Files
PaperClipAI/server/src/__tests__/instance-settings-managed-overlay.test.ts
DottaandPaperclip 8781f06a87 feat(connections): enable MCP aggregators by default (#13964)
## Thinking Path

> - Paperclip helps people manage AI agents for work.
> - Connections let those agents use external services with explicit
access rules.
> - Zapier, Arcade, Composio Connect, and Executor already have setup
and runtime support.
> - Their experimental switch still blocks discovery and setup by
default.
> - This pull request removes those gates and the Settings toggle.
> - Users can connect these providers without enabling an experiment.

## Linked Issues or Issue Description

Refs #13755. Refs #13941.

**What existing behavior does this improve?**
Apps browsing, inline setup, and agent connection search for the four
MCP aggregators.

**Current behavior**
An instance must enable the MCP aggregators experiment before users or
agents can start setup.

**Proposed behavior**
All four providers are available by default on local and managed
instances. Old stored and managed values still parse but cannot disable
them.

## What Changed

- Remove the aggregator gates from Apps, inline setup, server setup, and
agent search.
- Remove the Settings toggle and its UI hook.
- Retain the old setting key only for upgrade compatibility. Normalize
it to true and ignore managed overrides, as Apps already does.
- Replace opt-in fixtures with default-on coverage. Test old false
values, all four setup flows, provider choice, and the removed toggle.
- Update current connector guidance and remove the opt-in from the
runner acceptance fixture.

## Verification

- 306 focused tests passed across eight files: shared remote MCP
contracts; server remote MCP lifecycle, aggregator fallback, settings
normalization, and managed overlay; UI Apps browsing, setup, and
experimental settings.
- Server and UI TypeScript checks passed.
- UI token gates and `git diff --check` passed.
- The full local suite was not run, per the maintainer's instruction.
All 54 CI checks passed; two checks were skipped. One unrelated
workspace-preview readiness timeout passed on one failed-shard retry.
- The setup fixtures use simulated MCP responses. This change does not
claim new live provider acceptance.

## Risks

- Existing instances now show all four providers, even if the old flag
was false. This is intentional.
- External provider choice, credentials, company isolation, agent
grants, and tool policies still apply. Showing a connector does not
authorize an external account.
- No data migration is required. The compatibility key keeps old managed
configuration documents valid.
- Historical Zapier live acceptance remains incomplete in the existing
evidence report. The maintainer explicitly requested the default-on
rollout for all four existing providers; the report records that scoped
exception.

## Model Used

OpenAI GPT-6 (`gpt-6-astra`) through Codex, with reasoning, repository
tools, and test execution. The context window size is not exposed in
this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-24 17:31:32 -05:00

192 lines
8.3 KiB
TypeScript

import { describe, expect, it } from "vitest";
import type { Db } from "@paperclipai/db";
import {
applyManagedExperimentalOverlay,
instanceSettingsService,
normalizeExperimentalSettings,
} from "../services/instance-settings.js";
import { parseManagedConfigEnv } from "../services/managed-config.js";
const MANAGED_RAW = JSON.stringify({
v: 1,
mode: "cloud",
catalogVersion: "2026.720.0",
// enableApps is retained only for compatibility and must be ignored;
// enablePipelines remains a live managed feature.
features: { enableApps: false, enablePipelines: true },
plugins: { autoInstall: [] },
});
function managedEnv(raw: string | undefined = MANAGED_RAW) {
return { PAPERCLIP_MANAGED_CONFIG: raw };
}
/**
* Minimal stand-in for the drizzle query chains instanceSettingsService uses.
* Captures every `update().set()` payload so tests can assert what would be
* persisted.
*/
function stubDb(row: Record<string, unknown>) {
const persistedSets: Array<Record<string, unknown>> = [];
const db = {
select: () => ({ from: () => ({ where: () => Promise.resolve([row]) }) }),
insert: () => {
throw new Error("unexpected insert in test");
},
update: () => ({
set: (values: Record<string, unknown>) => {
persistedSets.push(values);
return { where: () => ({ returning: () => Promise.resolve([{ ...row, ...values }]) }) };
},
}),
} as unknown as Db;
return { db, persistedSets };
}
function settingsRow(experimental: Record<string, unknown>) {
return {
id: "row-1",
singletonKey: "default",
defaultEnvironmentId: null,
general: {},
experimental,
createdAt: new Date("2026-06-20T00:00:00.000Z"),
updatedAt: new Date("2026-06-20T00:00:00.000Z"),
};
}
describe("applyManagedExperimentalOverlay", () => {
it("is the identity with no managed config (self-hosted)", () => {
const experimental = normalizeExperimentalSettings({ enableApps: true });
const result = applyManagedExperimentalOverlay(experimental, null);
expect(result.experimental).toEqual(experimental);
expect(result.managedKeys).toEqual({});
});
it("ignores the retired Apps flag while overlaying live managed values", () => {
const config = parseManagedConfigEnv(managedEnv())!;
const stored = normalizeExperimentalSettings({ enableApps: true });
const { experimental, managedKeys } = applyManagedExperimentalOverlay(stored, config);
expect(experimental.enableApps).toBe(true);
// managed overlay > schema default
expect(experimental.enablePipelines).toBe(true);
// unmanaged keys keep their stored/default values
expect(experimental.enableCases).toBe(false);
expect(managedKeys).toEqual({
enablePipelines: { managed: true, managedBy: "paperclip-cloud" },
});
// input is not mutated
expect(stored.enableApps).toBe(true);
});
});
describe("instanceSettingsService managed overlay", () => {
it.each([{}, { enableMcpAggregators: false }])("keeps aggregators on with legacy stored and managed values: %j", async (stored) => {
const { db } = stubDb(settingsRow({ ...stored, enableChatConnectors: true }));
const service = instanceSettingsService(db, { runtimeEnv: managedEnv(JSON.stringify({
v: 1, mode: "cloud", catalogVersion: "legacy", features: { enableMcpAggregators: false }, plugins: { autoInstall: [] },
})) });
expect(await service.getExperimental()).toMatchObject({ enableMcpAggregators: true, enableChatConnectors: true, managedKeys: {} });
expect(await service.updateExperimental({ enableMcpAggregators: false })).toMatchObject({ experimental: { enableMcpAggregators: true, enableChatConnectors: true } });
});
it("persists chat connector opt-in and reads it back after service reconstruction", async () => {
const row = settingsRow({});
const { db, persistedSets } = stubDb(row);
const service = instanceSettingsService(db, { runtimeEnv: {} });
expect((await service.getExperimental()).enableChatConnectors).toBe(false);
for (const enabled of [true, false]) {
const updated = await service.updateExperimental({ enableChatConnectors: enabled });
Object.assign(row, persistedSets.at(-1));
expect(updated.experimental.enableChatConnectors).toBe(enabled);
const restored = await instanceSettingsService(db, { runtimeEnv: {} }).getExperimental();
expect(restored).toMatchObject({ enableApps: true, enableChatConnectors: enabled });
}
});
it("overlays the managed chat connector gate without changing stored data", async () => {
const { db, persistedSets } = stubDb(settingsRow({ enableChatConnectors: true }));
const service = instanceSettingsService(db, { runtimeEnv: managedEnv(JSON.stringify({
v: 1, mode: "cloud", catalogVersion: "test", features: { enableChatConnectors: false }, plugins: { autoInstall: [] },
})) });
expect(await service.getExperimental()).toMatchObject({
enableChatConnectors: false,
managedKeys: { enableChatConnectors: { managed: true, managedBy: "paperclip-cloud" } },
});
expect(persistedSets).toHaveLength(0);
});
it("fails closed at construction on a malformed managed config", () => {
const { db } = stubDb(settingsRow({}));
expect(() => instanceSettingsService(db, { runtimeEnv: managedEnv("{bad") })).toThrow(
/PAPERCLIP_MANAGED_CONFIG is not valid JSON/,
);
});
it("overlays managed values on getExperimental and exposes managedKeys", async () => {
const { db } = stubDb(settingsRow({ enableApps: true }));
const svc = instanceSettingsService(db, { runtimeEnv: managedEnv() });
const experimental = await svc.getExperimental();
expect(experimental.enableApps).toBe(true);
expect(experimental.enablePipelines).toBe(true);
expect(experimental.managedKeys).toEqual({
enablePipelines: { managed: true, managedBy: "paperclip-cloud" },
});
});
it("overlays managed values on get()", async () => {
const { db } = stubDb(settingsRow({ enableApps: true }));
const svc = instanceSettingsService(db, { runtimeEnv: managedEnv() });
const settings = await svc.get();
expect(settings.experimental.enableApps).toBe(true);
expect(settings.experimental.managedKeys?.enableApps).toBeUndefined();
});
it("leaves the self-hosted read path unchanged (no managedKeys field)", async () => {
const { db } = stubDb(settingsRow({ enableApps: true }));
const svc = instanceSettingsService(db, { runtimeEnv: {} });
const experimental = await svc.getExperimental();
expect(experimental.enableApps).toBe(true);
expect(Object.prototype.hasOwnProperty.call(experimental, "managedKeys")).toBe(false);
expect(experimental).toEqual(normalizeExperimentalSettings({ enableApps: true }));
const settings = await svc.get();
expect(Object.prototype.hasOwnProperty.call(settings.experimental, "managedKeys")).toBe(false);
});
it("never persists the overlay: updates write stored values, responses show managed ones", async () => {
const { db, persistedSets } = stubDb(settingsRow({ enableApps: true }));
const svc = instanceSettingsService(db, { runtimeEnv: managedEnv() });
const updated = await svc.updateExperimental({ enableCases: true });
expect(persistedSets).toHaveLength(1);
const persisted = persistedSets[0]!.experimental as Record<string, unknown>;
// The retired compatibility key normalizes on, independent of the
// managed document's historical value.
expect(persisted.enableApps).toBe(true);
// The overlay-added value is not written.
expect(persisted.enablePipelines).toBe(false);
expect(persisted.enableCases).toBe(true);
expect(persisted).not.toHaveProperty("managedKeys");
// The response still reflects the overlay.
expect(updated.experimental.enableApps).toBe(true);
expect(updated.experimental.enablePipelines).toBe(true);
expect(updated.experimental.managedKeys?.enableApps).toBeUndefined();
});
it("does not let managed metadata leak into self-hosted writes", async () => {
const { db, persistedSets } = stubDb(settingsRow({}));
const svc = instanceSettingsService(db, { runtimeEnv: {} });
const updated = await svc.updateExperimental({ enableCases: true });
expect(persistedSets).toHaveLength(1);
expect(persistedSets[0]!.experimental).not.toHaveProperty("managedKeys");
expect(Object.prototype.hasOwnProperty.call(updated.experimental, "managedKeys")).toBe(false);
});
});