened?**
The issue thread showed a saved answer before its reasoning and tool
history loaded. The later history moved the page.

**Expected behavior**
The first visible thread contains the initial reasoning and the saved
reply in order.

**Steps to reproduce**
1. Open an issue with an agent run and a saved reply.
2. Delay initial run-history hydration.
3. Observe the saved reply before its reasoning appears.

Related work: #15228 now contains the reveal gate. This PR adds a direct
regression assertion for that gate. #14667 takes a different loading
approach and remains open.

## What Changed

- Add a saved agent reply to the initial-history test.
- Assert that the native run's reasoning appears before that reply when
the thread becomes visible.
- Assert that the thread stays inert until history is ready.

## Verification

- `vitest run ui/src/components/TaskChatThread.test.tsx
ui/src/pages/IssueDetail.test.tsx` passed: 353 tests.
- `git diff --check origin/master...HEAD` passed.
- GitHub CI checks are in progress for the rebased head.

## Risks

- Low risk. This PR changes only a test.
- The production fix is already in #15228. This PR must not restore the
older code from the previous branch head.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex CLI assisted with tool use and code execution. The exact
model ID and context window were not exposed to this agent session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` /
`Closes: #` / `Refs: #` OR (b) described the issue in-PR following the
relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My remote branch name describes the change and contains no
internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes (no
user-facing documentation changed)
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 21:09:09 -05:00
DottaandPaperclip 0e0b63e5a5 feat(connections): add experimental task-pinned AI routing (#14967)
## Thinking Path

> - Paperclip manages AI agents and their work.
> - AI Connections separate account access from models and harnesses.
> - A pool must act as one connection while retaining each task’s
account.
> - Core must enforce member access and preserve session and recovery
rules.
> - A plugin supplies rotation policy without receiving credentials.
> - This change adds durable routing and native connector setup and
management.

## Linked Issues or Issue Description

**Subsystem affected**

AI Connections, Connectors, plugins, run dispatch, and session
compatibility.

**Problem or motivation**

Operators need to rotate new tasks across saved accounts while each task
keeps its account and session. Pool setup must fit the existing
connector catalog and account workflow.

**Proposed solution**

Add an experimental router binding, a capability-gated plugin hook, and
transactional task pins. Plugins declare native pooled connectors
through `aiConnectionRouter`. Core hosts the existing-account picker,
ordering step, and account settings. Related usage contract: #14936.
Companion private plugin:
https://github.com/paperclipai/paperclip-cloud/pull/643.

**Roadmap alignment**

This extends Apps and AI Connections. Core supplies generic enforcement
and native connector UI; the private plugin owns rotation and quota
policy. The prior duplicate search found no matching router
implementation.

## What Changed

- Add a router binding without changing existing concrete bindings. Keep
the instance flag and new pools disabled by default. Require manual
operator configuration. Show no routing toggle in Experimental settings
on either open-source or Cloud installs, even after routing is enabled.
- Persist company-scoped pools, one shared cursor per pool, and pins
keyed by company, pool, agent, and task. Commit pins and cursor advances
together with revision checks and bounded retries. Persist run-ID
affinity before allocation.
- Pass only authorized metadata and normalized usage to plugins. Core
retains credential handling, member access checks, runtime
qualification, and recovery evidence. Probe outside locks with a shared
15-second budget and freshness cache.
- Resolve routing before credential preparation and backend selection.
Preserve pins through turns, session resets, removed members, and quota
waits. Retain admitted recovery after disable or uninstall.
- Separate credential session epochs from token generations. Verified
refresh preserves the epoch; reconnect and manual replacement change it.
Include the credential slot ID in session and usage-cache identity, so
reconnecting an indexed legacy account invalidates its old session even
when both epochs are zero.
- Validate pool member installations before accepting saved-agent
bindings and recheck compatibility when the harness changes. Install
only authorized members in the new-agent transaction and record their
IDs in local activity. Pool membership cannot install a restricted
shared connection.
- Preserve pool bindings when agents hire teammates through either
creation API or native caller runtime inheritance. Block stale manager
credential references; retain explicit child authentication precedence
and reject incompatible inherited pools.
- Add native connector registration through plugin metadata. Reuse the
Connectors catalog, setup header, account header, sidebar, dialogs, and
usage display. Setup selects and orders saved connections. Advanced
settings hold usage rules and member runtime defaults. New-account setup
opens in another tab.
- Use revision-checked pool archival from the Connectors catalog and
account page. Keep task pins, cursors, recovery evidence, and underlying
connections. Reject ordinary connection updates or removals that bypass
pool revisions.
- Add pool selectors, composer models, override notes, quota status, run
details, activity records, and local run-log records. Keep
session-adoption copy minimal.
- Show **Used by** below the pool connections. List current company
agents with shared avatars and profile links. Include paused agents;
exclude terminated agents and agents using another pool.
- Add Core stories for the generic connector workflow and runtime
surfaces. Cloud stories reuse these production routes and tokens through
a preview-only alias.

## Verification

- Final head `73cb953bca30ed83e4505dd820edd9b5edffd28b`: full workspace
`pnpm -r typecheck`, `pnpm build`, and `pnpm check:token-gates` pass
locally.
- All 422 focused connector/settings/shared-contract/migration tests and
all 156 database-backed AI connection, hiring, reconnect, and
durable-routing cases pass (69 hiring cases rerun after the final
auth-precedence fix). The merged shared contract retains connection
instructions and pool metadata. The pool migration is generated at
sequence 0299 after the latest upstream migrations; this PR makes no
lockfile changes.
- All four full-app Playwright tests pass on the final head after a cold
restart and migration, against the installed private plugin and isolated
database, with no route or pool-API mocks. They cover hidden routing
controls after manual opt-in, native pool creation, ordering, membership
edits, rename, paused defaults, enabling/save/refresh persistence, stale
edits, cancellation/removal, preserved underlying accounts, unavailable
routers, and Used by avatars and profile links. Exact command:
`PAPERCLIP_CONNECTION_POOL_E2E=1
AI_CONNECTIONS_TEST_COMPANY_ID=a37b9625-5ecf-4e29-8081-04df3d6e7d6f
AI_CONNECTIONS_TEST_URL=http://127.0.0.1:3108 pnpm exec playwright test
--config tests/ai-connections-app/playwright.config.ts
connection-pools.spec.ts`.
- [Native setup, ordering, and management
screenshots](https://github.com/paperclipai/paperclip/pull/14967#issuecomment-6006976278)
address the review follow-up. [Earlier selector, quota, and run-detail
screenshots](https://github.com/paperclipai/paperclip/pull/14967#issuecomment-5971537316)
show the runtime surfaces. Core previews: `pnpm --filter @paperclipai/ui
storybook`, then **Connectors / Pool host** or **AI Connections /
Connection pools**. Cloud owns its host-backed plugin stories; both
repositories’ Operator Setup Required story assertions pass.
- Live acceptance used OpenAI/Codex and Anthropic/Claude ACPX, resumed
both exact sessions after restart, preserved pinned accounts through
explicit reset and controlled quota deferral/recovery, and committed
only two allocations across fourteen runs. A later UI-created task test
again rotated OpenAI then Anthropic and resumed OpenAI through
follow-up/restart/quota recovery. That later Anthropic execution was
blocked by its saved OAuth token expiring (provider 401). No live usage
probes ran.
- The full local `pnpm test:run` was attempted earlier and did not
complete because of macOS embedded PostgreSQL bootstrap/shared-memory
failures and the 40,000-file Git fixture timeout. The focused database
suites above now pass; full-suite verification is provided by the split
CI lanes. The preceding CI run had one runtime readiness timeout; it
passes locally both alone and inside the larger runtime suite. That
larger local suite also encountered an embedded PostgreSQL setup failure
and two macOS temporary-path alias assertions; those two assertions pass
with canonical TMPDIR=/private/tmp. All final-head CI checks are
terminal green, including full general/serialized server suites, Runner
checks, browser E2E shards, canary verification, build, and typecheck.
Greptile is 5/5 on that exact head with no unresolved threads.

## Risks

- The migration adds routing tables and a credential epoch column.
Install the private plugin only with the compatible Core contract.
- Routing and each pool require opt-in. Production distribution and
fleet defaults remain unchanged.
- Unknown usage stays eligible. Known pinned exhaustion waits; revoked
access requires operator repair.
- Legacy adapters require compatible members. Runner model and effort
overrides remain limited by qualified backend support.

## Model Used

OpenAI GPT-6 through Codex, with reasoning, repository editing, code
execution, and browser testing. The exact deployment model ID and
context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes:` / `Closes:`
/ `Refs:` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (targeted suites;
full-suite limitations are reported above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 20:44:37 -05:00
DottaandPaperclip 4857799a88 feat(connections): deliver saved instructions to authorized agent turns (#15216)
Persist optional connection instructions and deliver authorized snapshots to agent execution prompts. Keep provider templates with each app definition, preserve edits and opt-outs, and replace sessions when guidance or access changes.

Use shared production settings across setup and Permissions, with source visibility in agent Instructions. Add the initial memory-provider defaults and managed Honcho workspace configuration. Include migration 0298 and regression coverage for generic providers, runtime delivery, authorization, and catalog regeneration.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 18:16:00 -05:00
DottaandPaperclip 2c43b39167 refactor(ui): share task composer and project/worktree controls (#15091)
Use the shared composer for new tasks, including project and worktree selection, rich mentions and slash commands, and remembered task settings.

Save project preferences after successful task updates. Show known agent models by name and use Default for unknown runtime defaults.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 18:06:40 -05:00
DottaandPaperclip ad0c4f0767 fix(ui): keep mobile task output above the composer (#15282)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - People read agent output in the task conversation.
> - Mobile tasks scroll the document and keep the composer above the
footer.
> - The document body keeps a fixed height while the thread grows.
> - The old observer misses late thread growth, and a layout scroll
event can cancel follow mode.
> - This pull request observes the thread and preserves follow mode
until the reader scrolls up.
> - The benefit is visible new output without repeated manual scrolling.

## Linked Issues or Issue Description

**What happened?**

New task output can move behind the mobile composer while the reader is
already at the bottom. Late content layout does not resize the
fixed-height body. A scroll event after layout growth can also clear
follow mode before the resize observer runs.

**Expected behavior**

Keep new output visible above the composer while the reader follows the
bottom. Hold the reading position after an upward scroll. Resume
following when the reader returns to the bottom.

**Steps to reproduce**

1. Open a long task conversation on mobile and scroll to the bottom.
2. Let a streamed row or delayed content grow after the parent renders.
3. Check whether the latest output stays above the composer.
4. Scroll up to read earlier output, then return to the bottom.

**Paperclip version or commit**

Reproduced by regression tests against master at 6c36c07a4.

**Deployment mode**

Built from source. This is a mobile UI bug and does not depend on an
adapter or database.

Related work: #15228, #13229, and #13095. The search found no duplicate
fix for mobile document auto-follow.

## What Changed

- Observe the conversation box as well as the body for late layout
growth.
- Preserve bottom-follow intent when a layout scroll event arrives
without an upward scroll.
- Reconcile document scrolling when the viewport resizes.
- Add regressions for late growth, event ordering, reading position,
return to bottom, and viewport changes.
- Add a bounded Storybook streaming fixture with the production thread,
composer, and mobile footer.

## Verification

- 244 focused tests pass across `useWindowAutoFollow`,
`TaskMessageScroller`, and `TaskChatThread`. Three new regressions fail
before the fix.
- All 7,439 UI tests pass across 683 files (`pnpm exec vitest run
--project @paperclipai/ui`).
- `pnpm check:token-gates`, `pnpm -r typecheck`, and `pnpm build` pass.
- The full repository test shards and browser E2E checks pass in CI on
commit 43354eb38. The duplicate local `pnpm test:run` was stopped after
37 minutes once those CI test shards passed; that local run did not
complete.
- Browser check at 402 by 874: controlled streamed output stayed at
document bottom, with the newest paragraph above the composer. Scrolling
up held position as output grew. Returning to bottom resumed following.
- Open Storybook's **Task chat / Mobile streaming follow / Streaming**
story to repeat the check. The fixture makes no agent or provider calls.
- Greptile is 5/5 on commit 43354eb38. All review threads are resolved.
- All CI checks pass on the final commit, including the canary packaging
gate.

## Risks

- Scroll event order differs between browsers. The regression tests
cover a scroll event before resize reconciliation and deliberate upward
scrolling during growth.
- The change affects the mobile document scroll owner. Desktop scrolling
stays covered by its existing tests.
- Existing same-task targets and browser history restoration still pass.

## Model Used

OpenAI GPT-6 through Codex. The exact serving variant and context window
are not exposed in this session. Capabilities used: reasoning, code
editing, tool execution, and browser verification.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 17:33:29 -05:00
6c36c07a4f feat(adapters): add GPT-6.1 Sol and refresh shared coding harness pins (#14942)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents run through coding-agent adapters and the native runner. Both
use the same installed provider CLIs, model catalogs, and reasoning
controls.
> - OpenAI released GPT-6.1 Sol (`gpt-6.1-sol`) in Codex. Anthropic
released Claude Sonnet 5.5. The static Codex, Bedrock, and OpenCode
catalogs do not list these IDs.
> - The shared provider pack pins Codex 0.156.0 and OpenCode 1.18.32.
The evaluation image pins older Grok, Gemini, Kimi, Cursor, and GitHub
CLI releases. Codex 0.156.0 has no bundled metadata for GPT-6.1 Sol.
> - A model entry without a current harness, or a harness pin without
its runner integrity checks, fails at run time.
> - This pull request adds the verified model IDs and moves the harness
pins, executable digests, controller checks, and image pins together.
> - The benefit is that operators can select the current models, and the
native and local adapters share one current CLI installation.

## Linked Issues or Issue Description

Refs #13829 and #13838 (the September 22, 2026 model and harness
refresh). Related pull requests: #14993 (merged October 5, 2026,
superseding #14816) added the direct Claude Sonnet 5.5 entry and
refreshed the Claude runtime to Agent SDK 0.3.286 / Claude Code 2.1.286.
This pull request does not change the Claude runtime or the direct
Claude model list; it keeps the #14993 pins and adds only the Bedrock
Sonnet 5.5 ID. After #14993 merged, this branch was rebased onto
`master` (October 5, 2026). The six overlapping pin regions
(`docker/daytona-runner/Dockerfile`, `docker/daytona-runner/README.md`,
`package.json`, `pnpm-workspace.yaml`,
`packages/adapters/claude-local/src/index.test.ts`,
`packages/paperclip-runner/src/backends/native-backend-factory.test.ts`)
were resolved by keeping this pull request's Codex 0.160.0 and OpenCode
1.18.34 pins next to #14993's Claude 0.3.286 / 2.1.286 pins, taking the
union of the Sonnet 5.5 model IDs in the Claude test, and merging both
README paragraphs. The Sonnet 5.5 effort and CLI-gate lines in the
Claude adapter were identical in both pull requests and merged without a
diff. #14917 and #14918 reordered the Claude and Codex model lists
earlier; the new entries sit where those ordering rules put them.

Sources checked on 2026-10-02:

- [OpenAI Codex models](https://learn.chatgpt.com/docs/models): GPT-6.1
Sol uses `gpt-6.1-sol`, supports reasoning efforts from Light to Ultra,
and has Standard and Fast modes at launch. The page also records that
`gpt-5.4` and `gpt-5.4-mini` retired from Codex with ChatGPT sign-in on
August 31, 2026, and that `gpt-5.5` retires on October 14, 2026. Neither
retirement applies to the OpenAI API.
- [Codex CLI releases](https://github.com/openai/codex/releases) 0.157.0
through 0.160.0. The bundled model metadata in the 0.160.0 Linux binary
contains `gpt-6.1-sol`.
- [Claude Sonnet
5.5](https://platform.claude.com/docs/en/models/sonnet-5-5/overview):
Bedrock ID `anthropic.claude-sonnet-5-5`, released September 28, 2026.
- [OpenCode releases](https://github.com/anomalyco/opencode/releases)
1.18.33 and 1.18.34 (fixes only). The OpenCode model registry lists both
added provider-qualified IDs.
- npm `latest` tags for `@xai-official/grok` 1.0.46,
`@google/gemini-cli` 0.62.0, and `@moonshot-ai/kimi-code` 2.1.1.
[xAI](https://docs.x.ai/docs/models),
[Google](https://ai.google.dev/gemini-api/docs/models), and
[Kimi](https://www.kimi.com/code/docs/en/kimi-code/models.html) list no
newer coding models.
- Cursor CLI 2026.10.01-e373342 is the version the official installer
resolves. The pinned digest is the SHA-256 of the versioned Linux x64
archive.
- [GitHub CLI 2.102.0](https://github.com/cli/cli/releases/tag/v2.102.0)
(security fixes). The pinned digest matches the release `checksums.txt`.

## What Changed

- Codex adapter: add `gpt-6.1-sol` to the model list, the Fast mode
list, and the Ultra effort set. It is the first entry: #14918 orders the
list newest version first, and its description notes the ChatGPT app
lists GPT-6.1 Sol first. Update the adapter documentation text.
- Claude adapter: add `us.anthropic.claude-sonnet-5-5` (Bedrock Sonnet
5.5) to the Bedrock catalog in the newest-Sonnet slot after Opus 5.5;
`us.anthropic.claude-sonnet-5` moves into the older-Sonnet group,
matching what `sortClaudeModels` from #14917 produces at runtime. Any
Sonnet 5.5 ID (direct or Bedrock-qualified) now gets the documented
`xhigh` and `max` efforts and requires Claude Code 2.1.284 or later on
the CLI lane (the Claude Code changelog entry for 2.1.284 adds
`claude-sonnet-5-5`). These two lines are identical to the ones #14993
merged, so the branch carries no diff for them.
- OpenCode adapter: add `openai/gpt-6.1-sol` and
`anthropic/claude-sonnet-5-5` to the static fallback catalog.
- Codex runtime pin 0.156.0 → 0.160.0 in the root and workspace
overrides, the runner package, the Codex ACP package patch, the
qualified ACPX profiles, the Linux x64 executable digest, the Rust
provider backend and its tests, the provider-pack manifest pins, the
remote controller pins, the sandbox npm install spec, and the opt-in
qualification scripts.
- Remote Codex compatibility window: upper bound 0.157.0 → 0.161.0. The
minimum stays at 0.149.0.
- OpenCode runtime pin 1.18.32 → 1.18.34 in the runner package, the
materialization script, the server and Rust qualified versions, the eval
and live-session labels, fixtures, and the configuration label.
- Evaluation image (`docker/daytona-runner/Dockerfile`): Grok CLI
1.0.46, Gemini CLI 0.62.0, Kimi Code 2.1.1, Cursor CLI
2026.10.01-e373342 with its digest, GitHub CLI 2.102.0 with its digest,
Codex and OpenCode version probes, and the refreshed lockfile digest.
The Claude Code 2.1.286 probe comes from #14993 and is unchanged here.
- `pnpm-lock.yaml` is not part of this pull request. The repository's
pull request gate rejects lockfile edits, and the refresh bot
regenerates the lockfile on master (the same flow #13838 used). The
Dockerfile `PAPERCLIP_RUNNER_LOCK_SHA256` default is the digest of the
lockfile that `pnpm install --resolution-only --ignore-scripts
--no-frozen-lockfile` (the refresh workflow's command) produces for the
combined pins on the rebased branch (`e1856797…`); that lockfile differs
from master only in the `@openai/codex` 0.160.0 platform packages, the
`@anthropic-ai/claude-agent-sdk` 0.3.286 override that #14993 introduced
(the open refresh-bot pull request #14872 carries that part),
`opencode-ai` 1.18.34 with its Linux x64 baseline, and the `codex-acp`
patch hash.
- Documentation: runner README, runner compatibility doc, environment
variable example, and a new `doc/adapter-model-audit-2026-10-02.md` with
sources and deferred items.
- Tests: Codex adapter catalog, server adapter models, Codex
compatibility window, native session executor pins, runner package
contract, OpenCode materialization, and UI effort options.

Unchanged on purpose: Claude Agent SDK 0.3.286 / Claude Code 2.1.286
(already on `master` from #14993), ACP bridges (`acpx` 0.13.1,
`claude-agent-acp` 0.73.0, `codex-acp` 1.6.2; newer upstream releases
need a separate qualification), the native Grok runtime 1.0.13, Pi
0.84.2 / 0.87.1 (the Pi 1.0 runner stack covers it), and Hermes 0.19.0
(current). `gpt-5.4` and `gpt-5.4-mini` stay in the picker because the
OpenAI API still serves them.

## Verification

Run on Linux x64 with Node 25.9.0 and pnpm 9.15.4 after `pnpm install
--no-frozen-lockfile` (the refreshed lockfile stays local; see above).
The results below were re-run on the rebased head (October 5, 2026) for
the suites the conflict resolution touches; the other rows are from the
original run and are covered by CI on every push:

- Rebased head: `packages/adapters/codex-local` 482 passed;
`packages/adapters/claude-local` 340 passed, 4 failed (`execute.remote`,
`test.probe`, `execute.acp-fallback`, `acp` spawn/env-hardening cases
that fail identically on unchanged `master` in this host environment);
`server` adapter-models + codex-runtime-compatibility +
native-session-executor + adapter-registry 607 passed, 1 failed (the
same adapter-registry override-pause case as before, also failing on
`master` here); `packages/paperclip-runner` native-backend-factory +
qualified-profiles 36 passed; `ui` codex-reasoning-effort +
config-fields + model-utils 19 passed. Rust, full typecheck, build, and
the Docker image are left to CI as before.

- `vitest run` in `packages/adapters/codex-local`: 13 passed. `vitest
run` in `packages/adapters/claude-local` (whole package, including the
new Sonnet 5.5 gate and effort tests): see the latest CI run and the
comment below. `vitest run` in `packages/adapters/opencode-local`: 48
passed, 1 failed (`runtime-config.test.ts` reads the host
`PAPERCLIP_OPENCODE_PROVIDERS` variable; it fails the same way on the
unchanged base).
- `vitest run src/__tests__/adapter-models.test.ts
src/services/native-runtime/codex-runtime-compatibility.test.ts
src/__tests__/adapter-registry.test.ts` in `server`: 84 passed, 1 failed
(`adapter-registry.test.ts` override pause test; it fails the same way
on the unchanged base).
- `vitest run` in `ui` for `codex-reasoning-effort`,
`agent-setup-fields`, `config-fields`, and `ComposerRunSettingsPicker`:
25 passed.
- `node --test test/acpx-codex-package-contract.test.mjs
scripts/materialize-opencode-binary.test.mjs
scripts/runner-protocol-eval-campaign.test.mjs` in
`packages/paperclip-runner`: 23 passed. The package contract test
verifies the installed Codex ACP executable digest and the 0.160.0 patch
pin.
- `vitest run src/drivers/acpx src/backends src/drivers/opencode
src/live/live-session.test.ts` in `packages/paperclip-runner`: 626
passed, 5 failed, 1 skipped. The 5 failures
(`installation-integrity.test.ts` `/proc/self/fd` module loading and one
OpenCode answer-selection test) also fail on the unchanged base under
Node 25; Linux CI runs Node 24.
- `pnpm run test:opencode:qualification` in `packages/paperclip-runner`
against the installed OpenCode 1.18.34 executable: passed.
- `codex --version` from the installed pack prints `codex-cli 0.160.0`.
The Linux x64 executable digest `12eb3e81…652aad` was computed from the
`@openai/codex@0.160.0-linux-x64` archive after checking its registry
`dist.integrity`.
- `pnpm check:token-gates`: all gates clean.
- `pnpm run typecheck:typescript` in `packages/paperclip-runner`:
passed. Package typechecks ran one at a time; see the comment below for
the server and UI results.

Not run here, and needed from CI:

- Rust tests and `pnpm -r typecheck` / `pnpm build` for the server (no
`cargo` in this environment; the server typecheck prepares the runner
vendor build).
- The Docker evaluation image build and the real-binary Codex startup
and session-resume probes (no Docker; the probes need the compiled
`paperclip-runnerd`). The trusted CI runner workflow covers them.
- Authenticated inference with any new model. This change is metadata
and startup validation only.

## Risks

- Codex 0.160.0 changes the bundled model catalog and app-server
behaviour (authoritative provider catalogs, incremental running-turn
tracking). The patched `codex-acp` 1.6.2 bridge is unchanged and
declares `^0.148.0`; it worked with 0.156.0 under the same override. If
CI probes show a protocol change, the pin can return to 0.156.0 by
reverting this pull request.
- The compatibility window upper bound moves to `<0.161.0`. Remote
images with Codex 0.157 to 0.160 become accepted. Older images stay
accepted down to 0.149.0.
- Until the refresh bot lands the regenerated lockfile on master, the
Dockerfile lockfile digest default does not match the committed
lockfile. The trusted CI workflow computes the digest from its own
resolution at build time, so this affects only a local build that passes
no digest.
- Existing saved model selections and effort settings are not changed.
Agents on `gpt-5.4` or `gpt-5.5` with ChatGPT sign-in need a model
change before the OpenAI retirement dates; that is documented, not
enforced.
- Rollout order: deploy the controller and runner from this change
before promoting a sandbox image that carries these pins. Older
controllers reject the new provider-pack pins.

## Model Used

- Claude Fable 5.1 (Anthropic, model ID `claude-fable-5-1`), 1M context
window, adaptive thinking, tool use. The model ran as a Paperclip agent
through the Claude Code harness, performed the web research, edited the
code, and ran the tests listed above.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Bender (Fable) <noreply@paperclip.ing>
Co-authored-by: devinfoley <139239+devinfoley@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:59:08 -07:00
DottaandPaperclip b43073d11f feat(connections): sync and group accounts managed by aggregators (#15254)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections give agents governed access to external tools.
> - Aggregator gateways can expose accounts that users already connected
upstream.
> - The Apps catalog did not show those accounts or their current
provider status.
> - Separate cards and setup tasks also made account ownership unclear.
> - This pull request discovers upstream accounts and groups them under
one app card.
> - Users can find connected apps while each provider keeps control of
its accounts.

## Linked Issues or Issue Description

**Subsystem affected**

Connections across the database, shared contracts, server, and board UI.

**Problem or motivation**

Users cannot see which apps are connected through a saved aggregator
gateway. Native and upstream accounts need one app card. Discovery must
preserve company, user, gateway, and credential boundaries.

**Proposed solution**

Sync account metadata from Composio, Arcade, and supported Executor
gateways. Keep upstream account management in each provider. Use source
chips and search to browse the catalog. Preserve native setup and the
gateway's existing access policy.

**Alternatives considered**

Creating a local executable connection for each upstream account would
duplicate authorization state. Using an agent task for routine Composio
setup would add an unnecessary step. The board now calls the saved
gateway directly for that setup.

**Roadmap alignment**

This extends the shipped Connected Apps and MCP Tool Gateway features in
ROADMAP.md. The duplicate search found no open PR for managed account
discovery.

Related work: Refs #13755, Refs #13941, Refs #14725, Refs #13855. Open
PR #12906 covers adjacent toolkit routing work.

## What Changed

- Add provider-neutral discovery, sync, and refresh APIs. Preserve the
Composio API paths.
- Cache observations by company, saved gateway, viewing user, and
credential version. Retain stale observations after failed or incomplete
scans.
- Add optional Arcade account sync credentials in the vault. Discover
Executor accounts through its supported inventory interface.
- Group native and upstream accounts in one app card. Imported account
menus open their provider. Gateway menus own refresh and sync setup.
- Add Paperclip, Composio, Arcade, Installed, and All chips. Show 50
catalog entries per page. Keep connected accounts above discovery. Keep
explicit provider searches scoped.
- Simplify Composio app setup and refresh its connected app list on the
gateway Permissions page.
- Add a compact agent access card and task creation defaults for
connection setup. Preserve explicit blocks and approval policies.
- Add two replay-safe migrations, service and UI tests, Storybook
journeys, and acceptance stories.

## Verification

- Passed the repository typecheck, full build, token gates, and
migration ordering check.
- Passed the focused provider adapter, connection interaction, and
catalog tests after rebasing onto master.
- Passed all nine database sync and migration replay tests using a
disposable database on the test-drive PostgreSQL cluster. Removed that
database after the run.
- Verified Arcade cursor pagination against its official Go SDK and
passed all eight adapter tests, including short and incomplete pages.
- Passed all 45 interaction tests after making the exact requested tools
and their Allowed/Ask first permissions visible before granting access.
Verified the compact card in Storybook.
- Passed the complete UI suite on the final code: 683 files and 7,432
tests, including the corrected Composio destination assertions. Passed
130 focused tests for the UUID, management-link, and health-status
corrections.
- Passed 22 Composio setup/sync tests, 23 connection-intent service
tests, and the connection migration test in separate disposable
databases. Database startup alone was substituted; the suites exercised
their real SQL and services.
- Passed all 10 OpenAPI route checks and the full-stack
connection-intent browser test, including scoped consent, agent
continuation, and task completion.
- The local full runner encountered embedded PostgreSQL startup failures
on this loaded macOS host. The earlier in-flight run also held the
pre-fix Arcade transform; a fresh run of the final provider suite
passes. The final-head CI is queued during GitHub’s active Actions
incident: https://www.githubstatus.com/. The previous run also lost
several runners simultaneously; its real catalog assertion failures are
fixed and the fresh complete UI suite passes.
- Tested the real test-drive server in the embedded browser with a live
Composio gateway. Detected Airtable and Circleback. Verified refresh
progress, account rows, source chips, search scope, and 50-entry
pagination.
- Arcade and Executor coverage uses provider fixtures. Live credentials
were unavailable.
- Storybook builds successfully and includes grouped native/provider
accounts, stale and unavailable discovery, optional Arcade setup, and
mobile states. The acceptance document records the simulated and live
coverage separately.

- Greptile reviewed final commit
`217b024c27b5933e773ce9419c4e92b1032042c6` at 5/5. All six review
threads are resolved, security scans pass, and the PR has no merge
conflicts. The outstanding remote checks are `ci / Select trusted
runner` and `review`, queued by GitHub. They need to complete before
merge.

## Risks

- Provider response changes can break inventory discovery. Failed scans
retain observations and show stale status.
- Composio scans only the supported catalog and can take time. Large
inventories run in the background with progress and a bounded lease.
- Arcade requires a project API key and user ID when the gateway cannot
supply them. This key is used only for discovery.
- Executor discovery depends on the server's exposed inventory tools.
Unsupported servers report unavailable discovery.
- Cached account rows do not grant access or create executable
connections. Gateway policies still govern tool use. Account deletion
and per-app authorization remain upstream.
- The migrations add tables and one nullable column. Replay preserves
existing rows and company-scoped foreign keys.

## Model Used

OpenAI Codex, based on GPT-6. The session does not expose a more
specific serving model ID or context limit. Used reasoning, repository
tools, code execution, and browser verification.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 14:57:04 -05:00
Devin FoleyandPaperclip 55e0c895ef test(ui): finish sidebar focus cleanup before JSDOM teardown (#15255)
Finish deferred Radix focus cleanup before the sidebar test environment
closes. Use React act and controlled timers, check the real unmount focus
events for both menus, and assert no timer work remains.

Validation: all 7,368 UI tests, repository typecheck and build passed.
Hosted CI passed, including server tests, browser tests and canary packaging.
Greptile 5/5 on the exact reviewed head; no unresolved comments.
Local full-suite limitations and clean-base comparisons are recorded in the PR.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-05 12:11:32 -07:00
cab4263dc9 feat(claude-local): add Sonnet 5.5 and refresh the qualified Claude runtime (#14993)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Claude local adapter lists models for users with a Claude
subscription.
> - The list needs Claude Sonnet 5.5 and its supported effort levels.
> - Sonnet 5.5 needs Claude Code 2.1.284 or later on both execution
paths.
> - The qualified ACP runtime previously used Claude Code 2.1.280.
> - This change adds Sonnet 5.5 and pins Agent SDK 0.3.286, which
includes Claude Code 2.1.286.
> - Users can select the model and run it with a qualified runtime.

## Linked Issues or Issue Description

Refs #3936. This replaces #14816 because the maintainer integration
cannot write to the contributor fork.

Thank you to @SkilLab-Tech for the model support, runtime refresh,
tests, and platform digest verification. This branch preserves both
original commits: `8d2f3261af61a2ac1120e51e8a8618732ace543b` and
`e68d1d002a3ed745f016fb11c50ac5a3c5a9ff8d`.

Related work:

- #14917 added Claude model ordering. This branch includes that merged
change and resolves its conflicts with #14816.
- #14942 updates the other models and harnesses. It remains separate.
Its matching Sonnet effort and CLI-gate changes are identical. Both PRs
merge with master. The second PR will need a rebase after the first
merges because adjacent runtime-pin and test edits conflict.
- #14954 is another Sonnet 5.5 change. It overlaps with the model
additions but does not include the qualified runtime refresh.
- #14039 makes the per-task effort picker model-aware. #3937 is also
related to effort selection.

The original author checked the [Claude Code
changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md)
and [effort
documentation](https://platform.claude.com/docs/en/build-with-claude/effort)
on 2026-10-01.

## What Changed

- Add the direct `claude-sonnet-5-5` model and Low, Medium, High,
X-High, and Max effort levels.
- Require Claude Code 2.1.284 or later for that model on the CLI path.
- Put Sonnet 5.5 after Opus 5.5 in the current-model group. Keep Sonnet
5 in the older-model group.
- Retain the Sonnet 5.5 assertions and the model-order assertions in the
server tests.
- Pin Agent SDK 0.3.286 and Claude Code 2.1.286 across overrides,
integrity digests, qualified profiles, Rust provider pins, and the
Daytona version check.
- Update the related adapter and runtime documentation.

## Verification

Local verification uses the resolved source tree and pnpm 9.15.4. Model
tests passed on Node 25.9.0. Runtime integrity tests use CI's Node
24.21.0.

- Five focused Claude test files pass: 62 tests. They cover model
defaults, model ordering, CLI gates, and remote execution probes.
- Server model-list and UI setup tests pass: 30 tests.
- The Claude adapter typecheck passes.
- Runner integrity and qualification tests pass on Node 24.21.0: 78
tests. Four descriptor-loader tests fail on Node 25.9.0; all four pass
on the CI version.
- The runner package contract passes: 10 tests.
- Full local typecheck stopped with exit 137 in the database package
under the container's 4 GB memory limit. The production build reached
the runner Rust build, then stopped because `cargo` is absent.
- The full stable local Vitest run was stopped after all current-head CI
test shards passed. It did not complete locally. The 180 focused tests
listed above passed.
- `git diff --check` passes. The branch changes 20 files against master.
It has no lockfile or workflow changes.
- The original author verified all three platform digests against
registry integrity and ran the Linux executable. Its version was
`2.1.286 (Claude Code)`. See #14816 for that evidence.
- Greptile reviewed head `6db3d3f1` and gave 5/5 with zero comments.
Both Superagent scans and Commitperclip pass. All current-head CI jobs
pass, including build, typecheck, Rust, test shards, browser tests, and
the canary dry run.

## Risks

- The controller and provider pack must use matching runtime pins.
Deploy them together.
- CI owns `pnpm-lock.yaml`. The master lockfile refresh must resolve the
SDK override. Refresh the Daytona lock digest with that lockfile.
- Images built with Claude Code older than 2.1.284 need a rebuild before
the CLI path can use Sonnet 5.5.
- The runtime remains at SDK 0.3.286. This PR does not take the later
0.3.287 patch.
- A live Sonnet 5.5 session and a Daytona image build are not part of
the local verification.

## Model Used

- Original work: Anthropic Claude Code, `claude-sonnet-5-5`. Review:
`claude-opus-5-5`. The author reported `xhigh` effort, tool use, and
code execution. The original context window was not reported.
- Merge repair and PR preparation: OpenAI Codex, based on GPT-6, with
tool use and code execution. The runtime does not expose the exact model
identifier or context window in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

## Squash Attribution

Keep these trailers in the squash commit to preserve the original author
and AI attribution:

```text
Co-Authored-By: Claude Code (Ivan) <SkilLab-Tech@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
```

---------

Co-authored-by: Claude Code (Ivan) <ivan@skillab.com.br>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 11:03:20 -07:00
DottaandPaperclip 7498705642 fix(ui): stabilize mobile task reading and document navigation (#15228)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - People read tasks and send instructions from phones as well as
desktop browsers.
> - The mobile footer let page text show through its labels, and small
text fields made Safari zoom on focus.
> - Small scroll changes made the footer switch direction, and its
changing page padding moved the conversation.
> - Task pages also showed comments before question cards and run
history arrived, so the composer and reading position moved again.
> - Document links also used native navigation, which reset the reading
position or reloaded a task through its UUID URL. Desktop tabs were
crowded in the mobile drawer.
> - This pull request keeps navigation steady, opens documents in the
mounted task, and gives mobile readers a full-height panel with a
vertical tab selector.
> - The benefit is a stable task view and smoother scrolling on mobile.

## Linked Issues or Issue Description

**What happened?**

The mobile footer was translucent. Safari zoomed when a person focused a
small text field. The footer switched abruptly while scrolling. A large
task could show saved comments, then move the page again when a question
card or run history arrived. In a local test with delayed responses, a
late question moved the mobile composer by about 374 pixels. Opening a
plan from the feed could reset the view or reload the task through a
UUID link. The mobile document drawer left part of the feed exposed
above small desktop tab controls.

**Expected behavior**

The footer has an opaque surface and moves smoothly after deliberate
scrolling. Text fields do not cause automatic focus zoom. A task shows
its initial conversation and composer together at the final scroll
position. Background refreshes keep the existing conversation visible.
Document links open in the mounted task with its existing cache and
reading position. Mobile documents fill the viewport, show a clear close
button, and offer a vertical list of open tabs.

**Steps to reproduce**

1. Open a task with many long comments and a pending question in iOS
Safari.
2. Delay its interactions, activity, and runs responses by different
amounts.
3. Reload the page and watch the conversation and composer move as each
response arrives.
4. Scroll down and back up, including small direction changes and edge
bounce.
5. Focus the task composer, search field, and new-task title and
description.
6. Open a plan or another task document from the feed, including a link
that uses the task UUID. Close the panel and check the reading position.
7. Open several documents on a phone. Switch tabs and close both active
and inactive tabs.

**Paperclip version or commit**

Developed from `1c07b5903` and rebased onto `59015846a`.

**Deployment mode**

Built from source. Tested in an isolated local test drive with iOS 26.5
Simulator Safari and Chrome. A temporary local proxy delayed independent
responses for the layout test.

Related work found in the duplicate search:

- Refs #14727. It made saved replies appear before supporting history.
This PR keeps its parallel requests and narrows the tradeoff in favor of
a stable first layout.
- Refs #14667. This open PR takes a different approach with per-run
placeholders and retries. This PR fixes the observed question/composer
movement and mobile navigation behavior.
- Refs #13095 and #13597. These earlier fixes added task scroll anchors
and skipped transcript waits for scheduled retries.
- Refs #6550. Earlier mobile board polish.
- Refs #9467. This related open PR changes list and generic tab reflow.
The task-pane selector uses a separate component.

## What Changed

- Give the mobile footer an opaque semantic surface.
- Set a base-size floor for editable text on touch devices to prevent
Safari focus zoom. Preserve larger title text.
- Share mobile scroll tracking between both layouts. Accumulate scroll
distance, ignore edge bounce and changed document bounds, and update
once per frame.
- Use shared motion tokens for the footer and composer. Keep page
padding stable and honor reduced motion.
- Wait for the initial question cards, attachments, work products,
activity, runtime selection, plan, and relevant transcript history
before the first reveal. Skip scheduled retries and older runs outside
the initial comment window.
- Bound the first reveal to 15 seconds. A stalled supporting request
leaves saved conversation and the composer accessible with an explicit
loading notice.
- Keep concealed mobile history from stretching the document. Keep the
composer mounted but concealed until the same reveal. Keep both visible
during later refreshes.
- Route first and repeated same-task document clicks in place. Recognize
UUID and identifier links. Preserve the thread history entry and feed
position. Keep modifier clicks, downloads, external links, and classic
document behavior.
- Give the mobile task panel the full viewport and safe-area padding.
Use a visible X and 44-pixel touch controls. Replace the horizontal tab
strip with a vertical selector that wraps titles and supports keyboard
focus.
- Add four interactive Storybook states for a few tabs, long names, many
tabs, and the last tab. Reuse the production selector and tab
controller.
- Add navigation and tab regressions, update first-reveal regressions,
and document the behavior in `DESIGN.md`.

## Verification

- 392 tests passed across the seven focused task-loading, scroll,
mobile-navigation, layout, and composer suites. After review fixes, all
339 tests across the four affected suites passed, including
stalled-loading fallback on mobile and desktop and the motion-token
catalog.
- All 442 focused document, tab, task-thread, and scroll tests pass. The
final click-propagation cleanup also passes all 136 task-detail tests.
UI typecheck, UI production build, and `pnpm check:token-gates` passed.
- All four cases in `artifact-tab-arrival.spec.ts` and
`text-attachment-tabs.spec.ts` pass locally, covering desktop and mobile
selection, composer focus, document rendering, and downloads of the
original bytes.
- `pnpm --filter @paperclipai/ui build-storybook` passed. Open the
mobile tab stories under `Prototypes/Task detail/Mobile tabs`.
- A local diagnostic proxy measured cached plan content at about 250 ms
after the first click. The HTML load count and task request count did
not change. Feed scroll stayed at the same position. First, repeated,
and UUID document links were tested at phone and desktop widths.
Task-reference links close their preview before the document reader
opens.
- In Chrome at desktop and phone widths, the delayed-response task
showed one complete reveal. The late question no longer moved an already
visible composer.
- In iOS Simulator Safari, verified the large-task reload, opaque
footer, navigation hide/reveal, and search/new-task/composer focus
without automatic zoom.
- Full workspace typecheck and build passed. The updated UI also passes
typecheck, production build, and token gates.
- All 54 checks pass on the final commit
`bf5c9914e61833e7cc8794a69d72cf8c7057b952` (two additional checks are
intentionally skipped). Greptile reviewed that commit at 5/5, and all
review threads are resolved.
- Full local `pnpm test:run` was attempted but stopped after
server-fixture failures. Embedded PostgreSQL startup failure reproduced
in an isolated native-interaction fixture after five startup attempts.
The broad run also reported a rapid Slack callback ordering test
failure. These server paths are unchanged by this PR, and their CI
shards pass on the latest head. The full local suite is not claimed as
passing.
- A localhost proxy stalled the activity response for 30 seconds. Chrome
revealed the available conversation after the 15-second deadline at both
desktop and phone widths, kept the composer accessible, and cleared the
loading notice when the response arrived.

## Risks

Slow initial history requests can delay the first conversation reveal by
up to 15 seconds. If that deadline expires, late data can change the
available conversation while a loading notice remains visible. The
reveal waits only for runs in the initial comment window, and later
refreshes do not conceal an existing conversation. The larger editable
text can change line wrapping on phones. Mobile navigation and composer
motion use shared tokens and respect reduced-motion settings. Mobile tab
selection changes the control layout. Document links retain URL history
while sharing the task reading position; other tasks and external links
keep their normal navigation behavior.

I checked `ROADMAP.md`. This is a fix for existing UI behavior.

## Model Used

OpenAI GPT-6 in Codex. The runtime does not expose a more specific model
ID or context-window size. The agent used reasoning, code editing,
terminal tools, and Chrome and iOS Simulator testing.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 12:33:34 -05:00
DottaandPaperclip 59015846ae fix(chat): keep dismissed task questions in the feed (#15229)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents ask users questions in task chats and Agent Chat.
> - Agent Chat keeps unanswered questions as compact entries in the
feed.
> - Regular task chats still show a pending composer badge after
dismissal.
> - A page reload can also open a dismissed question form again.
> - This pull request applies the same feed behavior to both chat types
and saves dismissal per person and task.
> - Users can continue the chat and return to the original question
later.

## Linked Issues or Issue Description

**What happened?**

Dismissing a question in a regular task chat leaves a pending composer
badge. The question can return after a page reload. The earlier feed
behavior only applied to Agent Chat.

**Expected behavior**

A dismissed question stays in the feed. Its form and pending badge leave
the composer. Reload preserves dismissal. Opening the feed entry
restores the original question and draft answer.

**Steps to reproduce**

1. Open a regular task chat with a pending question.
2. Select an option, then dismiss the form.
3. Reload the page. Check that the composer stays clear.
4. Open the question in the feed. Check that the draft is restored.
5. Submit the answer. Check that the answered receipt appears.

**Paperclip version or commit**

Reproduced on master at `a386a599983519eb1d399f8b770bfccdb2a74762`.

**Deployment mode**

Browser UI in local and authenticated instances. This change does not
depend on the agent adapter.

Related work: Refs #14613, which added the Agent Chat feed behavior.
Refs #9141, which validates real answers on the server. Refs #11434,
which tracks comment-driven changes to interaction state. This PR
changes question presentation only.

## What Changed

- Show compact unanswered question entries in regular task chats.
- Exclude durable questions from composer pending counts and navigation.
- Save dismissal in local storage per person and task. Merge the latest
saved IDs so dismissals from another tab survive reload. A new question
can still open its form.
- Keep the original question pending and answerable. Keep approval and
permission controls.
- Run the question-history regressions in both chat modes. Add reload,
new-question, user/task scope, and stale-tab coverage.
- Share the real-component Storybook fixture. Add a regular task test
drive and an interactive dismissal/answer scenario.
- Update the planning-mode browser test to check a dismissed question in
the feed after reload and on mobile.
- Update the design rules, implementation spec, and preview
instructions.

## Verification

- 329 focused thread, composer, and interaction-card tests pass.
- `pnpm -r typecheck` passes. The UI typecheck also passes after the
review fix.
- `pnpm build` passes for the full repository.
- UI build, Storybook build, and token gates pass. The UI build and
token gates were rerun after the review fix.
- Greptile gives final commit `98f71f221` a 5/5 score. The current-head
check passes, and there are no unresolved review threads.
- All 56 current-head checks are terminal: 54 pass and two conditional
Storybook jobs skip. The CI run includes the full test shards, build,
typecheck, browser tests, aggregate verification gate, and package
canary.
- The stale-tab regression fails in both chat modes before the review
fix and passes after it.
- `pnpm exec playwright test --config tests/e2e/playwright.config.ts
tests/e2e/planning-mode-visual-verification.spec.ts` passes against a
throwaway local server. It checks dismissal, reload, task navigation,
and desktop/mobile planning controls.
- The duplicate local `pnpm test:run` attempt was stopped after the full
CI test suites passed. It did not complete locally.
- Manual browser test: select Green, dismiss, reload, reopen, submit the
saved answer, and inspect the answered receipt. Also send a new message
while the unanswered question remains in the feed. The test drive uses
real UI components with fixture response callbacks.
- To repeat the browser test, run `pnpm storybook`. Open **Chat &
Comments → Task Chat Unanswered Questions → Test Drive**.

## Risks

- Dismissal is a browser-local preference. It does not sync to another
browser or device. Clearing local storage removes it.
- When local storage is unavailable, dismissal lasts for the mounted
thread only.
- Unanswered questions can accumulate in the feed. They stay pending
until answered or resolved through the existing API.
- No database migration, API change, or change to approval permissions.

## Model Used

OpenAI Codex, `gpt-6.1-sol`, with xhigh reasoning, repository editing,
code execution, and browser control. The context-window size is not
exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 10:55:38 -05:00
DottaandPaperclip a386a59998 Reduce repeated native completion guidance and preserve final replies (#15151)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Native agents receive task constraints and completion tools from
Paperclip.
> - Completion tools already define the procedure for reporting a
result.
> - Repeated procedure text adds instructions to each full task turn.
> - The final reply must still explain a blocker and link a saved
document.
> - This pull request removes repeated procedure text and keeps these
visible outcome requirements explicit.
> - A document receipt supplies the exact link, and stricter evals check
the persisted reply and browser navigation.

## Linked Issues or Issue Description

Refs: #14961. Related: #14948 and #15007.

**What happened?**

Native task envelopes repeat completion procedure text. A reduced
envelope needs explicit final-reply requirements. The `write_document`
receipt also lacks a canonical document link.

**Expected behavior**

Keep the completion tools as the source of procedure details. Require
one accepted completion result before the final reply. A blocked reply
must explain the reason, owner and unblock action. A document reply must
contain a working link to the saved document.

**Steps to reproduce**

1. Run the native assigned-skill document case and native blocker case.
2. Inspect the run-attributed provider final and its persisted comment.
3. Check the blocker explanation or open the final reply's document
link.

## What Changed

- Remove repeated completion procedure text from the native task
constraints and backend instructions.
- Keep explicit blocker and document-link requirements in full task
turns.
- Return a company/task-scoped `documentHref` from `write_document`.
Preserve the link in the idempotent mutation receipt.
- Repeat canonical links for this run's current saved revisions in
accepted completion feedback. Give blocked providers final-response
guidance for the cause, owner and unblock action.
- Keep internal document/comment anchors when Markdown issue links load
cached issue details.
- Add a manual six-cell comparison suite with strict source, build,
default-instruction and budget admission.
- Capture eighteen shared runnerd RPC projections and six direct
OpenCode HTTP projections across start, resume and continuation phases,
using scripted local transports and no provider execution.
- Apply v3 checks only to the manual instruction comparison; preserve v2
checks for the existing native completion suite. Check the actual
persisted blocker reason and exact saved-document link. Click the
rendered document link and check the original content marker in the
classic document card or the new document tab.
- Forward exact OpenCode finishing calls through the controller. Wait
for acceptance, keep accepted feedback and concrete rejection text, and
reject malformed responses. Preserve ordinary dynamic-tool response
handling.
- Settle the completion decision and tool response before mapping a
racing idle/error/abort event or handling explicit close/interruption.
Reject a concurrent finishing call before controller admission.
- Add a provider-free regression through real runnerd, the OpenCode
proxy and a fake provider. Reject the first completion, accept the
corrected report in the same turn, and propose one result.
- Keep all original verdicts unchanged. Treat replay under new checks as
separate diagnostics.

## Verification

- `pnpm -r typecheck` and `pnpm build` pass locally.
- Native document-authority tests pass, including company/run
authorization and idempotent replay.
- Native runtime-context, backend and measurement tests pass.
- Final-answer calibration, protocol scoring, source-admission and
catalog tests pass. Wrong reasons, absent links and wrong link targets
fail.
- `pnpm test:e2e:runner:typecheck` passes. Discovery lists exactly six
single-attempt local cells with the declared models.
- Exported `prepareNativeInstructionPreflight` then
`verifyNativeInstructionPreflight` pass on this clean committed source.
They build locally and make zero provider calls.
- Corrective live confirmation is incomplete. Source 3a7349d passed both
Claude and both Codex cases. OpenCode saved the correct document but
omitted its final link; its blocker case was canceled before paid
execution. Preserve this failure. The e171282 confirmation was stopped
during build after fresh review found a completion-settlement race; it
executed zero providers. Source c3e0cb303 fixes that race. Two affected
OpenCode cases await fresh review and one bounded confirmation; earlier
results remain attributed to their original source.
- OpenCode proxy parsing, driver, factory and input tests: 81 pass
across retained focused runs, including six settlement races.
Evaluator/scoring/admission checks: 122 pass. The real proxy regression
passes. Fresh local prepare then verify passes with 18 shared and 6
direct scripted captures, fresh SDK/Rust builds and zero providers.
- The full local suite recorded two failures: a webhook timeout and a
Git-scan load count mismatch. Both files pass in isolation with
unchanged assertions/time budgets; preserve the original failure log.
Fresh c3e0cb303 CI and review are pending. This PR remains draft.

## Risks

- Final-answer wording can vary by provider. The checks cover the
declared release-access blocker and saved document fixture, not general
answer quality.
- A single trial does not establish general equivalence, cause, speed,
cost or live resume behavior.
- `documentHref` is an additive receipt field. It points to the current
saved document, not an immutable historical revision. Replaying an older
receipt does not fabricate a new link.
- The correction adds four production paths for document receipts,
accepted completion feedback and UI navigation, plus four OpenCode
controller/proxy paths, beyond the original three instruction paths.
Completion rejection must remain repairable; the production-boundary
regression covers it.
- Preserve the frozen comparison context for live measurement. A
merge-tree check against current master is clean. Do not relabel earlier
live results as results from a later source tree.

## Model Used

- OpenAI Codex, GPT-6 family. The exact serving model ID and context
window are unavailable in this session. Capabilities used: reasoning,
code editing, shell execution, test authoring and evidence review.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 08:10:14 -05:00
1c07b5903b feat: Chat leads the left nav, agent work beside chats, and a Combined Inbox + Task List flag (#15100)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The left nav is the main way people move between tasks, the inbox,
and Agent Chat
> - The nav has separate Inbox and Tasks rows that show overlapping
work, and Chat is one row among many
> - The side panel beside a chat shows the conversation's own artifacts,
not the work the agent did
> - People want Chat to be easy to find, and they want one place for
their task views
> - This pull request moves Chat to the top of Work, shows the agent's
tasks and artifacts beside each chat, and adds an experimental flag that
folds Inbox into Tasks
> - The benefit is a shorter nav and a chat view that shows what the
agent is working on. Both changes stay off until an operator enables
them

## Linked Issues or Issue Description

Refs #14706 (the secondary Agent Chat navigation this change builds on)
Refs #14848 (reopen the last visited agent chat)

**Subsystem affected**
UI navigation (left nav, mobile tab bar), Agent Chat side panel, task
list and inbox, and the company artifacts API.

**Problem or motivation**
Inbox and Tasks are two nav rows for overlapping work. Chat sits in the
top group with no clear home. The chat rail lists only agents you
already talked to, so you cannot see your other teammates there. The
side panel beside a chat shows only the conversation's own artifacts. It
does not show the tasks and files the agent made.

**Proposed solution**
With Agent Chat on, Chat leads the Work section and the rail lists every
eligible agent. The chat side panel opens on the agent's tasks as cards,
and the agent's artifacts are available from +. A new experimental flag,
Combined Inbox + Task List, makes Inbox a set of views inside Tasks.

**Alternatives considered**
Rebuilding the inbox inside the task list. Instead, `/issues` hosts the
existing Inbox component for inbox views and the existing task list for
status views, so all inbox behaviour stays the same.

**Roadmap alignment**
Agent Chat (ROADMAP.md, "Agent Chat (including CEO Chat)"). All changes
are behind experimental flags that are off by default.

## What Changed

- **Agent Chat nav (streamlined shell):** Chat is the first row of Work,
not a top-group row. Workspaces leaves the nav while Agent Chat is on.
The mobile tab bar is Home · Chat · + · Tasks · Agents. The legacy shell
keeps master's top-group Chat row.
- **Chat rail:** `AgentConversationsSidebar` lists every eligible agent.
The open chat is first, then conversations by recent activity, then the
rest of the roster alphabetically. Terminated agents and agents you left
are omitted unless you have history with them. The picker still marks
only real conversations as "Open chat".
- **Chat side panel:** a new default Tasks tab shows one card per task
the agent created, was assigned, commented on, or acted on, newest
first. It has the task list's filter popover and a sort control. **+ →
Artifacts** shows the agent's artifacts as cards. Cards open in a new
tab. Agent Chat off keeps the old Artifacts tab.
- **Artifacts API:** `GET /api/companies/:companyId/artifacts` accepts
`agentId`. The filter applies to documents, work products, and
attachments by the agent each result is attributed to. The shared
validator and the UI client carry the new parameter, and the OpenAPI
entry picks it up from the shared schema.
- **Combined Inbox + Task List flag (`enableCombinedInboxTasks`, off by
default):** new card in Settings > Experimental. The Inbox row goes away
and its badge moves to Tasks. A Views menu on `/issues` covers Mine,
Unread, Blocked, Recent, Everything, All, Active, Backlog, and Done.
Bare `/issues` opens the last-used view (default Mine). Links that carry
`assignee`, `workspace`, `participantAgentId`, or `q` open All so the
filter is kept. `/inbox/*` and
`/issues/{all,active,backlog,done,recent}` redirect to the matching
view. `/inbox/requests` stays its own page.
- **Task detail breadcrumb:** the view key now decides the source, so
quick-archive still works after a reload from an inbox view.
- **Docs:** `doc/PRODUCT.md` and `doc/SPEC.md` describe the chat rail,
the chat side panel, and the new flag.

## Verification

- `cd ui && npx vitest run --no-file-parallelism src/components/chat
src/components/task-side-panel/TaskSidePanel.test.tsx
src/components/AgentConversationsSidebar.test.tsx
src/components/Sidebar.test.tsx
src/components/SidebarCompanyMenu.test.tsx
src/components/Layout.test.tsx src/pages/AgentChats.test.tsx
src/pages/InstanceExperimentalSettings.test.tsx
src/lib/task-views.test.ts src/lib/issueDetailBreadcrumb.test.ts
src/pages/Inbox.test.tsx src/pages/Issues.test.tsx src/App.test.tsx
src/App.activity-routing.test.tsx
src/components/MobileBottomNav.test.tsx
src/components/CommandPalette.test.tsx`: 20 files, 356 tests pass.
- `cd server && npx vitest run
src/__tests__/company-artifacts-service.test.ts`: 13/13 pass, including
the new agent-filter test across all three artifact sources.
- The new rail test fails against the unmodified rail.
- `pnpm check:token-gates`: all gates clean.
- Manual: enable Agent Chat in Settings > Experimental. Open Chat. The
rail lists all agents. Open a chat. The side panel shows the agent's
tasks. Use **+ → Artifacts** to see the agent's artifacts. Then enable
Combined Inbox + Task List. The Inbox row goes away, and Tasks shows a
Views menu.
- Snapshot baselines are intentionally not updated. See
`doc/design/DECISION-SHEET.md`, "Per-change snapshot verification
demoted to dormant (Jul 13 2026)".

## Risks

- With both flags off, the app behaves like master. The only exception
is the API: it accepts a new optional query parameter.
- With Agent Chat on, the rail can list many agents in a large company.
It uses the agent list the app already loads, and search filters it.
- The Tasks panel reads at most 200 recently updated tasks per agent and
says so when it reaches the limit. The Artifacts panel reads at most 500
of the agent's artifacts.
- Combined Inbox + Task List changes what bare `/issues` opens for
people who enable it. Deep links with a task filter still open All.

## Model Used

- Claude (Anthropic), model ID `claude-opus-5-5`, through Claude Code
with tool use (shell, file edit, test runs). Extended thinking was
enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: scotttong <squadbot000@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-04 02:13:46 -07:00
DottaandPaperclip db72ad4c73 fix(ui): explain branch artifacts without remote links (#15051)
## Thinking Path

> - Paperclip helps people manage agent work and inspect its results.
> - The issue artifact list presents those results as work-product
cards.
> - A branch can have no remote URL or structured metadata.
> - The current card hides its summary and has no action in that case.
> - This pull request shows the summary and provides an accessible
details action.
> - The card labels the absent link without making a false link.

## Linked Issues or Issue Description

**What happened?**
A branch work product without a URL showed a short title and an icon. It
did not show the saved summary or provide an action.

**Expected behavior**
The card must show what the branch contains. People must be able to open
the saved details. It must not imply that a remote URL exists.

**Steps to reproduce**
1. Open the artifact list of an issue with a branch work product that
has `url: null` and `metadata: null`.
2. Find the branch card. Its summary and details action are missing
before this change.

Related work: #12717 introduced rich work-product cards.

## What Changed

- Keep linkless branch cards concise: show the title and no-link state.
Keep the full summary behind an optional Saved description toggle.
- Label a branch with no URL as having no remote link. Let a person open
its details with a keyboard-accessible button.
- Add a focused interaction test and two Storybook states for the
no-link branch.

## Verification

- `pnpm --filter @paperclipai/ui typecheck` passed.
- Focused Vitest tests passed: 45 tests in two files.
- `pnpm --filter @paperclipai/ui build` passed.
- `pnpm --filter @paperclipai/ui build-storybook` passed.
- `pnpm check:token-gates` passed.
- The Storybook collapsed and expanded states rendered in Chromium. Both
screenshots were captured.
- Full workspace typecheck could not finish: the runner Rust package
requires `cargo`, which is not installed in this environment.

## Risks

- Low risk. The change affects card text and the action for records
without a URL. It does not change the saved data or routes.
- Long saved summaries on other linkless work products expand the card
height after a person selects Details.

## Model Used

- OpenAI Codex coding agent. The execution environment does not expose
the exact model ID or context window to this agent. It used code
execution and a browser to validate the change.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [ ] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
(the managed execution workspace fixes this branch name)
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
(Storybook examples)
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-03 21:05:48 -05:00
DottaandPaperclip 2a8a99e4a5 fix(ui): reveal completed thinking caret beside label (#15048)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - The task thread shows completed agent work and its reasoning.
> - The completed work row places the disclosure caret at the far right.
> - The caret stays visible even when the reader does not inspect the
row.
> - The row needs a quiet control that stays close to the work label.
> - This pull request places the caret after that label and shows it on
hover or keyboard focus.
> - The change keeps the timestamp on the right and does not move
content on hover.

## Linked Issues or Issue Description

**What happened?**

The completed agent work row shows a disclosure caret at the far right
of the task thread. The caret stays visible when the pointer is
elsewhere.

**Expected behavior**

The caret stays near the work label. It appears on hover or keyboard
focus. The timestamp stays on the right.

**Steps to reproduce**

1. Open a task with a completed agent run.
2. Look at the completed work row without hovering over it.
3. Hover over the row and then use the keyboard to focus its button.

Related: #11772 addresses a different caret and composer layout.

## What Changed

- Move the completed work caret next to the work label.
- Keep its space reserved. Show it on hover or keyboard focus.
- Add a test for caret position, visibility classes, and the open state.

## Verification

- `node node_modules/vitest/vitest.mjs run
ui/src/components/IssueChatThread.test.tsx` passes all 100 tests.
- `node scripts/check-token-gates.mjs` passes all token gates.
- `git diff origin/master...HEAD --check` passes.
- CI passes on the latest head, including typecheck, build, tests, and
verification. The local isolated worktree could not run typecheck
because dependency installation failed while applying the existing
`codex-acp` patch.

## Risks

- Low risk. The same button still opens the work detail. Only the caret
position and visibility change.
- On a touch device, the caret is not visible without hover. The work
row stays a button that users can tap.

> This is a focused UI fix. It does not add a planned core feature from
`ROADMAP.md`.

## Model Used

- OpenAI Codex coding agent. The runner does not expose the exact model
ID or context window. The agent used reasoning, shell tools, and code
execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used with the details available in this
runner
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either linked public issues or described the issue in-PR
following the relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
ticket ID
- [x] I have run focused tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have checked documentation impact; no documentation change is
needed for this visual fix
- [x] I have considered and documented the risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-03 12:41:22 -05:00
DottaandPaperclip 1c3abf5075 fix(ui): use available space for composer labels (#15050)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - The task composer shows the next assignee and model before a message
starts work.
> - Fixed width limits shortened both labels when the composer had
unused space.
> - People could not read the selected agent and model even when the
full text could fit.
> - This pull request makes the capsule use the available composer
width.
> - It keeps the ellipsis when Plan mode or a narrow layout causes real
space pressure.
> - The benefit is clearer run settings without damage to the compact
composer layout.

## Linked Issues or Issue Description

**What happened?**

The task composer truncated the assignee name at 6rem and the complete
assignee and model capsule at 16rem. It did this even when the composer
had more available space.

**Expected behavior**

The composer must show the complete assignee and model labels when they
fit. It must use an ellipsis only when another control or a narrow
viewport limits the available width.

**Steps to reproduce**

1. Open a task composer with a long assignee name and a long model name.
2. Use a wide desktop layout.
3. Observe that the old capsule shortened both labels while unused space
remained.

**Paperclip version or commit**

Current `master` before this change.

**Deployment mode**

Local dev (`pnpm dev`).

**Installation method**

Built from source.

**Agent adapter(s) involved**

Not adapter-specific. This is a core UI bug.

**Database mode**

Not database-related.

**Access context**

Board.

**Additional context**

The Storybook cases cover a wide composer and a narrow composer with
Plan mode.

## What Changed

- Removed the fixed maximum width from the assignee and model capsule.
- Removed the fixed maximum width from the assignee label.
- Kept overflow ellipsis behavior when the parent row has insufficient
space.
- Added stable label selectors and focused component coverage.
- Added Storybook cases for complete labels and Plan-mode truncation.

## Verification

- `pnpm --filter @paperclipai/plugin-sdk build`
- `pnpm --filter @paperclipai/ui typecheck`
- `vitest run
ui/src/components/task-chat/ComposerRunSettingsPicker.test.tsx`
- `node scripts/check-token-gates.mjs`
- Storybook production build under Node.js 24.20.0
- Captured and inspected the two new Storybook cases.
- The complete repository typecheck and build reach the Rust Runner
step. This local environment does not have `cargo`. Hosted CI supplies
the Rust toolchain.
- The repository test suite reaches workspace-runtime tests. This local
runner does not allow their required temporary home directories. Hosted
CI supplies a writable test home.

## Risks

- Low risk. The change only removes fixed width limits from one flex
item.
- A very narrow composer can still shorten both labels. This is the
intended fallback.
- The Storybook constrained case verifies that Plan mode and Send remain
usable.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI GPT-5 through the Paperclip Codex runner. The run used
reasoning, tool use, code execution, browser automation, and image
inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [ ] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-03 12:39:18 -05:00
DottaandPaperclip 569c7203aa fix(ui): use latest issue runtime callbacks (#14863)
## Thinking Path

> - Paperclip lets people manage AI agents and their work.
> - The issue page uses an external-store adapter for comments.
> - The adapter must keep one identity during an unrelated render.
> - The adapter must also call the newest send and cancel functions.
> - Passive effects update those functions too late for a synchronous
runtime call.
> - This pull request updates the function refs during render and adds a
regression test.
> - The benefit is a stable comment thread with no stale comment action.

## Linked Issues or Issue Description

Refs #3678

**What happened?**

The issue comment runtime can call the prior send function after a
render. The callback refs do not update until passive effects run.

**Expected behavior**

The stable runtime adapter must call the newest function as soon as the
render supplies it.

**Steps to reproduce**

1. Render the issue runtime with one send function.
2. Render it again with a new send function and the same thread data.
3. Call the stable adapter before passive effects run.
4. Observe that the prior send function runs.

**Paperclip version or commit**

`6395cae072`

**Deployment mode**

Local development from source.

**Agent adapter(s) involved**

This is a core UI bug. It is not adapter-specific.

## What Changed

- Update the latest send and cancel refs during render.
- Keep the external-store adapter stable across callback-only renders.
- Add a test for a runtime callback before passive effects run.

## Verification

- `pnpm --filter @paperclipai/ui exec vitest run
src/hooks/usePaperclipIssueRuntime.test.tsx`
- `pnpm --filter @paperclipai/ui typecheck`
- `pnpm check:token-gates`
- `pnpm -r typecheck`
- `pnpm test:run`
- `pnpm build`

## Risks

- Low risk. The change only updates two refs earlier in the same render.
- The adapter identity and its data dependencies do not change.

> This bug fix does not add or overlap with a roadmap feature.

## Model Used

- OpenAI Codex with GPT-5. The exact deployed model ID and context
window are not exposed. Reasoning, tool use, and local code execution
were enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-03 06:52:49 -05:00
DottaandPaperclip cc67d4e1d8 fix: preserve steering and recover stopped task conversations (#15015)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - A task conversation must let a user guide a running agent and resume
stopped work.
> - The active run owns its input protocol, even when the user changes
the next model or effort.
> - Queue delivery waits for a provider receipt, which must be able to
persist during the request.
> - A stopped startup also needs a clear user action that passes normal
task admission.
> - This pull request fixes steering delivery, makes queue actions
immediate, and restores explicit continuation.
> - The benefit is a responsive conversation that can recover without
losing saved input.

## Linked Issues or Issue Description

**What happened?**

A queued message could change from Steer to Interrupt while a native run
prepared. A steer request could wait on its own database lock and fail
to deliver. A stopped startup could then leave the conversation without
a working Retry or message continuation. Interrupt also waited for the
server and showed a toast.

**Expected behavior**

The active run keeps its input protocol. Steer delivers input to that
run. Steer and Interrupt clear the submitted queue rows and show the
input in the conversation immediately. Failed delivery restores the
latest queue with an inline error. An eligible stopped run offers Retry,
and authenticated user input can start a fresh turn through normal task
admission.

**Steps to reproduce**

1. Start a task with a native Paperclip Runner.
2. Change the selected model or effort while that run prepares.
3. Queue a message and press Steer.
4. Observe the provider receipt and queue state during the request.
5. Stop a startup before its provider process begins, then try Retry or
send a new message.
6. Repeat queued delivery with a legacy runner and press Interrupt.

**Paperclip version or commit**

Reproduced on the parent of this branch, `59c07ede7`.

**Deployment mode**

Authenticated private deployment. The fixes also cover local task
conversations.

Related work: Refs #12834, Refs #13354, Refs #13275. The open refactor
in #13160 moves the same queue route; it does not fix the receipt lock
or stopped-run continuation addressed here.

## What Changed

- Select queue behavior from the active run's immutable dispatch and
runtime resolution.
- Leave the run row unlocked during provider acknowledgement, then lock
and read it before merging the receipt.
- Retain queued input if the target run stops during that wait. Keep
inline delivery errors visible after empty queue updates.
- Permit exact Retry and authenticated continuation after verified
native startup cancellation. Preserve pause, approval, budget,
ownership, and process-stop gates.
- Carry undelivered native queue input into a fresh turn once the old
execution is confirmed stopped.
- Show Steer and Interrupt input in the conversation and clear submitted
composer rows immediately. Restore the latest queue inline on failure.
Remove delivery toasts.
- Keep optimistic delivery stable across stale polls, empty queues, and
paginated history. Preserve classic Interrupt error handling.
- Document recovery and optimistic delivery behavior. Add regression
tests across server, shared queue projection, and UI boundaries.

## Verification

- Red-green regression tests reproduced the queue protocol, receipt
lock, stopped-startup continuation, and optimistic delivery failures.
- The focused server route, continuation, queue, and runner boundary
suites passed during implementation.
- The queue-route suite passes with 78 tests. The three complete
conversation UI suites pass with 347 tests.
- UI typecheck, production build, and `pnpm check:token-gates` pass.
- Workspace `pnpm -r typecheck` and `pnpm build` pass. The local
monolithic `pnpm test:run` is still running; remote CI verifies the
complete suite on the latest commit.
- All CI gates pass on `bd9031ad56abfcde13d13a13488c1b9217c2fd3a`,
including the full test shards, runner verification, browser E2E,
typecheck, release registry, and canary dry run.
- Greptile reports 5/5 for that commit. Both review threads are
resolved.

## Risks

This changes queue display and explicit continuation admission. The UI
must restore rejected delivery without losing other-session edits. The
server must preserve concurrent provider result updates and must not
resume a process whose stop is uncertain. Focused tests cover these
boundaries. This change has no database migration.

## Model Used

OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and
context window are not exposed in this session. Used reasoning,
repository tools, code execution, and browser inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 22:07:14 -05:00
59c07ede72 fix(ui): let a selected saved subscription be used without a tile click (#14996)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - A user creates an agent in the New Agent flow and connects a model
provider in the model step.
> - When a saved subscription exists, the step shows it as the selected
default and labels the primary button "Use saved subscription".
> - The button stays disabled until the user clicks the provider tile,
which adds no auth step on this path.
> - This extra click is a papercut: the visible choice looks ready but
does not work.
> - This pull request lets a selected saved subscription enable the
button without the tile click.
> - The benefit is one less confusing step, with no change to new
sign-ins or API keys.

## Linked Issues or Issue Description

No public issue exists. The description follows the bug template.

**What happened**
In New Agent > Connect model, choose a provider that has a saved
subscription (for example OpenAI with a saved default). The saved
subscription shows as selected and the primary button reads "Use saved
subscription". The button stays disabled until you click the provider
tile.

**Expected behavior**
The button is enabled when a saved subscription is selected. A click on
it reuses that subscription.

**Steps to reproduce**
1. Have a saved OpenAI subscription.
2. Open New Agent and go to the model connection step for a Codex agent.
3. Do not click the OpenAI Subscription tile.
4. See that "Use saved subscription" is disabled.

**Paperclip version or commit**
master at `4abff286c`.

## What Changed

- `AgentProviderConnection.tsx`: the `!opened` gate on the footer
primary button no longer applies when `method === "subscription"` and a
saved subscription is selected. All other disabled conditions stay
(pending auth, loading saved keys, login readiness, API key input).
- `connect()` never reads `opened`, so no auth step is skipped. New
sign-ins and API keys still require the user to open the provider tile.
- `AgentProviderConnection.test.tsx`: a regression test that renders the
initial state (tile not opened, saved subscription selected) and expects
the button to be enabled and to connect with the saved subscription. A
guard test checks that a new sign-in still requires opening the tile.

## Verification

- `cd ui && npx vitest run src/components/new-agent
src/components/ai-connections --no-file-parallelism`: 6 files, 64/64
tests pass.
- The new regression test fails on master and passes with this change.
- `pnpm --filter @paperclipai/ui typecheck`: 0 errors.
- `node scripts/check-token-gates.mjs`: all gates clean.
- Component QA in Storybook (real component, provider verification
simulated): before, the button is disabled and skipped by Tab until the
tile click. After, a direct click and Tab+Enter both connect, with
exactly one verification callback. Selecting a new subscription still
requires opening the tile.
- Full-app before/after QA with a disposable empty backend and a
simulated provider response: same result.
- Not tested: a live OpenAI sign-in. Repo-wide `pnpm -r typecheck`,
`pnpm test:run` and `pnpm build` are left to CI.

Manual check: open New Agent with a saved subscription, go to the model
step, and click "Use saved subscription" without clicking the tile.

## Risks

- Low risk. The change is one condition in one component.
- If a future change makes `connect()` depend on the tile being opened
for saved subscriptions, this path would skip that work. The comment at
the condition records why the gate is skipped.
- Open PR #14698 edits nearby lines in the same component. A small merge
conflict is possible.

## Model Used

- Claude Opus 5.5 (`claude-opus-5-5`), Anthropic, via Claude Code with
tool use (shell, file edit, browser automation). Extended reasoning on.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: scotttong <squadbot000@users.noreply.github.com>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 17:19:45 -07:00
DottaandPaperclip d7bdfc422c fix(ui): show agent avatar and align chat header controls (#14726)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - Agent chat shows which agent receives each message.
> - The chat header used initials instead of the agent avatar.
> - The name and controls did not use the same center alignment.
> - This change uses the shared avatar and centers the header content.
> - Users can identify the agent and open its settings from the same
row.

## Linked Issues or Issue Description

**What happened?**
The agent chat header showed initials instead of the agent avatar. The
settings control did not align with the name and avatar.

**Expected behavior**
Show the agent avatar. Put the avatar, name, and settings control on the
same horizontal center line.

**Steps to reproduce**
1. Enable Agent Chat in Experimental settings.
2. Open a conversation with an agent that has an appearance set.
3. Check the avatar and settings control in the top bar.

Related navigation work: #14706.

## What Changed

- Use `AgentAvatar` in the conversation breadcrumb.
- Update the breadcrumb key when the agent appearance changes.
- Center breadcrumb labels that have an adjacent action. Keep task
identifier baseline alignment unchanged.
- Add regression checks for avatar props, appearance changes, and center
alignment.

## Verification

- PASS: affected Vitest suites, 129 tests.
- PASS: `pnpm check:token-gates`.
- PASS: `pnpm --filter @paperclipai/ui typecheck` on an isolated retry.
- PASS: `pnpm --filter @paperclipai/ui build`.
- PASS: browser checks at 1000 and 390 CSS pixels. Avatar, name, and
settings control all have center Y = 29.5 CSS pixels.
- Screenshots use the real header and avatar renderer with isolated
context fixtures. No screenshot or fixture is part of this diff.
- Full typecheck and build cannot complete because Cargo is not
installed.
- Full tests stopped with SIGKILL. The first UI typecheck also stopped
with exit 137. These runs do not prove full-suite success.

## Risks

- Low risk. The change only affects UI rendering. It changes no API or
database contract.
- Breadcrumbs with adjacent actions now use center alignment. Ordinary
task identifiers keep baseline alignment.

## Model Used

OpenAI Codex agent, with code editing, shell tools, and browser checks.
The runtime did not expose the exact model ID or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [ ] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

No behavior or command documentation needs an update for this rendering
fix. The execution environment requires the assigned branch name to stay
unchanged. Pending review gates are not marked complete.

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 22:06:50 +00:00
Devin FoleyandPaperclip 5b8b2b38ca feat(apps): add Neon connection (#14980)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents reach external services through the Apps catalog. Each
catalog entry is a reviewed `AppDefinition` that wires a provider's
hosted MCP server into Paperclip's shared vault, grants, policies,
gateway, and audit trail.
> - Neon is a widely used serverless Postgres provider with an official
hosted MCP server, but it is not in the catalog. Teams that run their
databases on Neon must use the generic "connect your own MCP server"
path, which has no branding, no guidance, and no project or read-only
controls.
> - The connector playbook requires a catalog entry for a provider like
this: the hosted server supports dynamic client registration and bearer
API keys, and the common definition fields can express every option
Paperclip can serialize.
> - This pull request adds the Neon definition, its official artwork,
the research and permission-review ledger rows, documentation, and
deterministic tests, without any provider-specific runtime code.
> - The benefit is a one-click, governed Neon connection with optional
project pinning and read-only mode, and a documented path to live
qualification.

## Linked Issues or Issue Description

**Problem or motivation**

Neon is a common Postgres host for the applications agents work on, but
Paperclip's Apps catalog has no Neon entry. Operators who want agents to
inspect schemas, run SQL, or manage branches must paste the MCP URL into
the generic remote-MCP flow, which gives no branding, no provider
guidance, no project boundary, and no read-only switch.

**Proposed solution**

Add a catalog-only Neon connection built from the connector playbook:
browser sign-in through Neon's dynamic client registration with the
reviewed `read` and `write` scopes, or a customer API key sent as an
Authorization bearer header. Both methods expose Neon's documented
`projectId` pin and `readonly` switch as optional Advanced fields. Every
discovered tool stays governed by the normal per-action policies.

**Alternatives considered**

A plugin was not needed because no custom UI, tables, workers, or
webhooks are involved. A separate read-only method was not added because
the playbook treats read-only switches as advanced fields rather than
methods. Neon's repeatable `category` query filter was left out because
tenant fields serialize lists as one comma-joined value, so it cannot be
sent correctly without new runtime code; per-action policies cover
catalog narrowing instead.

**Roadmap alignment**

This extends the existing self-serve remote-MCP connection catalog and
does not overlap planned core work.

## What Changed

- Added the `neon` provider to `scripts/ingest-app-definitions.mjs`
(category, API-key placement, methods, tenant fields, guidance,
warnings) and regenerated
`packages/shared/src/app-definitions/neon.json` plus the generated
registry.
- Added the Neon row to the self-serve MCP research ledger with
`dcr_or_api_key` auth and risk tier S4.
- Added permission reviews for `neon/mcp-oauth` (explicit scopes `read`,
`write`, taken from Neon's live authorization-server metadata) and
`neon/mcp-api-key` (provider key), with evidence links.
- Added Neon's official tile icon (`ui/public/brands/apps/neon.png`,
copied byte-for-byte from the icon linked by neon.com) and the brand
manifest entry.
- Added prosumer gallery copy for the Neon card.
- Added `doc/connections/NEON.md` (service involvement, endpoints,
administrator setup, capabilities and policy, manifest, brand
provenance, validation hook) and linked it from the connections README
and the permission audit.
- Tests: Neon definition shape, store visibility and artwork, URL
recognition, reviewed scopes with scope-widening rejection, URL
projection of the project pin and read-only flag, invalid project ID
rejection, the connect form's API-key gating, and the pinned catalog
counts.

## Verification

- `pnpm exec vitest run packages/shared/src/app-definitions.test.ts
packages/shared/src/app-definitions-url.test.ts` — 34 passed.
- `pnpm exec vitest run
server/src/__tests__/tool-access-service.test.ts` — 367 passed.
- `pnpm exec vitest run ui/src/pages/apps/AppsConnect.test.tsx
ui/src/pages/apps/Browse.test.tsx ui/src/lib/app-brand-assets.test.ts
ui/src/pages/apps/AppLogo.brand-assets.test.tsx` — all passed.
- `node scripts/check-app-brand-assets.mjs` and `node --test
scripts/app-brand-validation.test.mjs` — passed.
- `pnpm --filter @paperclipai/shared typecheck`, `pnpm --filter
@paperclipai/server typecheck`, `pnpm --filter @paperclipai/ui
typecheck`, `pnpm check:token-gates` — clean.
- Manual: in a local instance, open Apps → Browse, confirm the Neon card
and icon, open `/apps/connect?source=neon`, confirm both methods, the
Advanced project pin and read-only toggle, and that Connect enables
after an API key is entered. The operator completed a live connection
against a Neon account on this build.
- Live metadata probed on 2026-10-02: both `.well-known` documents at
`mcp.neon.tech` return the recorded endpoints and scopes; an
unauthenticated `initialize` returns 401 with `resource_metadata`.

## Risks

- Low risk to existing providers: the change is additive catalog data
plus tests. The generated registry only gains one import.
- Neon's hosted server grants broad project and database management. The
definition carries two warnings, recommends a development project, and
keeps every write under the normal action policies; the read-only switch
is enforced by Neon's server, not locally.
- The permission-review ledger records live proof for both methods as
not run; the full lifecycle checklist in `doc/connections/NEON.md` still
needs a documented pass before the entry is considered fully qualified.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- Claude Fable 5.1 (`claude-fable-5-1`) in Claude Code, with extended
thinking and tool use (shell, file editing, browser verification).

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 15:04:52 -07:00
abderrahmen bejaouiandabderbj 92ad158ce1 fix(claude-local): order Claude models the way the Claude app does (#14917)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Each agent runs on an adapter, and the operator picks the agent's
model from a list the adapter advertises.
> - The `claude_local` adapter advertises a static list and merges in
the models the Anthropic API returns. Neither list has a deliberate
order.
> - The model dropdown then sorts every list by id. For Claude this
shows "Fable 5", "Fable 5.1", "Haiku 4.5", "Mythos 5", "Opus 4.6" ...
which is not the order of capability, release, or version (#14877).
> - This pull request gives the adapter one defined order, the one the
Claude app uses: the newest release of each family first, by decreasing
capability, then older releases grouped by family. The server applies it
to discovered models, and the dropdown keeps the adapter's order instead
of re-sorting.
> - The benefit is that a user who knows the Claude app finds the right
model at once, and older models sit at the end of the list.

## Linked Issues or Issue Description

Fixes #14877.

Related: #14147 touches the same adapter's model list (the
`ANTHROPIC_MODEL` default label) and does not change ordering. #14878 is
the Codex counterpart and depends on the dropdown change in this PR.

## What Changed

- `packages/adapters/claude-local/src/server/model-order.ts` (new):
`sortClaudeModels()` and `parseClaudeModelId()`. The parser reads the
current scheme (`claude-opus-4-8`), the legacy scheme
(`claude-3-7-sonnet-20250219`), dated snapshots, `-latest` aliases, the
`[1m]` suffix, and Bedrock ids (`us.anthropic.…-v1`, `…-v2:0`). The sort
puts the newest release of each family first (Fable, Mythos, Opus,
Sonnet, Haiku), then older releases grouped by family with versions
descending. An alias sorts before its dated snapshots, and dated
snapshots of one release sort newest first. Ids that are not Claude
models keep their incoming order at the end.
- `packages/adapters/claude-local/src/server/models.ts`: apply the order
to the static fallback, to the merged API list, and to the Bedrock list.
Reorder `BEDROCK_MODELS` to match.
- `packages/adapters/claude-local/src/index.ts`: reorder the advertised
`models` list to the same order.
- `ui/src/components/AgentConfigForm.tsx`: `ModelDropdown` gets a
`preserveOrder` prop. With it the dropdown shows the list as the adapter
ordered it; without it the list is sorted by id as before.
`ui/src/lib/model-utils.ts` adds `adapterCuratesModelOrder()`, true for
the built-in adapters whose list arrives in a deliberate order
(`claude_local`, `codex_local`, `paperclip_runner`, `gemini_local`,
`grok_local`, `kimi_local`, `openclaw_gateway`, and `opencode_local` /
`pi_local`, which the server sorts when discovered and which lead with
the default model when it falls back to the declared list). Cursor is
not in the set because its list comes from `agent models` discovery, and
adapters not named there, including externally installed ones, keep the
alphabetical fallback. The three dropdown call sites (`AgentConfigForm`,
`ConfigureBuiltInAgentModal`, `NewAgentSetup`) pass it; `NewAgentSetup`
decides by the resolved brand type, because a `paperclip_runner` agent
fetches the Claude or Codex list for its brand. Grouped lists
(`opencode_local`, `pi_local`) are unchanged.
- Tests: `model-order.test.ts` (adapter, including the snapshot-date
tie-breaker), `ModelDropdown.test.tsx` (ui: preserved order with the
prop, alphabetical without it, provider groups unchanged),
`model-utils.test.ts` (which adapters opt in), and two updated
expectations plus one new order assertion in
`server/src/__tests__/adapter-models.test.ts`.

Mythos is not in the Claude app's list. This PR ranks it directly after
Fable, in the top capability tier. The rank table in `model-order.ts` is
one line to change if you prefer a different slot.

## Verification

Run from the repository root:

```sh
pnpm exec vitest run packages/adapters/claude-local server/src/__tests__/adapter-models.test.ts ui/src/lib/model-utils.test.ts ui/src/components/ModelDropdown.test.tsx ui/src/components/AgentConfigForm.render.test.tsx ui/src/components/ConfigureBuiltInAgentModal.test.tsx ui/src/pages/NewAgent.test.tsx
pnpm --filter @paperclipai/adapter-claude-local typecheck
pnpm --filter @paperclipai/ui typecheck
pnpm --filter @paperclipai/server typecheck
pnpm check:module-boundaries && pnpm check:token-gates && pnpm check:tokens
```

Red on `master`, green here:

- `ModelDropdown.test.tsx` fails against the unmodified dropdown because
the ids come back sorted alphabetically even with `preserveOrder`.
- `adapter-models.test.ts` fails against the unmodified adapter because
the first model is `claude-opus-4-8`, not `claude-fable-5-1`.

Manual check: open an agent that uses `claude_local`, open the model
dropdown. With no `ANTHROPIC_API_KEY` the list reads Fable 5.1, Mythos
5, Opus 5.5, Sonnet 5, Haiku 4.5, Fable 5, Opus 5, Opus 4.8, Opus 4.7,
Opus 4.6, Sonnet 4.6, Sonnet 4.5. With a key, the discovered models slot
into the same order.

## Risks

- The other built-in adapters in the set (Gemini with `Auto` first,
Grok, Kimi, OpenClaw, the runner's Codex list, and the OpenCode and Pi
lists in the built-in-agent modal) are now shown as their adapter
delivers them instead of alphabetized. Cursor's discovered list and
every adapter outside the set, including externally installed ones, keep
the alphabetical order they had, so no option moves between refreshes.
Grouped lists are unchanged.
- The first entry of the Claude list changes from Opus 4.8 to Fable 5.1.
Nothing reads the first entry as a default: `DEFAULT_CLAUDE_LOCAL_MODEL`
is `claude-opus-5` and is resolved separately.
- No API, schema, or migration change.

## Model Used

Anthropic Claude Fable 5.1 (`claude-fable-5-1`) through Claude Code,
extended thinking on, with tool use for reading the repository, running
vitest and tsc, and editing files. The account holder reviewed the
change and owns the commit.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: abderbj <115119179+abderbj@users.noreply.github.com>
2026-10-02 13:24:04 -07:00
DottaandPaperclip 43f391e807 refactor(slack): clarify browser setup prompt from live testing (#14965)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Slack chat connections let people start and continue agent work from
Slack.
> - The setup prompt guides an agent through the Paperclip and Slack
browser interfaces.
> - A live setup completed, but several instructions did not match the
current interfaces.
> - Those gaps can send users to the wrong connection flow or leave them
waiting for controls that do not appear.
> - This pull request updates the prompt with the steps observed during
the live setup.
> - The benefit is a clearer path from a fresh instance to a verified
Slack conversation.

## Linked Issues or Issue Description

Refs: #13920 and #14862. The first added the Slack conversation flow.
The second updated the shared setup prompt control. A search found no
duplicate open PR or matching public issue.

**Issue type**

Outdated instructions and missing setup guidance.

**Where is the issue?**

`ui/src/pages/apps/chat/SlackSetupPrompt.tsx`

**What's wrong?**

The prompt omits the Chat connectors setting on fresh instances. It uses
an old navigation label. It assumes an avatar crop dialog and a Save
button always appear. It also assumes the suggested bot username matches
Slack and that the Slack reply contains a task link.

**Suggested fix**

Use the current labels. Explain the feature prerequisite, avatar save
behavior, real mention selection, clipboard recovery, and the path to
task and run evidence.

## What Changed

- Add the Chat connectors prerequisite and current Connectors, resume,
and identity-link labels.
- Explain Slack's combined Create and Install action and how to continue
from its success page.
- Handle avatar uploads that save immediately. Require a reload to
confirm the saved icon.
- Select the real bot from Slack's mention suggestions, including names
with punctuation.
- Recover from an empty or stale clipboard without exposing credentials.
- Find the linked task through Conversations and inspect the agent's
Runs page.

## Verification

- `pnpm exec vitest run
ui/src/pages/apps/chat/SlackSetupPrompt.test.tsx`: 10 tests passed after
rebasing onto current master.
- `git diff --check origin/master...HEAD`: passed.
- `pnpm build`: passed.
- `pnpm -r typecheck`: passed.
- `pnpm check:token-gates`: passed.
- Full Vitest suite: passed in CI for this commit, including all server,
chat, workspace, and serialized test shards. The duplicate local `pnpm
test:run` was stopped after CI finished; it did not complete locally.
- Current-commit CI: all checks passed, including build, typecheck, E2E,
Runner verification, and canary dry run. Greptile rated the change 5/5
with no findings or unresolved review threads.
- Live browser test before the wording update: created and installed a
new Slack app, verified the callback, uploaded and reopened the avatar,
linked the configuring user's identity, and enabled the selected test
channel. The first mention received a reply. A follow-up without another
mention recalled the first message. Both agent runs succeeded.
- The wording update does not repeat Slack app installation. Existing
tests verify the complete copied prompt, clipboard fallback, and
instance URL handling.
- This is a prompt-text refactor. No runtime behavior changes, so the
existing tests cover the copied result without a new test that repeats
the wording.

## Risks

- Low risk. This change updates prompt text in one file.
- Provider interfaces can change. The prompt tells the agent to inspect
the current page and handle optional controls.
- The prompt handles the observed mention mismatch. This change does not
alter the generated suggested username.

## Model Used

- OpenAI Codex, based on GPT-6, with reasoning, repository tools, code
execution, and browser automation. The session does not expose an exact
runtime model ID or context window size. The live test also used an
earlier model whose exact ID was not exposed.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 15:11:05 -05:00
Devin FoleyandPaperclip 144083fd48 fix(interactions): wait for workspace readiness before enabling approval (#14893)
## Thinking Path

> - Paperclip lets people manage AI agents and review their work.
> - Task confirmations must use the work produced by their source run.
> - The server blocks approval while that run still needs to sync its
workspace.
> - The card currently enables approval before that check can pass, so
an ordinary click produces an error.
> - This PR exposes the existing readiness check and shows “Preparing
approval…” with acceptance disabled.
> - The card refreshes itself and enables approval when the source
workspace settles.

## Linked Issues or Issue Description

**What happened?**

A confirmation appears while its source run is still preparing or
syncing its workspace. Its enabled approval button returns a conflict
asking the user to retry after syncing.

**Steps to reproduce**

1. Run an agent in an isolated workspace.
2. Have it create a confirmation before workspace finalization
completes.
3. Click the approval button while the source workspace is still active.

**Expected behavior**

The card explains that approval is preparing. Acceptance becomes
available automatically when the same server check permits it. Reject
and revise remain available.

Related work: #10770 handles this conflict after a click with retries.
#9520 proposes changing the workspace acceptance barrier. This PR
preserves that barrier and exposes readiness before the click, including
in compact task chat. It preserves the terminal-finalize behavior from
#10099.

## What Changed

- Add an optional, read-only `acceptanceBlocker` to interaction
responses. Readiness uses the existing source-run workspace predicate,
with one check per pending source run.
- Disable acceptance and show a shared preparation notice in classic and
compact confirmation cards, including checkbox and secret-binding
confirmations.
- Refresh preparing cards every two seconds in task detail, attention,
pipelines, and Skill Studio. Restore each surface's previous polling
cadence when preparation clears.
- Preserve live tool reviews, questions, rejection, revision, and the
server acceptance barrier. No automatic acceptance occurs.
- Document the preparation state and cover readiness, terminal sync
outcomes, unrelated runs, historical cards, and automatic refresh.

## Verification

- Focused service, card, query-refresh, and helper tests: 217 passed
across five files.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- `pnpm build-storybook`: passed.
- `pnpm check:token-gates`: passed.
- `pnpm test:run`: incomplete locally. Stopped after about 17 minutes
once it reproduced seven existing environment failures: two Slack tests
and two email tests lack ancestor-directory skill fixtures; three
company-skills tests fail on macOS runtime-cache staging permissions.
These are outside this change. The full CI test matrix passed.
- CI: all 53 checks passed; two optional Storybook jobs were skipped.
The branch has no conflicts with `master`.
- Greptile: 5/5 on commit `8a6f216d8d`, with no review threads.
- Reviewed added lines and new files for credentials, private URLs,
internal task references, user paths, and run artifacts. None found.

## Risks

- No database migration or change to acceptance authorization. Readiness
is advisory; the server still enforces its existing gate at acceptance.
- An open preparing card adds a read every two seconds. This cadence
stops after readiness clears; historical cards add no workspace checks.
- Failed or stale finalization retains the existing server behavior.
This PR does not change recovery policy.

## Model Used

OpenAI GPT-6 through Codex. The exact serving model ID and
context-window size are not exposed in this session. Used reasoning,
repository inspection, tool execution, and automated tests. No
sub-agents.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (217 focused tests; full
local-suite limitations are recorded above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 13:08:25 -07:00
DottaandPaperclip 7a52dcdc74 fix: repair MCP validation and cancelled execution recovery (#14951)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The tool gateway gives agents access to connected services. Recovery
controls what happens when a run stops.
> - Generated tool names can exceed the provider limit after the MCP
client adds its prefix.
> - The same invalid definition can fail each automatic retry. A
cancelled run can also hold saved messages without showing its cause.
> - This pull request bounds tool names, stops configuration retries,
and retains cancellation evidence.
> - It shows the stopped run and admits saved input only after the
existing safety checks pass.
> - The benefit is a clear recovery path that preserves operator Stop
and prevents duplicate message delivery.

## Linked Issues or Issue Description

**What happened?**

A long connected MCP tool name makes the provider reject the entire
request. Automatic recovery repeats the invalid request. Separately,
unexpected legacy cancellations can leave saved input behind a recovery
hold. The notice does not identify the stopped run or its cause.

**Expected behavior**

Complete MCP names fit the provider limit. Tool-definition errors
require configuration repair. Cancelled runs retain their source and
reason. The recovery notice shows the cause and saved-message count.
Verified unexpected cancellations can start a fresh turn through the
existing admission checks.

**Steps to reproduce**

1. Assign an App gallery connection with a long application key and tool
name to a Claude agent.
2. Start a run. The provider rejects a name over 128 characters,
including its MCP prefix.
3. For cancellation recovery, stop a legacy provider turn without an
operator Stop request and send a user message while the recovery hold is
active.
4. Inspect the recovery notice and the deferred message queue.

**Paperclip version or commit**

Rebased onto master at `cf8ad63c806685bfd7c48e3ed4a919d61a7c55f1`.

**Deployment mode**

Hosted or self-hosted server with legacy Claude or Codex execution.

Related public work:

- Refs #14017. That PR caps name segments. This PR preserves existing
short names and uses stable hash aliases for long complete names. It
also covers classification and recovery.
- Refs #4510. That PR adds a cancellation-source column. This PR records
bounded evidence in the existing run result, without a migration.
- Refs #12552 and #4506. Those PRs suppress recovery after operator
cancellation. This PR preserves operator intent and uses the existing
continuation gates.

## What Changed

- Bound gateway names with the full provider prefix in the 128-character
budget. Retain the original upstream tool name for dispatch and
permissions.
- Classify invalid tool definitions as configuration failures before
diagnostic redaction. Stop automatic retries and continuation attempts
for that error code.
- Persist cancellation source, expectedness, initiator, reason, and
time. Preserve recorded Stop intent when adapter results arrive. Report
unexpected started cancellations with closed diagnostic labels.
- Show the run cause, saved-message count, and Inspect run link. Offer
Continue for eligible unexpected cancellations. Require verified
provider stop, empty tool inventory, ownership, and the existing pause,
budget, approval, and dependency gates. Use the existing queue for
single delivery.
- Add regression coverage and update the execution, MCP gateway, and
run-log documentation.

## Verification

- `pnpm -r typecheck` and `pnpm build` passed.
- `pnpm check:token-gates` passed.
- Ran `pnpm test:run` and completed its workspace and serialized groups.
Initial resource and timing failures passed on isolated reruns. All 149
serialized route suites passed.
- Reran the changed server, adapter, and UI suites after the rebase.
Coverage includes long-name upstream dispatch, configuration retry
suppression, cancellation evidence retention, privacy labels, oversized
run projection, and concurrent saved-message delivery.
- `pnpm test:e2e tests/e2e/legacy-failure-continuation.spec.ts` passed
all six browser scenarios. The recovery notice shows the run cause and
inspection link, and each recovery entry point reaches one new response.
- Added database-backed checks for active, removed, paused, unavailable,
and disabled chat connections. The final continuation and
recovery-notice suites passed 167 tests. Externally bound chats hide
board Continue and show a usable next action.
- All 55 GitHub checks passed on
`42afbf1371dcaeb72646e3d8f65c19ff7cddf8de`. Two unrelated Storybook jobs
were skipped by their normal conditions. Greptile reviewed that commit
at 5/5 with no findings and no open review threads.

## Risks

- Long tool names change to aliases. Existing short names stay
compatible. The original connection and upstream name remain the
dispatch authority.
- Invalid tool definitions no longer get automatic retries. An operator
must repair the configuration before a new attempt.
- Continuation changes apply only to positively identified unexpected
legacy cancellations with complete empty tool inventory. Operator Stop,
unknown historical cancellations, outstanding tools, and unverified
provider termination keep their holds.
- No database migration. The added projection fields are optional.
Cancellation reason and initiator IDs remain local run evidence; Sentry
receives only closed source and initiator-type labels and expectedness.

## Model Used

- OpenAI GPT-6 through Codex, with reasoning, repository editing, shell
execution, and GitHub tool use. The runtime does not expose the exact
model variant or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 13:47:59 -05:00
DottaandPaperclip 7d59de6113 feat(connections): probe provider usage limits on demand (#14936)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections store the AI accounts used by legacy and native runners.
> - Subscription accounts can reach session, weekly, model, or paid
usage limits.
> - Operators need to read these limits for a specific stored account
before making a routing decision.
> - This pull request adds an on-demand usage probe to the connection
service and account detail.
> - The result preserves provider limits, reset times, paid usage, and
unknown values for later consumers.

## Linked Issues or Issue Description

**Subsystem affected**

Shared contracts, the connection service and API, and the account detail
UI.

**Problem or motivation**

Managed AI accounts lack a common operation to read their current usage
limits. A local harness probe can read a different login from the
account selected for an agent.

**Proposed solution**

Add `aiConnectionService.probeUsage()` and a board-only connection usage
endpoint. Probe the selected credential grant on request. Support Codex,
Claude, and Grok subscriptions, plus OpenRouter API key limits.

**Alternatives considered**

Harness-specific automatic polling would couple the read to execution
and can read ambient credentials. This change uses the managed
connection credential and leaves scheduling and admission decisions to
later work.

**Roadmap alignment**

This extends the existing Personal & Shared AI Accounts capability. It
adds no routing or quota enforcement. Related: Refs #14459 for managed
OpenAI quota reads; Refs #14781 and Refs #13379 for downstream pacing
and budget work. This operation reads one requested account across all
three subscription providers.

## What Changed

- Add typed usage snapshots and a probe capability flag to managed AI
connections.
- Normalize Codex, Claude, Grok, and OpenRouter responses. Keep model
scopes, provider admission, reset periods, and paid allowances separate.
Preserve unknown values.
- Enforce company membership, credential audience, grant identity, and
connection lifecycle before reading the stored secret.
- Add a board-only `GET
/api/companies/:companyId/ai-connections/:connectionId/usage` endpoint
with `no-store` responses.
- Add manual **Check usage** and **Refresh** actions to account details.
Show compact usage bars, resets, admission and overage status; remove
repeated descriptions and account-default copy. Clear previous results
during a new request or error.
- Add Storybook previews using the production account components for all
four providers, initial checks, loading, and permission errors.
- Add provider, authorization, runner selection, API, and UI coverage.
Document provider sources and live qualification.

## Verification

- Initial provider, authorization, selection, API, and UI validation
passed (96 focused tests): `pnpm exec vitest run
server/src/services/ai-connection-usage.test.ts
server/src/__tests__/ai-connections.test.ts
ui/src/components/ai-connections/AiConnectionUsagePanel.test.tsx
server/src/__tests__/openapi-routes.test.ts`.
- `pnpm -r typecheck` passes for the initial implementation. After
simplifying the UI, 9 usage-panel and date-helper tests, UI typecheck,
token gates, and Storybook build pass. The initial feature module
boundary check also passed.
- Real Codex, Claude, and Grok credentials were saved to encrypted
disposable connections. The actual usage HTTP route returned 200 with
`status: ok`. Legacy and native runner selection checks passed. The
tests started no model turn and exchanged no refresh token. The
disposable databases and vaults were removed.
- Live Claude responses added structured scoped limits. Live Grok
responses omitted included-plan usage. Tests now cover both shapes and
preserve the Grok omission as unknown.
- The full workspace build passes. A full local test run hit a heartbeat
feedback timeout. That case passes in isolation. The duplicate local run
was stopped after all remote checks passed. The Slack ordering and
OpenCode transport CI flakes also pass in isolation and on the CI rerun.


- Current head: `ff3d479029a1c4248190323e221b2803cfb0d79d`. All 54
active checks pass. Two Storybook checks are intentionally skipped by
the workflow. Greptile is 5/5 with no unresolved review findings; the
branch is mergeable.

## Risks

- Subscription usage endpoints can change. Credentials can lack
usage-read permission. The probe returns explicit errors without fresh
limits in these cases.
- A successful probe can contain partial data. Missing utilization or
admission remains unknown. An enabled paid-usage switch does not prove a
funded balance.
- This change adds no migration. It does not change runner admission or
automatic provider selection. Provider requests use fixed endpoints,
disabled redirects, bounded response sizes, and a 15-second deadline.

## Model Used

OpenAI Codex, GPT-6, with reasoning, file editing, shell execution, and
HTTP tools. The session does not expose the exact runtime model variant
or context window size. Real provider credentials were used only for the
authorized live checks.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 11:47:14 -05:00
DottaandPaperclip 6c1a75da49 feat(connections): make AgentMail a default connection with inline setup (#14772)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections give agents access to external services.
> - AgentMail needs both a saved key and an inbox assigned to the agent.
> - Chat requests offered a setup link instead of an inline card and
could treat a saved key as complete.
> - Inbox setup also hid address conflicts behind a generic server error
and a separate review step.
> - This pull request makes AgentMail a default connection, adds the
inline card, reduces setup to two steps, and shows conflicts beside the
address.
> - Shared native dropdown styles also give every caret a consistent
inset.

## Linked Issues or Issue Description

**What happened?**

AgentMail requests in chat did not show a usable inline connection card.
Manual setup required extra screens, ignored saved account keys, and
could trap new-address setup in a locked inbox dropdown. Agent selectors
omitted the avatar from the selected value. A taken address could
produce an HTTP 403 from AgentMail and appear as an internal server
error. Native dropdown arrows also touched the right edge of their
fields.

**Expected behavior**

Make AgentMail available as a default connection. Ask for the API key
inline, with a direct link to its provider page. Default human access to
the company and agent access to the requesting agent. Resume the agent
only after an assigned inbox is active. Manual setup should ask for an
agent and email address, then finish. Address checks should run as the
user types. Taken addresses should show clickable alternatives. A domain
dropdown beside the name should prefer a verified custom domain. Setup
should suggest authorized saved AgentMail keys and show agent avatars in
the picker and selected value.

**Steps to reproduce**

1. Ask an agent to connect AgentMail when it has no assigned inbox.
2. Check that an inline API-key card appears and links to the provider's
API-key page.
3. Open AgentMail setup, choose an agent, and request an address that is
already taken.
4. Correct the inline error, refresh, and finish setup with the same
request ID.
5. Inspect native dropdown carets in light, dark, disabled, and
right-to-left states.

Uses the bounded provider-error parser merged in #14768. Related work:
#13256 introduced AgentMail; #14725 expanded connection search.

## What Changed

- Stop recurring email queries for tasks that have no email thread.
Share the query between the thread provider and activity view. Keep
email-task updates and invalidation-based discovery.
- Make AgentMail available without the experimental chat setting. Keep
the catalog, setup and management routes, agent Channels tab, task email
feed, receiving worker, and agent tools available by default. Other
experimental chat providers stay gated.

- Make the email address and copy icon a single clickable action with
the shared Copied! confirmation. Add View inbox linking directly to the
matching AgentMail console inbox, with the address encoded as one URL
path segment.

- Reorganize inbox Settings around the copyable email address, usage
instructions, and receiving status. Move reconnect credentials into a
disclosure and separate the Disconnect action. Add production Settings
stories for active, paused, unassigned-address, revoked, webhook,
long-address, mobile, and reconnect states. Show repair controls when
the inbox has an error. Keep usage instructions tied to an active inbox
with an address.

- Add AgentMail channel intents and an inline key field with the direct
API-key URL.
- Keep setup and retry state tied to the interaction. Require an active
inbox for completion. Preserve company and agent access checks.
- Reduce manual setup to agent selection and email selection. Put the
domain dropdown beside the address and default to a verified custom
domain. Preserve explicit choices across reloads. Keep receiving
settings under Advanced options.
- Check the initial address and edits after a 350 ms pause. Abort
superseded requests and ignore stale responses. Show clickable
suggestions and retain known creation conflicts across reloads.
- Add a company-scoped, manager-only address check using the saved
credential. Search the visible inbox list instead of fetching an
uncreated inbox: live AgentMail retains negative lookups that can break
subsequent access-key creation. Unlisted addresses remain unknown;
creation is authoritative.
- Suggest labeled saved AgentMail keys in both manual setup and the
inline card. Filter by company, provider, active credential, and
current-user grants on the server. Prefer an account key and preserve
the selected key or an explicit new-key choice across refresh. Use
verified scope metadata and bounded concurrent checks for legacy keys.
Never return secret values.
- Catch an inbox-only key before the email step. Allow its existing
inbox only after an explicit choice. Recover old locked drafts at the
key picker. Save the replacement key before retiring an empty draft,
then use a new setup URL so refresh preserves the switched account; stop
if cleanup fails. Preserve already allocated addresses and their
original accounts.
- Use the shared AgentSelect in email setup. Show the canonical agent
avatar in each option and the selected value, including other consumers
of the shared component. Add regression coverage for legacy and current
Lucide agent-mention icon formats.
- Start each catalog Add connection with a fresh setup identity. Honor
Finish setup's exact draft/account/address instead of resuming an
unrelated browser draft. Return Cancel and Done to Connectors and Email
settings to the inbox. Group the task/thread explanation in a How it
Works card.
- Route AgentMail catalog removal through the email inbox control API,
including unfinished drafts. Refresh both the catalog and inbox views.
- Render each inbox management tab separately. Access uses the saved
account grants and agent controls; Conversations and Activity use the
shared persisted email feed. Activity lifecycle actions use the email
API. Reconnect returns to inbox Settings. Conversation failures show a
retry instead of a false empty state. Email delivery recovery stays in
the task.
- Map documented provider address conflicts to a field error. Preserve
actionable messages for other failures.
- Preserve non-secret draft fields across refresh, scoped to the
requested agent. Never save API keys in browser storage. Resume partial
inbox creation with the original agent, address, and request ID.
- Show an already-created address with explicit retry and new-address
recovery instead of locked inputs. Preserve the original inbox and
resumable draft when choosing another address. Distinguish runtime-key
404 errors and log safe provider status/operation/code.
- Apply final agent access once within email setup authorization for a
new account whose original installs are unchanged. Preserve later
permission edits and reused account installs. Support in-place retry of
progress loading.
- Let a failed inline setup change keys after retiring an empty draft.
Persist its replacement setup identity without storing secrets. Recover
a server-saved account when refresh interrupts the save response, while
preserving intentional account changes.
- Render the production setup in Storybook and add error, recovery, and
mobile states.
- Inset native select carets in shared CSS. Preserve custom icons,
listboxes, keyboard behavior, and forced-color controls.
- Add browser regression coverage and an AgentMail Product E2E case with
persisted-state and rendered-card evidence.

## Verification

- Full `pnpm -r typecheck`, `pnpm build`, `pnpm check:token-gates`, and
`git diff --check` passed after the default-availability change.
- All 485 focused tests passed. These cover setup, management, catalog
and route gates, connection intents, email authorization, Cursor
execution, and the OpenAPI contract. All 39 email integration tests run
with the experimental chat setting off.
- The shared polling change passed four behavioral tests, UI typecheck
and build, and token gates.
- `tests/e2e/agentmail.spec.ts` passed with the actual server setting
off. This full-stack browser test uses simulated provider responses. It
covers catalog entry, saved keys, editable address and domain controls,
creation, conflicts, retry, all management tabs, clipboard feedback, the
provider link, and task email rendering.
- In the live local browser, Add connection reached the editable email
step with the saved account key. The verified custom domain was selected
by default. Both domain choices worked. The existing inbox Settings page
remained available. Both active inboxes completed new mail checks with
the setting off. No new provider inbox or email message was created for
this pass.
- Earlier live provider acceptance covered creation on a verified custom
domain, Finish connecting on the reported draft, successful mail checks
after refresh, and catalog removal of disposable draft and active
connections. Clicking the email address copied the exact address and
showed Copied!. View inbox opened the same inbox in AgentMail’s console.
No email messages were sent.
- Production setup and Settings Storybook builds and interactions
passed. Settings states include active, paused, unassigned, revoked,
webhook, long-address, mobile, and reconnect. Receiving and
revoked-access stories had zero accessibility violations.
- Full local `pnpm test:run` on an earlier revision completed with
14,709 passing, 87 skipped, and four transient failures. All four failed
cases passed in focused reruns without product changes. That serial full
local command was not repeated after each follow-up. The latest-head
full CI suite is the final test gate.
- CI found an obsolete browser assertion that hid every channel when the
flag was off. Updated it to keep AgentMail and the Channels surface
visible while preserving the GitHub chat route gates. All 11 provider
browser tests passed locally after scoping the Channels selector to the
agent sidebar. Two initial local attempts stopped at temporary Postgres
initialization. The passing run used a separate disposable database on
the existing local Postgres server; it was removed after the test.
- Updated the remaining sidebar and aggregator discovery assertions for
default AgentMail availability. Ordinary task fixtures now return no
email thread. All 128 sidebar/task-page tests and all 42 aggregator
tests passed locally.
- Latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`: full CI
passed, with 54 successful checks including Snyk and two intentional
Storybook skips. The CI run is
https://github.com/paperclipai/paperclip/actions/runs/37020833647. A
fresh Greptile review scored 5/5 with no unresolved threads. Live model
evaluations and inbound/outbound email delivery were not run.

## Risks

- AgentMail no longer needs experimental opt-in. Setup still requires a
human to connect an account and assign an inbox. Inline setup creates an
inbox after a human submits a new or saved key. Company access, agent
access, inbox assignment, and completion checks remain enforced.
- AgentMail read APIs cannot prove global address availability. The
visible-list check is bounded to 100 entries and cannot see inboxes
outside the key’s scope. The UI reports this limitation, suggests
alternatives without claiming they are free, and keeps final creation
conflicts inline. Lookup outages show an error without preventing the
authoritative creation attempt.
- Native select CSS affects the whole app. Custom-icon selects and
multi-row lists are excluded. Forced-color mode keeps the browser caret.
- Saved-key discovery uses stored verified scope metadata and checks
authorized legacy credentials concurrently within a shared three-second
deadline. Provider outages mark legacy choices unavailable; users can
still enter another key. Final use rechecks authorization and provider
access.
- No database migration or transport default change. Live connection
remains the default.

## Model Used

OpenAI Codex, GPT-6, with reasoning, tool use, and code execution. The
exact served model ID and context-window size are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused suites; full-suite
limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green (latest head
`b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`)
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`)
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 10:01:15 -05:00
DottaandPaperclip ec3bacc9bd fix(chat): hide ignored provider information (#14929)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Task and agent chats show agent progress and problems that need
attention.
> - Codex also sends account, skill, and unrelated thread notifications.
> - The runner correctly ignores that information but reports it as a
warning.
> - Chat then shows an internal diagnostic as an actionable provider
notice.
> - This pull request keeps the diagnostic in run logs and removes it
from chat.
> - Real provider warnings, errors, and agent replies remain visible.

## Linked Issues or Issue Description

**What happened?**

Chat showed “Received a provider update” and a warning with the text
“ignored
unrelated provider information”. Its details said “User Actionable: Yes”
even
though no user action was needed. Saved conversations retained the same
noise.

**Expected behavior**

Keep ignored provider information in the run log. Do not show it as chat
activity
or a user warning. Preserve real warnings and errors.

**Steps to reproduce**

1. Start a conversation with the native Codex runner.
2. Have the provider send an account update, skill change, or unrelated
thread
   notification during the turn.
3. Inspect live chat and reload its saved history.

The regression tests also reproduce the old stored notice without a live
account.

**Paperclip version or commit**

Source implementation on master at `e00d10d5d`. The duplicate search
found no
open PR for this fix. Related prior work: #13109 improved
provider-notice
presentation. #12367 added Codex thread normalization. This change
addresses
the internal information that those paths still projected as chat
warnings.

**Deployment mode**

Native Paperclip Runner with the Codex app-server provider. The issue
was seen
in hosted chat and can be reproduced with local provider fixtures.

## What Changed

- Map ignored unrelated Codex information to `harness.diagnostic` in the
Rust
  and TypeScript normalizers.
- Retain a bounded allowlist of redacted provider method and thread/turn
identifiers.
- Use the same Unicode character limit and truncation marker in both
normalizers.
- Share the text redactor through a pure helper. Keep provider
connection code
  out of the standalone demo's source closure.
- Omit that diagnostic and the matching legacy notice from live chat.
- Omit the matching legacy notice from saved chat history.
- Test diagnostic retention, account-notification integration, live and
saved
  chat, and continued visibility of real warnings, errors, and replies.
- Document the local run-log event and historical display behavior.

## Verification

- Passed: 68 tests in the two affected UI transcript suites.
- Passed: 60 TypeScript tests across provider events, transport
behavior, and
  the standalone demo boundary.
- Passed: 13 Rust provider-event tests and the Codex
account-notification
  integration test.
- Passed: `pnpm check:token-gates` and Cargo formatting checks.
- Passed: full `pnpm build` and `pnpm -r typecheck`. After the review
fix,
the provider package build, typecheck, and both provider-event suites
passed again.
- Full local `pnpm test:run` failed: 608 files / 10,904 tests passed, 30
server
suites failed, and 104 files / 4,012 tests were skipped. Most failures
were
  embedded PostgreSQL startup errors. Two tests timed out in
`heartbeat-comment-wake-batching` and
`workspace-git-snapshot-streaming`.
  PostgreSQL startup also failed in `heartbeat-run-event-sequencing` and
`native-finalization-migration`. These server files are unchanged by
this PR.
Isolated heartbeat reruns were skipped locally. The stable test script
stopped
  after this general-server group, so later groups did not run locally.
- The original review thread is resolved. Greptile is 5/5 on current
head
  `683dab7cce57187c57e84c83f5e9da4ad75c9c04`.
- All current-head CI gates passed, including the full
server/chat/workspace
test matrix, Rust and TypeScript runner suites, browser E2E, build,
typecheck,
and release canary. [CI
run](https://github.com/paperclipai/paperclip/actions/runs/37021330663).
- Replay the exact old warning in either transcript adapter. It must
produce
no chat row. A genuine provider warning or error must still produce a
row.

## Risks

- Low risk. The display filter matches one diagnostic code or the
complete
  legacy warning shape. Other provider notices remain visible.
- New ignored-information events use the existing harness-diagnostic
event
type. They retain diagnostic evidence without original account payloads.
- No database migration, API permission, provider execution, or recovery
  behavior changes. This affects the local run log, not Telemetry or
  OpenTelemetry exports.

## Model Used

OpenAI Codex, GPT-6. The exact backend model ID and context-window size
are
not exposed in this session. Used reasoning, repository inspection, code
editing, tool use, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run the affected tests locally and they pass (the broad
local run has PostgreSQL startup errors and timeouts documented above;
the full CI matrix passed)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 09:59:34 -05:00
DottaandPaperclip e00d10d5d5 fix(connections): repair stale AI defaults from agent settings (#14916)
## Thinking Path

> - Paperclip manages AI agents and controls the credentials used for
their work.
> - Managed AI connections resolve each responsible user's provider
default.
> - Agent settings created another account but kept the old default
selected.
> - A rejected provider test left the old account marked as connected.
> - Claude ACP reported a typed login failure as a generic
terminal-access error.
> - This pull request repairs the selected account or selects the new
login explicitly.
> - Agents can save and run with the repaired credential, and failed
logins request sign-in.

## Linked Issues or Issue Description

- Fixes #14831.
- Refs #13867. Environment failures remain separate from
credential-health failures.

## What Changed

- Add an agent-settings action to reconnect an unavailable personal
default in place. Keep its connection, grant, default, and agent access.
- State that a new account becomes the user's provider default. Select
its returned grant before changing the agent binding. Keep the actual
sign-in method.
- Show default-update errors and allow retry without another provider
login.
- Show the agent-access choice. Connection managers start with
company-wide access for their own tasks. Other members start with access
for the current agent.
- Use the server's connection-manager permission in the shared list
response. This includes members with a custom management grant.
- Mark credentials as needing attention after an explicit login
rejection in Test or Save. This includes API-key 401 and 403 responses.
Network, quota, and server failures keep the credential health
unchanged.
- Reuse the credential-generation check so an old failure cannot
invalidate a newer reconnect.
- Route Claude's typed provider `access` failure to the existing
login-recovery flow. Replace its generic terminal-access fallback with a
sign-in message.
- Add regression tests and update the AI Connections documentation.

## Verification

- Red: the UI tests failed on the missing reconnect action, unused
returned grant, missing access choice, and lost default-update error.
The server tests failed because rejected credentials stayed connected.
The real ACP fixture returned `acpx_turn_failed` for typed login
failures.
- Green: 156 tests passed across the AI connection, hiring, agent field,
and New Agent suites. All 37 environment-route tests passed. The Claude
ACP authentication fixtures also passed.
- `pnpm check:token-gates` passed.
- `pnpm -r typecheck` passed.
- `pnpm build` passed.
- The full local `pnpm test:run` passed 707 files and 14,503 tests, then
exited with an agent-conversation timeout and embedded PostgreSQL
startup failures in unchanged suites. The isolated conversation and
migration tests passed on rerun. Later local test groups did not run
after this failure.
- [All CI gates
passed](https://github.com/paperclipai/paperclip/actions/runs/37012669356)
on commit `38513dfe2`. This includes the full test matrix, browser
tests, typecheck, build, Runner checks, and canary dry run.
- Greptile reviewed commit `38513dfe2` and returned 5/5 with no open
findings.
- The regression tests use a real embedded database and a real ACP
fixture process. Live provider sign-in requires a valid account and was
not run.

## Risks

- Connecting a new account from agent settings changes the user's
provider default. The dialog states this before sign-in.
- The displayed access choice can allow all company agents to use the
account for its owner's tasks. Reconnect keeps the existing access.
Server permissions still control installs.
- Claude's typed `access` category maps to the provider's
`auth_required` signal. Tool and workspace request failures retain their
existing classification.
- No database migration or provider credential format changes are
required.

## Model Used

- OpenAI GPT-6 through Codex. The exact served model identifier and
context window are not exposed in this session. Capabilities used:
reasoning, repository tools, code editing, and command execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:57:52 -05:00
dependabot[bot] c83df091b1 build(deps): bump react-i18next from 17.0.12 to 17.0.15 (#12970)
Bumps [react-i18next](https://github.com/i18next/react-i18next) from
17.0.12 to 17.0.15.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md">react-i18next's
changelog</a>.</em></p>
<blockquote>
<h2>17.0.15</h2>
<ul>
<li>fix(Trans): empty paired component tags now preserve a component's
single valid React-element child, whether supplied through a named
component map (<code>&lt;wrap&gt;&lt;/wrap&gt;</code>), a component
array (<code>&lt;0&gt;&lt;/0&gt;</code>), or indexed JSX children
(<code>&lt;1&gt;&lt;/1&gt;</code>). This matches the existing behavior
for two or more children and self-closing tags. React represents one JSX
child as an element and multiple children as an array; the previous
array-only check silently rendered the one-child case empty.
Compatibility note: when that sole element contains an interpolation
object, the restored raw children can expose an existing React rendering
limitation as an error instead of silently rendering empty; the same
shape already errors with two children. Fixes <a
href="https://redirect.github.com/i18next/react-i18next/issues/1932">#1932</a>.</li>
</ul>
<h2>17.0.14</h2>
<ul>
<li>fix: the <code>i18n</code> object returned by
<code>useTranslation</code> was only refreshed when
<code>i18n.language</code> changed, so a <code>resolvedLanguage</code>
(or <code>languages</code>) change of its own kept handing components
the previous snapshot. That happens whenever the translations for the
current language arrive after the switch — i18next resolves to the
fallback until its store has them — and components reading
<code>i18n.resolvedLanguage</code> (language switchers, for example)
then stayed one switch behind. The cached wrapper is now keyed on all
three language fields, which are exactly the ones the surrounding
<code>useMemo</code> already depends on; wrapper identity still only
changes when the language state does, so the caching from <a
href="https://redirect.github.com/i18next/react-i18next/issues/1885">#1885</a>
is unaffected. Reported via <a
href="https://redirect.github.com/i18next/next-i18next/issues/2348">next-i18next#2348</a>.</li>
</ul>
<h2>17.0.13</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>useTranslation()</code> is now available under
<code>enableSelector: 'strict'</code>. <code>useTranslation</code> was
gated on <code>true | 'optimize'</code> only, so under
<code>'strict'</code> it resolved to the legacy signature and the
selector overload disappeared entirely (<code>keyPrefix: ($) =&gt;
$.ns.foo</code> failed with <code>Type '($: any) =&gt; any' is not
assignable to type 'undefined'</code>). <code>Trans</code> already
handled all three modes. Companion to the same fix for
<code>getFixedT</code> in <a
href="https://redirect.github.com/i18next/i18next/pull/2446">i18next#2446</a>.
Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/react-i18next/pull/1930">#1930</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/i18next/react-i18next/commit/7d38e0919507f0d339ac29b9fbd5f718eaadc829"><code>7d38e09</code></a>
17.0.15</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/875b327d3515c781cd083dd77d3d8838dc1efc06"><code>875b327</code></a>
fix(Trans): preserve single-element children in empty slots</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/5f8c5f9e6c7cdabdc476111d0748c91e33bbaa30"><code>5f8c5f9</code></a>
17.0.14</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/6def81a790ddc55cc6c09a9f306ea6c88e25867c"><code>6def81a</code></a>
fix: refresh the returned i18n wrapper when resolvedLanguage
changes</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/f37ea872c74e74ca64a5b6652cc131893405770b"><code>f37ea87</code></a>
docs: &quot;For AI assistants&quot; paragraph in the README</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/e0592bafde1a904588c115f67b36cddf382e49c5"><code>e0592ba</code></a>
chore: keep dev-only and local files out of the npm package</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/addf646a37f5980af08814b5a2568def28e7e428"><code>addf646</code></a>
17.0.13</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/7c634ee3f396af22ec7b5c3c647b8d5ab198b5ae"><code>7c634ee</code></a>
changelog v17.0.13</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/5ceefb0eff8bb430c658b21e5a08b457e78d87df"><code>5ceefb0</code></a>
fix(types): allow selector keyPrefix in useTranslation under
enableSelector '...</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/aa7ba520255753c50d7fff9ab33ce0c7a60a45a2"><code>aa7ba52</code></a>
chore(examples): require activesupport &gt;= 7.2.3.1 in the RN
Gemfiles</li>
<li>Additional commits viewable in <a
href="https://github.com/i18next/react-i18next/compare/v17.0.12...v17.0.15">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 22:06:28 -07:00
dependabot[bot] f48bbba2ba build(deps): bump @assistant-ui/react from 0.15.21 to 0.15.22 (#12971)
Bumps
[@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react)
from 0.15.21 to 0.15.22.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/releases">@​assistant-ui/react's
releases</a>.</em></p>
<blockquote>
<h2><code>@​assistant-ui/react</code><a
href="https://github.com/0"><code>@​0</code></a>.15.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
- fix: type the assistant transport request body that
<code>prepareSendCommandsRequest</code> receives; its fields are no
longer <code>unknown</code> in <code>@assistant-ui/react</code>, and
<code>threadId</code> is an optional <code>string</code>, absent when a
resume has no remote id, instead of <code>string | null</code> (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a>
- feat: <code>useAssistantTransportRuntime</code> accepts
<code>cloud</code>: Assistant Cloud backs the thread list and every
request carries the cloud thread id; without <code>cloud</code>,
<code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as
it does for <code>useLocalRuntime</code>. <code>adapters.history</code>,
which this runtime never read, is deprecated (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a>
- fix: lock the current scroll container after reasoning content or its
ancestor chain changes (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a>
- fix: prevent stale message hover updates after unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a>
- fix: scope selection toolbars to their owning thread (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
- feat: <code>CloudRendererHost</code> draws a stored conversation in
the Assistant Cloud dashboard's As shown view with the app's own
components; a read only thread now reports itself disabled, so its
composer renders disabled, and ignores composer input instead of
throwing (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
- feat: show a message with uploading attachments in the thread while it
is being sent (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>MessagePrimitive.Attachments</code> now hands its render
function <code>Attachment</code> rather than
<code>CompleteAttachment</code>, because the row of a message that is
still being sent shows attachments that are still uploading. a render
function that reads <code>attachment.content</code> should check
<code>attachment.status.type === &quot;complete&quot;</code> first.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a>
- fix: honor registered data-part fallbacks on native MessageContent and
grouped parts (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a>
- fix: emit declarations from one TypeScript program so two builds of
the same commit produce the same <code>.d.ts</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>aui-build</code> now emits the unbundled <code>.d.ts</code>
output in one TypeScript pass over the whole package, so two builds of
the same commit produce identical declarations; the per-module emit it
replaced followed the bundler's load order and let union member order,
alias visibility and import specifiers move between builds. Declarations
import barrels as the source does and keep <code>import type</code>; the
exported types are unchanged. A <code>/// &lt;reference&gt;</code>
directive that must reach the published declarations now carries
<code>preserve=&quot;true&quot;</code> in the source.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a>
- fix: every distribution re-exports the same shared surface from
<code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code>
gains <code>ReadonlyThreadProvider</code>,
<code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>,
<code>GroupByContext</code>, <code>VoiceSessionState</code>, the
external store runtime (<code>useExternalStoreRuntime</code>,
<code>useExternalMessageConverter</code>, their adapters and options),
the message queue, the tool approval types, the generative UI renderer
and the cloud thread list hooks; <code>@assistant-ui/react-native</code>
gains <code>VoiceSessionState</code>, the cloud thread list hooks, the
generative UI renderer and the runtime state and adapter types the web
package already carried; <code>@assistant-ui/react</code> gains
<code>MessageRole</code>, <code>RunConfig</code>,
<code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>,
<code>ThreadsState</code>, <code>JoinStrategy</code>,
<code>TitleGenerationAdapter</code>,
<code>createSimpleTitleAdapter</code> and
<code>ChainOfThoughtPartByIndexProvider</code>. (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a>
- fix(react): attach the ExportMarkdown download anchor to the document
so Firefox starts the download (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
- fix: prevent disabled attachment dropzones from navigating to dropped
files. (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a>
- fix: clear attachment drag state when the dropzone is disabled (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
- fix(react): stop a pending bottom scroll from hijacking
keyboard-driven content growth (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a>
- fix: resolve component registries by own keys only, so a component,
tool or data part name that only <code>Object.prototype</code> has
(<code>toString</code>, <code>constructor</code>,
<code>__proto__</code>) takes the <code>Fallback</code> or
<code>GenerativeUIRenderError</code> path instead of rendering the
inherited built-in (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a>
- fix: expose feedback submission state to assistive technology (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
- feat: name the runtime state types <code>ThreadRuntimeState</code>,
<code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>,
<code>AttachmentRuntimeState</code> and
<code>ThreadListItemRuntimeState</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p>these are the states <code>ThreadRuntime</code>,
<code>MessageRuntime</code>, <code>ComposerRuntime</code>,
<code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code>
return from <code>getState()</code>, now exported by all three
distributions; <code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code> had no name for them. in
<code>@assistant-ui/react</code>, <code>ThreadState</code>,
<code>MessageState</code>, <code>ComposerState</code>,
<code>AttachmentState</code> and <code>ThreadListItemState</code> still
name these runtime states but are deprecated: from 0.16 they name the
store states <code>useAuiState</code> reads, as they already do in
<code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code>. code that annotates a runtime's
<code>getState()</code> result should move to the new names.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
- fix(react): keep the selection toolbar in sync after a right-click, so
a context menu that swallows the mouseup no longer leaves it showing
(and quoting) the previous selection (<a
href="https://github.com/samdickson22"><code>@​samdickson22</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
- feat: a tool UI can record what the user did on its tool call with
<code>unstable_recordInteraction</code>, kept on the part as
<code>unstable_interactions</code> and stored in cloud history; the
answer to a human input request is recorded once the runtime accepts it,
the local runtime persists records and keeps them out of model input,
external stores receive them through
<code>unstable_onRecordToolInteraction</code>, and readonly threads
ignore them (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a>
- fix: Use successful Standard Schema output for tool execution and
model output. Keep the original arguments for validation errors and
stored tool calls. (<a
href="https://github.com/ephraimduncan"><code>@​ephraimduncan</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7777">#7777</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c51ba8fb3014375ae62784084aaefe3ecc6d72fa"><code>c51ba8f</code></a>
- feat(core): let typed text enter a connected voice session through
<code>sendText</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@​assistant-ui/react's
changelog</a>.</em></p>
<blockquote>
<h2>0.15.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
- fix: type the assistant transport request body that
<code>prepareSendCommandsRequest</code> receives; its fields are no
longer <code>unknown</code> in <code>@assistant-ui/react</code>, and
<code>threadId</code> is an optional <code>string</code>, absent when a
resume has no remote id, instead of <code>string | null</code> (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a>
- feat: <code>useAssistantTransportRuntime</code> accepts
<code>cloud</code>: Assistant Cloud backs the thread list and every
request carries the cloud thread id; without <code>cloud</code>,
<code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as
it does for <code>useLocalRuntime</code>. <code>adapters.history</code>,
which this runtime never read, is deprecated (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a>
- fix: lock the current scroll container after reasoning content or its
ancestor chain changes (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a>
- fix: prevent stale message hover updates after unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a>
- fix: scope selection toolbars to their owning thread (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
- feat: <code>CloudRendererHost</code> draws a stored conversation in
the Assistant Cloud dashboard's As shown view with the app's own
components; a read only thread now reports itself disabled, so its
composer renders disabled, and ignores composer input instead of
throwing (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
- feat: show a message with uploading attachments in the thread while it
is being sent (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>MessagePrimitive.Attachments</code> now hands its render
function <code>Attachment</code> rather than
<code>CompleteAttachment</code>, because the row of a message that is
still being sent shows attachments that are still uploading. a render
function that reads <code>attachment.content</code> should check
<code>attachment.status.type === &quot;complete&quot;</code> first.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a>
- fix: honor registered data-part fallbacks on native MessageContent and
grouped parts (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a>
- fix: emit declarations from one TypeScript program so two builds of
the same commit produce the same <code>.d.ts</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>aui-build</code> now emits the unbundled <code>.d.ts</code>
output in one TypeScript pass over the whole package, so two builds of
the same commit produce identical declarations; the per-module emit it
replaced followed the bundler's load order and let union member order,
alias visibility and import specifiers move between builds. Declarations
import barrels as the source does and keep <code>import type</code>; the
exported types are unchanged. A <code>/// &lt;reference&gt;</code>
directive that must reach the published declarations now carries
<code>preserve=&quot;true&quot;</code> in the source.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a>
- fix: every distribution re-exports the same shared surface from
<code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code>
gains <code>ReadonlyThreadProvider</code>,
<code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>,
<code>GroupByContext</code>, <code>VoiceSessionState</code>, the
external store runtime (<code>useExternalStoreRuntime</code>,
<code>useExternalMessageConverter</code>, their adapters and options),
the message queue, the tool approval types, the generative UI renderer
and the cloud thread list hooks; <code>@assistant-ui/react-native</code>
gains <code>VoiceSessionState</code>, the cloud thread list hooks, the
generative UI renderer and the runtime state and adapter types the web
package already carried; <code>@assistant-ui/react</code> gains
<code>MessageRole</code>, <code>RunConfig</code>,
<code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>,
<code>ThreadsState</code>, <code>JoinStrategy</code>,
<code>TitleGenerationAdapter</code>,
<code>createSimpleTitleAdapter</code> and
<code>ChainOfThoughtPartByIndexProvider</code>. (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a>
- fix(react): attach the ExportMarkdown download anchor to the document
so Firefox starts the download (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
- fix: prevent disabled attachment dropzones from navigating to dropped
files. (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a>
- fix: clear attachment drag state when the dropzone is disabled (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
- fix(react): stop a pending bottom scroll from hijacking
keyboard-driven content growth (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a>
- fix: resolve component registries by own keys only, so a component,
tool or data part name that only <code>Object.prototype</code> has
(<code>toString</code>, <code>constructor</code>,
<code>__proto__</code>) takes the <code>Fallback</code> or
<code>GenerativeUIRenderError</code> path instead of rendering the
inherited built-in (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a>
- fix: expose feedback submission state to assistive technology (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
- feat: name the runtime state types <code>ThreadRuntimeState</code>,
<code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>,
<code>AttachmentRuntimeState</code> and
<code>ThreadListItemRuntimeState</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p>these are the states <code>ThreadRuntime</code>,
<code>MessageRuntime</code>, <code>ComposerRuntime</code>,
<code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code>
return from <code>getState()</code>, now exported by all three
distributions; <code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code> had no name for them. in
<code>@assistant-ui/react</code>, <code>ThreadState</code>,
<code>MessageState</code>, <code>ComposerState</code>,
<code>AttachmentState</code> and <code>ThreadListItemState</code> still
name these runtime states but are deprecated: from 0.16 they name the
store states <code>useAuiState</code> reads, as they already do in
<code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code>. code that annotates a runtime's
<code>getState()</code> result should move to the new names.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
- fix(react): keep the selection toolbar in sync after a right-click, so
a context menu that swallows the mouseup no longer leaves it showing
(and quoting) the previous selection (<a
href="https://github.com/samdickson22"><code>@​samdickson22</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
- feat: a tool UI can record what the user did on its tool call with
<code>unstable_recordInteraction</code>, kept on the part as
<code>unstable_interactions</code> and stored in cloud history; the
answer to a human input request is recorded once the runtime accepts it,
the local runtime persists records and keeps them out of model input,
external stores receive them through
<code>unstable_onRecordToolInteraction</code>, and readonly threads
ignore them (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a>
- fix: Use successful Standard Schema output for tool execution and
model output. Keep the original arguments for validation errors and
stored tool calls. (<a
href="https://github.com/ephraimduncan"><code>@​ephraimduncan</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/f008537f39f0936992b0f6d2433c092935df5faf"><code>f008537</code></a>
chore: update versions (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7724">#7724</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
feat(react): CloudRendererHost draws a stored conversation in the
dashboard's...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
fix(react): keep the selection toolbar quoting what is selected after a
right...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
feat(core): record the user's interactions with a tool ui on its tool
call (#...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
feat(core): show a message with uploading attachments while it is sent
(<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8030">#8030</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
fix: type the assistant transport body that prepareSendCommandsRequest
receiv...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
fix(react): claim file drops when attachment dropzone is disabled (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8010">#8010</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
feat: name the runtime state types and deprecate their old names (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7981">#7981</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/15937b8844db7757d3595d5644bc27196e742f4a"><code>15937b8</code></a>
test(react): skip the initial viewport scroll in the MessageRoot hover
test (...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
fix(react): cancel pending bottom scroll on a keyboard gesture (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7897">#7897</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.22/packages/react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 21:36:32 -07:00
dependabot[bot] 3934fd14e5 build(deps-dev): bump @storybook/addon-docs from 10.5.10 to 10.6.0 (#12972)
Bumps
[@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">@​storybook/addon-docs's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@​storybook/addon-docs's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a>
Bump version from &quot;10.6.0-beta.0&quot; to &quot;10.6.0-beta.1&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a>
Bump version from &quot;10.6.0-alpha.9&quot; to
&quot;10.6.0-beta.0&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a>
Bump version from &quot;10.6.0-alpha.8&quot; to
&quot;10.6.0-alpha.9&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a>
Bump version from &quot;10.6.0-alpha.7&quot; to
&quot;10.6.0-alpha.8&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/3bf4afdce8aba47cc7960d3a3e09a3fd1ceb2baa"><code>3bf4afd</code></a>
Merge branch 'next' into kasper/tools-cli-bootstrap-perf</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/4ea0b1bc2c1a26ce061f5b44051e8f01273f27fa"><code>4ea0b1b</code></a>
refactor(docs): move anchorBlockIdFromId into docs-tools</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/5c80681f18d273461e1b15cb775a77347079b0b0"><code>5c80681</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35965">#35965</a>
from storybookjs/valentin/sb-1804-surface-story-doc...</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/docs">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 21:14:09 -07:00
dependabot[bot] 479554120d build(deps): bump i18next from 26.4.0 to 26.4.2 (#12973)
Bumps [i18next](https://github.com/i18next/i18next) from 26.4.0 to
26.4.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/i18next/releases">i18next's
releases</a>.</em></p>
<blockquote>
<h2>v26.4.2</h2>
<ul>
<li>fix: <code>$&amp;</code>, <code>$`</code>, <code>$'</code> and
<code>$$</code> inside a nested value (<code>$t(key)</code>) now stay
literal. <code>nest()</code> handed the resolved value straight to
<code>String.replace</code> as the replacement argument, so those
sequences were read as replacement patterns: <code>$&amp;</code>
re-inserted the <code>$t(...)</code> match, <code>$`</code> /
<code>$'</code> inserted the text before / after it, and <code>$$</code>
collapsed to <code>$</code>. Through <code>t()</code> the
<code>$&amp;</code> case was worse than a wrong string: the nested
lookup resets the shared nesting regexp, so the re-inserted
<code>$t(...)</code> was matched again on every pass and
<code>t()</code> never returned — also under the default
<code>escapeValue: true</code> when the value arrives via a variable
forwarded through nesting options (<code>$t(key, { &quot;name&quot;:
&quot;{{name}}&quot; })</code> with a name containing
<code>$&amp;</code>). The value is now <code>$</code>-escaped at the
<code>String.replace</code> call, the same guard
<code>interpolate()</code> already has, and a non-string value returned
by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is
stringified before that. Nested values are still not HTML-escaped (<a
href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>).
Thanks <a href="https://github.com/mahirhir"><code>@​mahirhir</code></a>
(<a
href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li>
</ul>
<h2>v26.4.1</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>getFixedT()</code> is now available under <code>enableSelector:
'strict'</code>. Its constraint was gated on <code>true |
'optimize'</code> only, so under <code>'strict'</code> it collapsed to
<code>never</code>, the overload dropped out, and the returned
<code>t</code> silently lost its <code>keyPrefix</code> scope
(<code>t(($) =&gt; $.deep)</code> failed with <code>Property 'deep' does
not exist on type '{}'</code>). The same call already typechecked under
<code>true</code> and <code>'optimize'</code>. Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's
changelog</a>.</em></p>
<blockquote>
<h2>26.4.2</h2>
<ul>
<li>fix: <code>$&amp;</code>, <code>$`</code>, <code>$'</code> and
<code>$$</code> inside a nested value (<code>$t(key)</code>) now stay
literal. <code>nest()</code> handed the resolved value straight to
<code>String.replace</code> as the replacement argument, so those
sequences were read as replacement patterns: <code>$&amp;</code>
re-inserted the <code>$t(...)</code> match, <code>$`</code> /
<code>$'</code> inserted the text before / after it, and <code>$$</code>
collapsed to <code>$</code>. Through <code>t()</code> the
<code>$&amp;</code> case was worse than a wrong string: the nested
lookup resets the shared nesting regexp, so the re-inserted
<code>$t(...)</code> was matched again on every pass and
<code>t()</code> never returned — also under the default
<code>escapeValue: true</code> when the value arrives via a variable
forwarded through nesting options (<code>$t(key, { &quot;name&quot;:
&quot;{{name}}&quot; })</code> with a name containing
<code>$&amp;</code>). The value is now <code>$</code>-escaped at the
<code>String.replace</code> call, the same guard
<code>interpolate()</code> already has, and a non-string value returned
by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is
stringified before that. Nested values are still not HTML-escaped (<a
href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>).
Thanks <a href="https://github.com/mahirhir"><code>@​mahirhir</code></a>
(<a
href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li>
</ul>
<h2>26.4.1</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>getFixedT()</code> is now available under <code>enableSelector:
'strict'</code>. Its constraint was gated on <code>true |
'optimize'</code> only, so under <code>'strict'</code> it collapsed to
<code>never</code>, the overload dropped out, and the returned
<code>t</code> silently lost its <code>keyPrefix</code> scope
(<code>t(($) =&gt; $.deep)</code> failed with <code>Property 'deep' does
not exist on type '{}'</code>). The same call already typechecked under
<code>true</code> and <code>'optimize'</code>. Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da"><code>4dba50f</code></a>
26.4.2</li>
<li><a
href="https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009"><code>e436b62</code></a>
build</li>
<li><a
href="https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92"><code>d955fb0</code></a>
fix: stringify formatter results in nested values, changelog
v26.4.2</li>
<li><a
href="https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425"><code>dfafa3c</code></a>
fix: keep replacement patterns literal in nested values (<a
href="https://redirect.github.com/i18next/i18next/issues/2447">#2447</a>)</li>
<li><a
href="https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a"><code>3c9981e</code></a>
chore: keep dev-only and local files out of the npm package</li>
<li><a
href="https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8"><code>c057ee0</code></a>
26.4.1</li>
<li><a
href="https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2"><code>02e3e16</code></a>
changelog v26.4.1</li>
<li><a
href="https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751"><code>6f198f2</code></a>
fix(types): allow selector keyPrefix in getFixedT under enableSelector
'stric...</li>
<li>See full diff in <a
href="https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 19:58:00 -07:00
dependabot[bot] b31ce54b81 build(deps): bump react-router-dom from 7.18.2 to 7.18.4 (#12974)
Bumps
[react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom)
from 7.18.2 to 7.18.4.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md">react-router-dom's
changelog</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.4"><code>react-router@7.18.4</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.3"><code>react-router@7.18.3</code></a></li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a>
Release v7.18.4 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a>
Release v7.18.3 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15424">#15424</a>)</li>
<li>See full diff in <a
href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 19:29:44 -07:00
dependabot[bot] f07f8d9599 build(deps-dev): bump @storybook/addon-a11y from 10.5.10 to 10.6.0 (#12976)
Bumps
[@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">@​storybook/addon-a11y's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@​storybook/addon-a11y's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a>
Bump version from &quot;10.6.0-beta.0&quot; to &quot;10.6.0-beta.1&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a>
Bump version from &quot;10.6.0-alpha.9&quot; to
&quot;10.6.0-beta.0&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a>
Bump version from &quot;10.6.0-alpha.8&quot; to
&quot;10.6.0-alpha.9&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a>
Bump version from &quot;10.6.0-alpha.7&quot; to
&quot;10.6.0-alpha.8&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/898f0ce828ec8bd00985934786724b94f8428c42"><code>898f0ce</code></a>
Bump version from &quot;10.6.0-alpha.6&quot; to
&quot;10.6.0-alpha.7&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cf97b46ca1a452f6f47206fd6ed7043a88e38a60"><code>cf97b46</code></a>
Bump version from &quot;10.6.0-alpha.5&quot; to
&quot;10.6.0-alpha.6&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2b7f6be9c96f72d6eca4b80af11db1a4ff380e8e"><code>2b7f6be</code></a>
Bump version from &quot;10.6.0-alpha.4&quot; to
&quot;10.6.0-alpha.5&quot; [skip ci]</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/a11y">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 17:08:56 -07:00
dependabot[bot] 41c18aa443 build(deps-dev): bump storybook from 10.5.10 to 10.6.0 (#12984)
Bumps
[storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">storybook's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/db38cb39d9be5609bba4ac3b861b2263c21ae1b6"><code>db38cb3</code></a>
CLI: Serve skills through one path with a single expected-failure
channel</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/79bc6a63e0ecd6eb10baecb6302661da09eea1f7"><code>79bc6a6</code></a>
CLI: Address review on skills reshape; credit skills --all in eval
parser</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c11b0f2a6eb1e15b489a8c0bc17c5eace4c8a8b5"><code>c11b0f2</code></a>
CLI: Drop per-skill --help; --help always prints the catalog</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c878263a6ced94ef30148b99758bea139122f5de"><code>c878263</code></a>
CLI: Drop skills get/list, add skills --all</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c55462ef810dcf5641636a54021861f5d1d90222"><code>c55462e</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/36117">#36117</a>
from storybookjs/kasper/tools-record-storybook-path</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/8ad41c80847390d53af17342e33c94d0f87bb368"><code>8ad41c8</code></a>
CLI: Reject surplus skills arguments</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/8d607e3b18731f63e09d23ad488623f0c01224bd"><code>8d607e3</code></a>
Tools: Match Storybook installations correctly on Windows</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/core">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 16:32:07 -07:00
dependabot[bot] 67ebed8a52 build(deps): bump lucide-react from 1.45.0 to 1.48.0 (#12985)
Bumps
[lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react)
from 1.45.0 to 1.48.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lucide-icons/lucide/releases">lucide-react's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.48.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): added <code>briefcase-plus</code> icon by <a
href="https://github.com/tylerkade"><code>@​tylerkade</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4757">lucide-icons/lucide#4757</a></li>
<li>feat(icons): added <code>square-sparkles</code> icon by <a
href="https://github.com/nananecy"><code>@​nananecy</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li>
<li>feat(icons): added <code>line-dot-left-horizontal</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3855">lucide-icons/lucide#3855</a></li>
<li>fix(packages/svelte,solid): fix shared type imports in Solid and
Svelte by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4846">lucide-icons/lucide#4846</a></li>
<li>chore(deps-dev): bump react-native from 0.76.9 to 0.87.1 in the
react-native-deps group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4673">lucide-icons/lucide#4673</a></li>
<li>feat(packages): export __iconNode data across framework packages by
<a href="https://github.com/lx3133584"><code>@​lx3133584</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4761">lucide-icons/lucide#4761</a></li>
<li>fix(icons): Tweak <code>card-sim</code> chip by <a
href="https://github.com/danielbayley"><code>@​danielbayley</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3649">lucide-icons/lucide#3649</a></li>
<li>feat(icons): added <code>line-dot-top-vertical</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3856">lucide-icons/lucide#3856</a></li>
<li>feat(icons): added <code>line-dot-bottom-vertical</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3857">lucide-icons/lucide#3857</a></li>
<li>fix(packages/react-native): pass testID to the rendered Svg element
by <a href="https://github.com/OlegBezr"><code>@​OlegBezr</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li>
<li>chore(<code>@​lucide/vue</code>): Fix types <code>@lucide/vue</code>
package and added workflow for it. by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4883">lucide-icons/lucide#4883</a></li>
<li>test(packages/shared): cover buildLucideIconForReact by <a
href="https://github.com/vugarbbakhishov-hub"><code>@​vugarbbakhishov-hub</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li>
<li>feat(site): Better icon detail page and add unreleased flag by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4877">lucide-icons/lucide#4877</a></li>
<li>fix(icons): changed <code>map-pinned</code> icon by <a
href="https://github.com/jguddas"><code>@​jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4880">lucide-icons/lucide#4880</a></li>
<li>fix(icons): changed <code>mail-pen</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4899">lucide-icons/lucide#4899</a></li>
<li>chore(deps-dev): bump the angular-deps group across 1 directory with
14 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4895">lucide-icons/lucide#4895</a></li>
<li>chore(deps): bump the vue-deps group with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4893">lucide-icons/lucide#4893</a></li>
<li>chore(typchecking): More typecheck jobs for all packages by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4885">lucide-icons/lucide#4885</a></li>
<li>feat(icons): add house-cog icon by <a
href="https://github.com/ajaxjiang96"><code>@​ajaxjiang96</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/nananecy"><code>@​nananecy</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li>
<li><a href="https://github.com/OlegBezr"><code>@​OlegBezr</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li>
<li><a
href="https://github.com/vugarbbakhishov-hub"><code>@​vugarbbakhishov-hub</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li>
<li><a
href="https://github.com/ajaxjiang96"><code>@​ajaxjiang96</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0">https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0</a></p>
<h2>Version 1.47.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): add lambda icon by <a
href="https://github.com/UbaidUllah9962"><code>@​UbaidUllah9962</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li>
<li>feat(icons): delegated <code>faucet</code> icon from lab by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4764">lucide-icons/lucide#4764</a></li>
<li>feat(icons): added <code>door-closed-package</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4814">lucide-icons/lucide#4814</a></li>
<li>feat(icons): added 'nepali-rupee' icon by <a
href="https://github.com/sarajdhakal"><code>@​sarajdhakal</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li>
<li>feat(icons): added <code>tube-lotion</code> icon by <a
href="https://github.com/AlecRust"><code>@​AlecRust</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li>
<li>feat(icons): Added cupcake icon by <a
href="https://github.com/briz123"><code>@​briz123</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3000">lucide-icons/lucide#3000</a></li>
<li>feat(icons): added square-dashed-x icon by <a
href="https://github.com/EthanHazel"><code>@​EthanHazel</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4535">lucide-icons/lucide#4535</a></li>
<li>feat(icons): add <code>rotate-cw-clock</code> icon by <a
href="https://github.com/gkkconan"><code>@​gkkconan</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li>
<li>fix(icons): remove path from save-off by <a
href="https://github.com/HPRILLER"><code>@​HPRILLER</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4848">lucide-icons/lucide#4848</a></li>
<li>fix(icons): changed <code>calendar-chevrons-right</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4865">lucide-icons/lucide#4865</a></li>
<li>fix(icons): changed <code>broccoli</code> icon by <a
href="https://github.com/jguddas"><code>@​jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4871">lucide-icons/lucide#4871</a></li>
<li>feat(icons): added square-dashed-plus by <a
href="https://github.com/psjdev"><code>@​psjdev</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4849">lucide-icons/lucide#4849</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/UbaidUllah9962"><code>@​UbaidUllah9962</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li>
<li><a
href="https://github.com/sarajdhakal"><code>@​sarajdhakal</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li>
<li><a href="https://github.com/AlecRust"><code>@​AlecRust</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li>
<li><a href="https://github.com/gkkconan"><code>@​gkkconan</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lucide-icons/lucide/commit/f06ac67e33d645c40b8ce19a0419c85c5d7dd751"><code>f06ac67</code></a>
chore(typchecking): More typecheck jobs for all packages (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4885">#4885</a>)</li>
<li>See full diff in <a
href="https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 16:02:11 -07:00
Devin FoleyandPaperclip 4b2bd6563d fix(chat): hide obsolete execution status and system notices (#14874)
## Thinking Path

> - Paperclip lets people oversee agent work through task conversations.
> - Conversations should show failures and waits that still affect the
task.
> - Old run errors and recovery notices remained visible after later
work or task completion.
> - These messages looked current even when no action remained.
> - This change hides obsolete execution status while preserving the
responses and activity.
> - The full diagnostic record stays available in run history.

## Linked Issues or Issue Description

**What happened?**

Task chat kept showing “Run failed”, “Stopped”, and “Waiting to resume”
after the execution had been superseded or the task had finished. Stored
system notices also remained in the conversation. Completed tasks
disabled Retry but kept the error message.

**Expected behavior**

Hide system status that no longer applies. Keep the latest unresolved
failure, active recovery holds, and useful recovery actions visible.
Preserve messages, files, questions, session boundaries, and inspectable
activity.

**Steps to reproduce**

1. Let a task run fail, then record a pre-start recovery wait.
2. Complete a later attempt or mark the task done.
3. Open the task conversation. Before this change, the old error and
wait remain visible.

**Paperclip version or commit**

Reproduced in component tests against `0f9e9be408`.

**Deployment mode**

Task chat in local or hosted deployments; both legacy adapters and the
native runner.

Related: #14857 and #14869 address execution recovery. This PR addresses
the remaining conversation presentation. Searched GitHub for historical
chat status, historical errors, and “Waiting to resume”; no duplicate PR
found.

## What Changed

- Determine status relevance from task state, attempt order, successor
evidence, and recovery state. Time alone does not hide errors.
- Hide obsolete run markers and stored execution notices. Require run or
recovery provenance, so unrelated system updates such as child-task
blockers remain visible. Keep errors from the latest failed attempt
actionable.
- Keep unresolved execution holds visible. A refused pre-start retry
does not replace a real attempt, and another agent’s work does not
resolve a run-specific error.
- Show historical activity without Worked/Stopped labels. Keep
historical failures out of the current turn’s summary.
- Anchor activity to visible comments so removing a notice cannot remove
the response or activity with it.
- Document the presentation rules and cover both runner modes and both
task presentation modes.

## Verification

- 334 focused component and status-policy tests passed across four
files, including the child-task relay regressions.
- `pnpm build` passed. The UI build also passed after the final
presentation changes.
- `pnpm exec vitest run --project @paperclipai/ui`: 667 files and 7,157
tests passed. Subsequent focused tests cover the final activity-anchor,
live-successor, and notice-provenance changes.
- `pnpm -r typecheck` passed. UI typecheck and build passed again after
the review fix.
- `pnpm test:run` completed its general-server phase with 14,716 tests
passed, 17 failed, and 87 skipped; it stopped before later phases. The
failures occurred in four unchanged server suites: chat channels, email
channels, company skills, and runtime skill cache. A targeted rerun
reproduced missing bundled skill paths and `EACCES` during
cache-directory rename on macOS. All Linux CI suites pass for the final
commit, including these server suites.
- Design token gates and diff checks pass.
- All 53 checks pass on commit `7af9753859`; two optional Storybook
checks are skipped. [Final CI
run](https://github.com/paperclipai/paperclip/actions/runs/36931968751)
includes build, full typecheck, all server and workspace test shards,
all eight end-to-end shards, runner verification, and the canary dry
run.
- Greptile scores the final commit at 5/5. No review threads remain
unresolved. The branch is current with `master` and has no merge
conflicts.

## Risks

This changes presentation only. It does not change execution, recovery,
stored comments, or run history. The main risk is hiding a current
diagnostic too early. Tests cover active holds, refused retries,
different agents, missing timestamps and provenance, live successors,
preserved responses, and the current retry target.

The base branch has a dependency override/lockfile mismatch. Local
installation used the same resolution fallback as CI, then restored the
tracked lockfile. No dependency changes are included.

## Model Used

OpenAI Codex (GPT-6). The exact runtime model identifier and context
window are not exposed in this session. Used reasoning, repository
inspection, code execution, and regression tests.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass — changed-code tests pass;
unrelated full-suite failures are documented above
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 15:18:47 -07:00
DottaandPaperclip efc2e6810e fix: show each task once in dashboard agent cards (#14847)
## Thinking Path

> - Paperclip helps people manage AI agents and their tasks.
> - The dashboard shows recent agent activity in compact cards.
> - Those cards use run records, so two runs for one task can create
duplicate task cards.
> - An operator needs to see each task once when scanning the dashboard.
> - This pull request selects one run per linked task before it applies
the card limit.
> - The live runs page still shows each run for run inspection.

## Linked Issues or Issue Description

**What happened?**

The dashboard showed the same task in two agent cards when that task had
both an active run and a completed run.

**Expected behavior**

The dashboard should show a linked task at most once. It should keep the
active run card when one is present.

**Steps to reproduce**

1. Start an agent run for a task that already has a completed run.
2. Open the company dashboard.
3. Observe two cards linked to the same task.

**Paperclip version or commit**

Reproduced on the pre-change master at `8b4aa0692`.

**Deployment mode**

Local dev, built from source. The bug is in the core dashboard UI and
does not depend on an agent adapter or database mode.

## What Changed

- Select distinct linked tasks from capped active and recent run samples
before applying the dashboard card limit.
- Keep separate cards for runs without a linked task.
- Preserve the dashboard's count of additional distinct cards behind the
live-runs link.
- Add UI and embedded Postgres regression tests for duplicate runs and
document the dashboard rule.
- Give the existing multi-request cross-tenant authorization test enough
time on loaded CI runners.

## Verification

- `pnpm --filter @paperclipai/ui exec vitest run
src/components/ActiveAgentsPanel.test.tsx`
- `pnpm --filter @paperclipai/ui exec vitest run
src/api/heartbeats.test.ts`
- `pnpm exec vitest run server/src/__tests__/dashboard-service.test.ts
server/src/__tests__/agent-live-run-routes.test.ts`
- `pnpm exec vitest run
server/src/__tests__/agent-cross-tenant-authz-routes.test.ts`
- `pnpm --filter @paperclipai/ui typecheck`
- `pnpm --filter @paperclipai/server typecheck`
- `pnpm --filter @paperclipai/ui build`
- `pnpm -r typecheck`
- `pnpm build`
- `pnpm check:token-gates`
- Review the dashboard with an active and a completed run on the same
task. Confirm that it shows one card. Open Live agent runs to inspect
both run records.

## Risks

- A very high volume of recent runs for one task can fill the capped
sample and leave older tasks off the dashboard. The Live runs page
remains available for full run inspection.
- The dashboard may fetch up to 50 distinct run representatives to
preserve its overflow count. The default run API response and persisted
data are unchanged.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, GPT-6. The runtime does not expose the exact model ID or
context window size to this task. The model used reasoning, tool calls,
and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 12:18:35 -05:00
DottaandPaperclip 6d654f63d1 feat(apps): make MCP action test results readable (#14859)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connected Apps let an operator control which MCP actions an agent
can use.
> - The Permissions page lets the operator run a real action as an
agent.
> - The Test dialog displayed the nested MCP response as escaped JSON.
> - A useful result was hard to read, even when the action worked.
> - This pull request renders known MCP content as a readable preview
and keeps the raw response available.
> - The benefit is faster validation without losing the data needed to
diagnose a failure.

## Linked Issues or Issue Description

**What existing behavior does this improve?**

The per-action Test dialog on a connection's Permissions page.

**Subsystem affected**

ui/ — React board UI.

**Current behavior**

The dialog shows the gateway response as an escaped JSON blob. Text
content that contains JSON stays inside a string. The obsolete
connection Test page also keeps a separate set of stories.

**Proposed behavior**

The dialog uses structured MCP content when present. It parses JSON text
blocks when possible. It shows compact tables, cards, fields, or plain
text. It keeps the full raw response behind a control and opens that
view for errors or unknown block shapes. Stories exercise the
Permissions page dialog, and the obsolete Test page and stories are
removed.

**Reason and benefit**

An operator can inspect a successful action result at a glance and still
inspect the exact gateway response when a call fails or looks wrong.

**Breaking changes**

No API or stored data changes. The Test dialog presentation changes. The
raw response stays available.

**Additional context**

I tested a read-only Notion search through the real Permissions page.
The dialog showed three result cards and the raw response control
worked. Storybook uses invented example data.

No directly matching public issue or open PR was found in the GitHub
search.

## What Changed

- Render structured MCP output and JSON text content in the action Test
dialog.
- Show wide rows as cards, keep short rows as tables, and retain the raw
response for diagnosis.
- Remove the obsolete connection Test page and its stories.
- Add focused dialog tests and Permissions page Storybook cases for
success, errors, mixed blocks, and malformed blocks.
- Document the Test dialog result behavior in the connection playbook.
- Keep agent mention icons visible when the Lucide icon node is
unavailable in server rendering, which repaired a repeatable CI failure.

## Verification

- `pnpm -r typecheck` — passed.
- `pnpm exec vitest run --project @paperclipai/ui` — passed (7,111
tests).
- `pnpm exec vitest run
ui/src/pages/apps/app-detail/ActionTestDialog.test.tsx` — passed (11
tests).
- `pnpm exec vitest run --project @paperclipai/ui
ui/src/components/MarkdownBody.test.tsx` — passed (53 tests).
- `pnpm test:run` — started, then stopped after the review fixes changed
the head; the full sharded suite passed in CI.
- `pnpm build` — passed.
- `pnpm check:token-gates` — passed.
- Use a connected MCP app. Open Permissions, select a read action, and
run Test. Inspect the preview and the raw response control.

## Risks

- MCP tools can return provider-specific block shapes. Unknown blocks
open the raw response so the operator can inspect the exact result.
- Row and field previews limit visible data. The raw response preserves
the complete result.

> This is a targeted improvement to the existing Connected Apps item in
`ROADMAP.md`.

## Model Used

OpenAI Codex, GPT-6. The session used tool access, code execution, and
browser validation. The exact deployment ID and context window were not
exposed to the session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 11:52:26 -05:00
DottaandPaperclip 527e146980 feat(ui): share animated agent setup prompts (#14862)
Use the shared animated prompt-copy control across setup, invitations, webhooks, and task handoffs. Preserve first-click copying, clipboard recovery, and logo continuity. Add Storybook coverage and restore mention icon masks for the current Lucide data shape.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-01 11:46:14 -05:00
DottaandPaperclip 33a00d2f1e fix(ui): reopen last visited agent chat (#14848)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - Agent Chat keeps one conversation for each agent and board user.
> - The Chat sidebar entry opens the agent chooser each time.
> - A user must then find and reopen the chat they just used.
> - The browser already records recent agent chat visits by company and
user.
> - This pull request uses that record to reopen the last available
chat.
> - The chooser still serves users who have no available saved chat.

## Linked Issues or Issue Description

Related: #14706 added the secondary Agent Chat navigation.

**What happened?**

The Chat sidebar entry opened the agent chooser, even after a user
opened an agent chat.

**Expected behavior**

The Chat entry should reopen the last agent chat visited by the current
user in the current company.

**Steps to reproduce**

1. Enable Agent Chat and open a chat with an agent.
2. Open another page.
3. Select Chat in the sidebar.
4. Observe the agent chooser instead of the chat.

**Paperclip version or commit**

Reproduced on master at `0829d94af`.

**Deployment mode**

Local development, browser UI. The change also uses the same browser
storage path in authenticated mode.

## What Changed

- Use the existing recent chat record when the Chat landing route opens.
- Check saved agents against the current roster and chat history before
redirecting.
- Keep the chooser when no saved chat is available, and show a retry
state for load errors.
- Add route tests and update the Agent Chat implementation spec.

## Verification

- `pnpm exec vitest run ui/src/pages/AgentChats.test.tsx
ui/src/lib/recent-agent-chats.test.ts` — 16 tests passed.
- `pnpm check:token-gates` — passed.
- `pnpm exec playwright test --config tests/e2e/playwright.config.ts
tests/e2e/agent-chat-sessions.spec.ts --grep 'secondary chat navigation
preserves layout'` — passed.
- `pnpm --filter @paperclipai/ui typecheck` — passed on the final
commit.
- `pnpm -r typecheck` and `pnpm build` — passed earlier in this branch;
latest-head CI completed all 47 jobs successfully.
- `pnpm test:run` reported an unrelated native runtime test failure
before it was stopped. That test and an unrelated external object
refresh test passed in isolation. CI runs the same suites on the PR.
- To check in the UI: open an agent chat, leave it, and select Chat. The
same chat should open. Clear the recent chat record or use another
company to see the chooser.

## Risks

- The recent order is stored in the browser. Clearing browser storage
returns the user to the chooser.
- An existing chat ID is stored with its visit. If the chat is removed,
the landing route skips that visit when history loads. Cross-tab storage
removal clears the identity; failed writes retain an in-tab fallback.
- The landing route waits for the agent roster and validates saved issue
IDs against chat history when available. If history fails, an active
agent chat can still open; roster or session failures show a retry
action.
- No database or API contract changes are required.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, GPT-6 family. The runtime did not expose an exact API
model ID or context window. It used reasoning, repository tools, shell
commands, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 11:01:45 -05:00
dependabot[bot] 26900655b4 chore(deps): bump lucide-react from 1.38.0 to 1.45.0
Bumps
[lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react)
from 1.38.0 to 1.45.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lucide-icons/lucide/releases">lucide-react's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.45.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): added <code>calendar-chevrons-right</code> icon by <a
href="https://github.com/AlexandrePhilibert"><code>@​AlexandrePhilibert</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3565">lucide-icons/lucide#3565</a></li>
<li>feat(icons): added <code>building-complex-plus</code> icon by <a
href="https://github.com/tylerkade"><code>@​tylerkade</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4758">lucide-icons/lucide#4758</a></li>
<li>feat(icons): add hourglass-cog icon by <a
href="https://github.com/lazerg"><code>@​lazerg</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4635">lucide-icons/lucide#4635</a></li>
<li>feat(icons): added <code>mouth</code> &amp; <code>mouth-off</code>
by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4787">lucide-icons/lucide#4787</a></li>
<li>feat(icons): added <code>iv-bag</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4821">lucide-icons/lucide#4821</a></li>
<li>fix(icons): changed <code>lectern</code> icon by <a
href="https://github.com/UsamaKhan"><code>@​UsamaKhan</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/2925">lucide-icons/lucide#2925</a></li>
<li>feat(icons): add <code>layout-arrow-right</code> and
<code>layout-arrow-down</code> by <a
href="https://github.com/samuelalake"><code>@​samuelalake</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4541">lucide-icons/lucide#4541</a></li>
<li>feat(icons): added <code>park</code> icon by <a
href="https://github.com/skajosborn"><code>@​skajosborn</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3177">lucide-icons/lucide#3177</a></li>
<li>fix(icons): changed <code>album</code>, <code>book-marked</code>,
<code>folder-bookmark</code> icons by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3043">lucide-icons/lucide#3043</a></li>
<li>fix(icons): correct misspelled tags by <a
href="https://github.com/decknamec"><code>@​decknamec</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4836">lucide-icons/lucide#4836</a></li>
<li>feat(icons): added <code>houses</code> icon by <a
href="https://github.com/danielbayley"><code>@​danielbayley</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3241">lucide-icons/lucide#3241</a></li>
<li>feat(icons): added <code>notebook-dot</code> icon by <a
href="https://github.com/elenakovelskikh"><code>@​elenakovelskikh</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3228">lucide-icons/lucide#3228</a></li>
<li>feat(icons): add <code>messages-circle</code> icon by <a
href="https://github.com/Mirazstudio-offical"><code>@​Mirazstudio-offical</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4754">lucide-icons/lucide#4754</a></li>
<li>feat(icons): added <code>plant-pot</code> icon by <a
href="https://github.com/vqh2602"><code>@​vqh2602</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3122">lucide-icons/lucide#3122</a></li>
<li>fix(icons): changed <code>cookie</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4815">lucide-icons/lucide#4815</a></li>
<li>fix(icons): remove duplicate use-cases prop from cookie.json by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4838">lucide-icons/lucide#4838</a></li>
<li>fix(site): fix home card icons by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4839">lucide-icons/lucide#4839</a></li>
<li>feat(docs): added &quot;How to use Lucide icons&quot; section to
resources by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4829">lucide-icons/lucide#4829</a></li>
<li>fix(packages/vue): fix generated icon declaration types for
<code>@​lucide/vue</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4841">lucide-icons/lucide#4841</a></li>
<li>chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4845">lucide-icons/lucide#4845</a></li>
<li>chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 in
/integrations/lucide-react/vite by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4844">lucide-icons/lucide#4844</a></li>
<li>ci(ci.yml): Add dispatch post release by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4847">lucide-icons/lucide#4847</a></li>
<li>feat(icons): added <code>globe-code</code> icon by <a
href="https://github.com/AleksejDix"><code>@​AleksejDix</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3722">lucide-icons/lucide#3722</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/tylerkade"><code>@​tylerkade</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4758">lucide-icons/lucide#4758</a></li>
<li><a href="https://github.com/alx-xo"><code>@​alx-xo</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4115">lucide-icons/lucide#4115</a></li>
<li><a
href="https://github.com/skajosborn"><code>@​skajosborn</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3177">lucide-icons/lucide#3177</a></li>
<li><a
href="https://github.com/elenakovelskikh"><code>@​elenakovelskikh</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3228">lucide-icons/lucide#3228</a></li>
<li><a
href="https://github.com/Mirazstudio-offical"><code>@​Mirazstudio-offical</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4754">lucide-icons/lucide#4754</a></li>
<li><a
href="https://github.com/AleksejDix"><code>@​AleksejDix</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3722">lucide-icons/lucide#3722</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.44.0...1.45.0">https://github.com/lucide-icons/lucide/compare/1.44.0...1.45.0</a></p>
<h2>Version 1.44.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(packages/icons): fixed <code>@​lucide/icons</code> rollup
config by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4824">lucide-icons/lucide#4824</a></li>
<li>fix(icons): changed <code>door-open</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4826">lucide-icons/lucide#4826</a></li>
<li>fix(docs): replace missing LucideIcon icon names in guides by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4827">lucide-icons/lucide#4827</a></li>
<li>feat(docs): fixed fuse js search by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4825">lucide-icons/lucide#4825</a></li>
<li>fix(icons): changed <code>satellite-dish</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4813">lucide-icons/lucide#4813</a></li>
<li>fix(icons): arcified flip icons &amp; renamed them by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4833">lucide-icons/lucide#4833</a></li>
<li>fix(icons): improve legibility of credit card icons by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4831">lucide-icons/lucide#4831</a></li>
<li>feat(lab): add check-x icon by <a
href="https://github.com/ishanbagra18"><code>@​ishanbagra18</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4737">lucide-icons/lucide#4737</a></li>
<li>fix(icons): correct compromised tags in shield icons by <a
href="https://github.com/decknamec"><code>@​decknamec</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4835">lucide-icons/lucide#4835</a></li>
<li>feat(icons): added <code>toothbrush</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4755">lucide-icons/lucide#4755</a></li>
</ul>
<h2>New Contributors</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b"><code>94e4cb9</code></a>
chore(dependencies): Update dependencies (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806">#4806</a>)</li>
<li><a
href="https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2"><code>99d25bd</code></a>
feat(packages): extract icon build logic into
<code>@lucide/shared</code> (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409">#4409</a>)</li>
<li>See full diff in <a
href="https://github.com/lucide-icons/lucide/commits/1.45.0/packages/lucide-react">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=lucide-react&package-manager=npm_and_yarn&previous-version=1.38.0&new-version=1.45.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 08:49:02 -07:00