mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-09 06:15:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents need a governed way to request app connections during issue work. > - The catalog now describes the available providers and setup methods. > - A request must become a durable, company-scoped intent before an operator acts on it. > - This pull request adds that intent runtime across server, agent, CLI, and shared contracts. > - The benefit is a safe bridge from agent need to operator-approved setup. ## Linked Issues or Issue Description Refs #11965 This is stack 7 of 11. It depends on stack 6 and replaces another reviewable part of #11965. ## What Changed - Add connection intent types, validation, service logic, and routes. - Add agent runtime tools and CLI support for connection requests. - Add issue-thread interaction support for connection intents. - Add runtime, route, adapter, and contract tests. - Hold the final resolved-continuation row lock through asynchronous adapter preparation until an actual process spawn, so parking or reassignment cannot cross that boundary. - Report Hermes Gateway's first remote run request through the shared dispatch hook so the resolved-intent lock is released at the true dispatch boundary. - Revalidate the addressed user's live non-viewer membership and connection-management authority for every intent mutation, including OAuth completion. ## Verification - `pnpm --filter @paperclipai/server typecheck` - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/tool-access-service.test.ts` - Result: 176 tests passed. - `pnpm build` - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-stale-queue-invalidation.test.ts` (32 passed; includes non-process dispatch lock-release coverage) - `pnpm exec vitest run --project @paperclipai/server server/src/__tests__/connection-intents-service.test.ts -t "addressed-user mutation"` (1 passed) - `pnpm exec vitest run --project @paperclipai/server server/src/__tests__/tool-access-service.test.ts -t "binds OAuth callback completion to the initiating board session"` (1 passed) - `pnpm --filter @paperclipai/hermes-paperclip-adapter test -- src/gateway/server/execute.test.ts` (23 passed; includes dispatch-hook ordering and exactly-once coverage) - `pnpm --filter @paperclipai/hermes-paperclip-adapter typecheck` ## Risks - A malformed intent could create an unusable operator request. - Validators and company checks reject invalid or cross-company requests. - The final continuation gate holds the issue row lock through adapter preparation until process or remote dispatch; later operator changes use the normal active-run interruption path. - The change does not add a database migration. > I checked `ROADMAP.md`. This stack continues the existing app connection work from #11965 and does not duplicate another planned item. ## Model Used OpenAI Codex, GPT-5. The runtime model ID and context window were not exposed. The model used reasoning, tool use, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have linked the public source pull request with `Refs #` - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
99 lines
4.0 KiB
TypeScript
99 lines
4.0 KiB
TypeScript
// Re-export everything from the shared adapter-utils/server-utils package.
|
|
// This file is kept as a convenience shim so existing in-tree
|
|
// imports (process/, http/, heartbeat.ts) don't need rewriting.
|
|
import type { ChildProcess } from "node:child_process";
|
|
import { logger } from "../middleware/logger.js";
|
|
import * as serverUtils from "@paperclipai/adapter-utils/server-utils";
|
|
export type { RunProcessResult } from "@paperclipai/adapter-utils/server-utils";
|
|
|
|
type BuildInvocationEnvForLogsOptions = {
|
|
runtimeEnv?: NodeJS.ProcessEnv | Record<string, string>;
|
|
includeRuntimeKeys?: string[];
|
|
resolvedCommand?: string | null;
|
|
resolvedCommandEnvKey?: string;
|
|
};
|
|
|
|
export const runningProcesses: Map<string, { child: ChildProcess; graceSec: number; processGroupId: number | null }> =
|
|
serverUtils.runningProcesses;
|
|
export const MAX_CAPTURE_BYTES = serverUtils.MAX_CAPTURE_BYTES;
|
|
export const MAX_EXCERPT_BYTES = serverUtils.MAX_EXCERPT_BYTES;
|
|
export const parseObject = serverUtils.parseObject;
|
|
export const asString = serverUtils.asString;
|
|
export const asNumber = serverUtils.asNumber;
|
|
export const asBoolean = serverUtils.asBoolean;
|
|
export const asStringArray = serverUtils.asStringArray;
|
|
export const parseJson = serverUtils.parseJson;
|
|
export const appendWithCap = serverUtils.appendWithCap;
|
|
export const appendWithByteCap = serverUtils.appendWithByteCap;
|
|
export const resolvePathValue = serverUtils.resolvePathValue;
|
|
export const renderTemplate = serverUtils.renderTemplate;
|
|
export const redactEnvForLogs = serverUtils.redactEnvForLogs;
|
|
export const buildPaperclipEnv = serverUtils.buildPaperclipEnv;
|
|
export const buildRuntimeToolsEnv = serverUtils.buildRuntimeToolsEnv;
|
|
export const isPaperclipRuntimeEnvKey = serverUtils.isPaperclipRuntimeEnvKey;
|
|
export const isForbiddenConfigEnvKey = serverUtils.isForbiddenConfigEnvKey;
|
|
export const defaultPathForPlatform = serverUtils.defaultPathForPlatform;
|
|
export const ensurePathInEnv = serverUtils.ensurePathInEnv;
|
|
export const ensureAbsoluteDirectory = serverUtils.ensureAbsoluteDirectory;
|
|
export const ensureCommandResolvable = serverUtils.ensureCommandResolvable;
|
|
export const resolveCommandForLogs = serverUtils.resolveCommandForLogs;
|
|
|
|
export function buildInvocationEnvForLogs(
|
|
env: Record<string, string>,
|
|
options: BuildInvocationEnvForLogsOptions = {},
|
|
): Record<string, string> {
|
|
const maybeBuildInvocationEnvForLogs = (
|
|
serverUtils as typeof serverUtils & {
|
|
buildInvocationEnvForLogs?: (
|
|
env: Record<string, string>,
|
|
options?: BuildInvocationEnvForLogsOptions,
|
|
) => Record<string, string>;
|
|
}
|
|
).buildInvocationEnvForLogs;
|
|
|
|
if (typeof maybeBuildInvocationEnvForLogs === "function") {
|
|
return maybeBuildInvocationEnvForLogs(env, options);
|
|
}
|
|
|
|
const merged: Record<string, string> = { ...env };
|
|
const runtimeEnv = options.runtimeEnv ?? {};
|
|
|
|
for (const key of options.includeRuntimeKeys ?? []) {
|
|
if (key in merged) continue;
|
|
const value = runtimeEnv[key];
|
|
if (typeof value !== "string" || value.length === 0) continue;
|
|
merged[key] = value;
|
|
}
|
|
|
|
const resolvedCommand = options.resolvedCommand?.trim();
|
|
if (resolvedCommand) {
|
|
merged[options.resolvedCommandEnvKey ?? "PAPERCLIP_RESOLVED_COMMAND"] =
|
|
serverUtils.redactCommandTextForLogs(resolvedCommand);
|
|
}
|
|
|
|
return redactEnvForLogs(merged);
|
|
}
|
|
|
|
// Re-export runChildProcess with the server's pino logger wired in.
|
|
import type { RunProcessResult } from "@paperclipai/adapter-utils/server-utils";
|
|
const _runChildProcess = serverUtils.runChildProcess;
|
|
|
|
export async function runChildProcess(
|
|
runId: string,
|
|
command: string,
|
|
args: string[],
|
|
opts: {
|
|
cwd: string;
|
|
env: Record<string, string>;
|
|
timeoutSec: number;
|
|
graceSec: number;
|
|
onLog: (stream: "stdout" | "stderr", chunk: string) => Promise<void>;
|
|
onSpawn?: (meta: { pid: number; processGroupId: number | null; startedAt: string }) => Promise<void>;
|
|
},
|
|
): Promise<RunProcessResult> {
|
|
return _runChildProcess(runId, command, args, {
|
|
...opts,
|
|
onLogError: (err, id, msg) => logger.warn({ err, runId: id }, msg),
|
|
});
|
|
}
|