Files
PaperClipAI/tests/ai-connections-app/connection-pools.spec.ts
DottaandPaperclip 0e0b63e5a5 feat(connections): add experimental task-pinned AI routing (#14967)
## Thinking Path

> - Paperclip manages AI agents and their work.
> - AI Connections separate account access from models and harnesses.
> - A pool must act as one connection while retaining each task’s
account.
> - Core must enforce member access and preserve session and recovery
rules.
> - A plugin supplies rotation policy without receiving credentials.
> - This change adds durable routing and native connector setup and
management.

## Linked Issues or Issue Description

**Subsystem affected**

AI Connections, Connectors, plugins, run dispatch, and session
compatibility.

**Problem or motivation**

Operators need to rotate new tasks across saved accounts while each task
keeps its account and session. Pool setup must fit the existing
connector catalog and account workflow.

**Proposed solution**

Add an experimental router binding, a capability-gated plugin hook, and
transactional task pins. Plugins declare native pooled connectors
through `aiConnectionRouter`. Core hosts the existing-account picker,
ordering step, and account settings. Related usage contract: #14936.
Companion private plugin:
https://github.com/paperclipai/paperclip-cloud/pull/643.

**Roadmap alignment**

This extends Apps and AI Connections. Core supplies generic enforcement
and native connector UI; the private plugin owns rotation and quota
policy. The prior duplicate search found no matching router
implementation.

## What Changed

- Add a router binding without changing existing concrete bindings. Keep
the instance flag and new pools disabled by default. Require manual
operator configuration. Show no routing toggle in Experimental settings
on either open-source or Cloud installs, even after routing is enabled.
- Persist company-scoped pools, one shared cursor per pool, and pins
keyed by company, pool, agent, and task. Commit pins and cursor advances
together with revision checks and bounded retries. Persist run-ID
affinity before allocation.
- Pass only authorized metadata and normalized usage to plugins. Core
retains credential handling, member access checks, runtime
qualification, and recovery evidence. Probe outside locks with a shared
15-second budget and freshness cache.
- Resolve routing before credential preparation and backend selection.
Preserve pins through turns, session resets, removed members, and quota
waits. Retain admitted recovery after disable or uninstall.
- Separate credential session epochs from token generations. Verified
refresh preserves the epoch; reconnect and manual replacement change it.
Include the credential slot ID in session and usage-cache identity, so
reconnecting an indexed legacy account invalidates its old session even
when both epochs are zero.
- Validate pool member installations before accepting saved-agent
bindings and recheck compatibility when the harness changes. Install
only authorized members in the new-agent transaction and record their
IDs in local activity. Pool membership cannot install a restricted
shared connection.
- Preserve pool bindings when agents hire teammates through either
creation API or native caller runtime inheritance. Block stale manager
credential references; retain explicit child authentication precedence
and reject incompatible inherited pools.
- Add native connector registration through plugin metadata. Reuse the
Connectors catalog, setup header, account header, sidebar, dialogs, and
usage display. Setup selects and orders saved connections. Advanced
settings hold usage rules and member runtime defaults. New-account setup
opens in another tab.
- Use revision-checked pool archival from the Connectors catalog and
account page. Keep task pins, cursors, recovery evidence, and underlying
connections. Reject ordinary connection updates or removals that bypass
pool revisions.
- Add pool selectors, composer models, override notes, quota status, run
details, activity records, and local run-log records. Keep
session-adoption copy minimal.
- Show **Used by** below the pool connections. List current company
agents with shared avatars and profile links. Include paused agents;
exclude terminated agents and agents using another pool.
- Add Core stories for the generic connector workflow and runtime
surfaces. Cloud stories reuse these production routes and tokens through
a preview-only alias.

## Verification

- Final head `73cb953bca30ed83e4505dd820edd9b5edffd28b`: full workspace
`pnpm -r typecheck`, `pnpm build`, and `pnpm check:token-gates` pass
locally.
- All 422 focused connector/settings/shared-contract/migration tests and
all 156 database-backed AI connection, hiring, reconnect, and
durable-routing cases pass (69 hiring cases rerun after the final
auth-precedence fix). The merged shared contract retains connection
instructions and pool metadata. The pool migration is generated at
sequence 0299 after the latest upstream migrations; this PR makes no
lockfile changes.
- All four full-app Playwright tests pass on the final head after a cold
restart and migration, against the installed private plugin and isolated
database, with no route or pool-API mocks. They cover hidden routing
controls after manual opt-in, native pool creation, ordering, membership
edits, rename, paused defaults, enabling/save/refresh persistence, stale
edits, cancellation/removal, preserved underlying accounts, unavailable
routers, and Used by avatars and profile links. Exact command:
`PAPERCLIP_CONNECTION_POOL_E2E=1
AI_CONNECTIONS_TEST_COMPANY_ID=a37b9625-5ecf-4e29-8081-04df3d6e7d6f
AI_CONNECTIONS_TEST_URL=http://127.0.0.1:3108 pnpm exec playwright test
--config tests/ai-connections-app/playwright.config.ts
connection-pools.spec.ts`.
- [Native setup, ordering, and management
screenshots](https://github.com/paperclipai/paperclip/pull/14967#issuecomment-6006976278)
address the review follow-up. [Earlier selector, quota, and run-detail
screenshots](https://github.com/paperclipai/paperclip/pull/14967#issuecomment-5971537316)
show the runtime surfaces. Core previews: `pnpm --filter @paperclipai/ui
storybook`, then **Connectors / Pool host** or **AI Connections /
Connection pools**. Cloud owns its host-backed plugin stories; both
repositories’ Operator Setup Required story assertions pass.
- Live acceptance used OpenAI/Codex and Anthropic/Claude ACPX, resumed
both exact sessions after restart, preserved pinned accounts through
explicit reset and controlled quota deferral/recovery, and committed
only two allocations across fourteen runs. A later UI-created task test
again rotated OpenAI then Anthropic and resumed OpenAI through
follow-up/restart/quota recovery. That later Anthropic execution was
blocked by its saved OAuth token expiring (provider 401). No live usage
probes ran.
- The full local `pnpm test:run` was attempted earlier and did not
complete because of macOS embedded PostgreSQL bootstrap/shared-memory
failures and the 40,000-file Git fixture timeout. The focused database
suites above now pass; full-suite verification is provided by the split
CI lanes. The preceding CI run had one runtime readiness timeout; it
passes locally both alone and inside the larger runtime suite. That
larger local suite also encountered an embedded PostgreSQL setup failure
and two macOS temporary-path alias assertions; those two assertions pass
with canonical TMPDIR=/private/tmp. All final-head CI checks are
terminal green, including full general/serialized server suites, Runner
checks, browser E2E shards, canary verification, build, and typecheck.
Greptile is 5/5 on that exact head with no unresolved threads.

## Risks

- The migration adds routing tables and a credential epoch column.
Install the private plugin only with the compatible Core contract.
- Routing and each pool require opt-in. Production distribution and
fleet defaults remain unchanged.
- Unknown usage stays eligible. Known pinned exhaustion waits; revoked
access requires operator repair.
- Legacy adapters require compatible members. Runner model and effort
overrides remain limited by qualified backend support.

## Model Used

OpenAI GPT-6 through Codex, with reasoning, repository editing, code
execution, and browser testing. The exact deployment model ID and
context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes:` / `Closes:`
/ `Refs:` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (targeted suites;
full-suite limitations are reported above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-05 20:44:37 -05:00

160 lines
11 KiB
TypeScript

import { expect, test, type APIRequestContext } from "@playwright/test";
import type { AiConnectionList, AiConnectionPool, AppDefinition } from "@paperclipai/shared";
// Exercise the full shipped app and an installed router, with real persistence.
// No browser routes, credentials, providers, or pool APIs are mocked. Opt in
// only against a loopback test-drive company with existing saved accounts.
const companyId = process.env.AI_CONNECTIONS_TEST_COMPANY_ID;
test.skip(process.env.PAPERCLIP_CONNECTION_POOL_E2E !== "1" || !companyId, "Opt in with an isolated connection-pool test drive");
let prefix: string;
let connector: AppDefinition;
let accounts: AiConnectionList["connections"];
const poolsPath = `/api/companies/${companyId}/ai-connection-pools`;
async function listPools(request: APIRequestContext): Promise<AiConnectionPool[]> {
const response = await request.get(poolsPath);
expect(response.ok()).toBe(true);
return response.json();
}
test.beforeAll(async ({ request }, testInfo) => {
const origin = new URL(testInfo.project.use.baseURL!);
expect(origin.protocol).toBe("http:");
expect(["127.0.0.1", "[::1]"]).toContain(origin.hostname);
const health = await (await request.get("/api/health")).json();
expect(health).toMatchObject({ status: "ok", bootstrapStatus: "ready", deploymentMode: "local_trusted" });
const company = await (await request.get(`/api/companies/${companyId}`)).json();
expect(company.name).toMatch(/test drive|e2e/i);
prefix = company.issuePrefix;
const gallery = await (await request.get(`/api/companies/${companyId}/tools/gallery`)).json();
connector = gallery.apps.find((app: AppDefinition) => app.aiConnectionRouter && app.availability?.available);
expect(connector, "Install and enable a router plugin, then opt in to the instance flag").toBeTruthy();
const list: AiConnectionList = await (await request.get(`/api/companies/${companyId}/ai-connections`)).json();
expect(list.canManageConnections).toBe(true);
accounts = list.connections.filter((account, index, all) => account.status === "connected" && all.findIndex(candidate => candidate.id === account.id) === index).slice(0, 2);
expect(accounts, "Use two pre-existing authorized accounts").toHaveLength(2);
});
test("operator-enabled routing has no experimental settings control", async ({ page, request }) => {
const response = await request.get("/api/instance/settings/experimental");
expect(response.ok()).toBe(true);
expect(await response.json()).toMatchObject({ enableAiConnectionRouters: true });
await page.goto(`/${prefix}/company/settings/instance/experimental`);
await expect(page.getByRole("heading", { name: "Experimental", exact: true })).toBeVisible();
await expect(page.getByRole("heading", { name: "Experimental features", exact: true })).toBeVisible();
await expect(page.getByText("AI connection routers", { exact: true })).toHaveCount(0);
await expect(page.getByRole("switch", { name: "Toggle AI connection routers experimental setting", exact: true })).toHaveCount(0);
});
test("native catalog setup, account edits, conflicts and removal persist through the full app", async ({ page, request }) => {
test.setTimeout(90_000);
const originalPools = await listPools(request);
const originalAccountIds = (await (await request.get(`/api/companies/${companyId}/ai-connections`)).json()).connections.map((account: { id: string }) => account.id).sort();
let poolId: string | undefined;
try {
await page.goto(`/${prefix}/dashboard`);
await page.getByRole("link", { name: "Connectors", exact: true }).click();
await page.getByRole("button", { name: `Add connection pool ${connector.name}`, exact: true }).click();
await expect(page.getByRole("heading", { name: "Add a connection pool", exact: true })).toBeVisible();
await expect(page.getByRole("button", { name: "Continue", exact: true })).toBeDisabled();
await expect(page.getByRole("link", { name: "Connect a new account", exact: true })).toHaveAttribute("target", "_blank");
for (const account of accounts) await page.getByRole("checkbox", { name: account.name, exact: true }).check();
await page.getByRole("button", { name: "Continue", exact: true }).click();
await page.getByRole("button", { name: `Move ${accounts[1]!.name} up`, exact: true }).click();
await page.getByRole("button", { name: "Back", exact: true }).click();
for (const account of accounts) await expect(page.getByRole("checkbox", { name: account.name, exact: true })).toBeChecked();
await page.getByRole("button", { name: "Continue", exact: true }).click();
await expect(page.getByRole("list", { name: "Connection order" }).getByRole("listitem").first()).toContainText(accounts[1]!.name);
await page.getByRole("button", { name: "Create pool", exact: true }).click();
await expect(page).toHaveURL(/\/apps\/[a-f0-9-]+\/permissions$/);
poolId = new URL(page.url()).pathname.split("/").at(-2)!;
const saved = async () => (await listPools(request)).find(pool => pool.id === poolId)!;
expect(await saved()).toMatchObject({ enabled: false, mode: "round_robin", thresholdPercent: 90 });
expect((await saved()).members.map(member => member.binding.connectionId)).toEqual([accounts[1]!.id, accounts[0]!.id]);
await expect(page.getByRole("link", { name: "Settings", exact: true })).toBeVisible();
await expect(page.getByRole("link", { name: "Review", exact: true })).toHaveCount(0);
await expect(page.getByRole("checkbox", { name: "Enable this pool", exact: true })).not.toBeChecked();
await expect(page.getByRole("region", { name: "Used by", exact: true })).toContainText("No agents yet.");
const name = `Pool E2E ${Date.now()}`;
await page.getByRole("button", { name: "Rename app", exact: true }).click();
await page.getByRole("textbox", { name: "App name", exact: true }).fill(name);
await page.getByRole("button", { name: "Save", exact: true }).click();
await expect(page.getByRole("heading", { name, level: 1 })).toBeVisible();
await page.getByRole("button", { name: `Remove ${accounts[0]!.name}`, exact: true }).click();
await page.getByRole("button", { name: "Save changes", exact: true }).click();
await expect.poll(async () => (await saved()).members.length).toBe(1);
await page.reload();
await expect(page.getByRole("list", { name: "Connection order" }).getByRole("listitem")).toHaveCount(1);
await page.getByRole("button", { name: "Add connections", exact: true }).click();
const picker = page.getByRole("dialog", { name: "Add connections", exact: true });
await picker.getByRole("checkbox", { name: accounts[0]!.name, exact: true }).check();
await picker.getByRole("button", { name: "Done", exact: true }).click();
await page.getByRole("checkbox", { name: "Enable this pool", exact: true }).check();
await page.getByRole("button", { name: "Save changes", exact: true }).click();
await expect.poll(async () => (await saved()).enabled).toBe(true);
await page.reload();
await expect(page.getByRole("heading", { name, level: 1 })).toBeVisible();
await expect(page.getByRole("checkbox", { name: "Enable this pool", exact: true })).toBeChecked();
await expect(page.getByRole("list", { name: "Connection order" }).getByRole("listitem")).toHaveCount(2);
// Two real pages keep their reviewed revisions. A stale save must not
// overwrite a newer edit, and refreshing must recover the latest version.
const other = await page.context().newPage();
await other.goto(page.url());
await expect(other.getByRole("heading", { name, level: 1 })).toBeVisible();
await page.getByRole("checkbox", { name: "Enable this pool", exact: true }).uncheck();
await page.getByRole("button", { name: "Save changes", exact: true }).click();
await expect.poll(async () => (await saved()).enabled).toBe(false);
await other.getByRole("button", { name: "Save changes", exact: true }).click();
await expect(other.getByRole("alert")).toContainText(/changed|reload/i);
expect((await saved()).enabled).toBe(false);
await other.close();
await page.getByRole("button", { name: "Manage connection pool", exact: true }).click();
await page.getByRole("menuitem", { name: "Remove connection", exact: true }).click();
const confirmation = page.getByRole("alertdialog");
await expect(confirmation).toContainText("The connections in this pool are kept.");
await confirmation.getByRole("button", { name: "Cancel", exact: true }).click();
expect(await saved()).toBeTruthy();
await page.getByRole("link", { name: "All connectors", exact: true }).click();
await page.getByRole("button", { name: `Manage ${name} connection`, exact: true }).click();
await page.getByRole("menuitem", { name: "Remove connection", exact: true }).click();
await page.getByRole("alertdialog").getByRole("button", { name: "Remove connection", exact: true }).click();
await expect(page.getByRole("alertdialog")).toHaveCount(0);
await expect.poll(async () => (await listPools(request)).map(pool => pool.id).sort()).toEqual(originalPools.map(pool => pool.id).sort());
await expect(page.getByRole("button", { name: `Open ${name} permissions`, exact: true })).toHaveCount(0);
const remaining = await (await request.get(`/api/companies/${companyId}/ai-connections`)).json();
expect(remaining.connections.map((account: { id: string }) => account.id).sort()).toEqual(originalAccountIds);
} finally {
// Cleanup only this test's own disposable pool, through the normal API.
if (poolId) {
const pool = (await listPools(request)).find(pool => pool.id === poolId);
if (pool) expect((await request.delete(`${poolsPath}/${poolId}`, { data: { expectedRevision: pool.revision } })).ok()).toBe(true);
}
}
});
test("an unavailable dynamic router stays on an actionable setup page", async ({ page }) => {
await page.goto(`/${prefix}/apps/connect?${new URLSearchParams({ source: "ai-router-0000" })}`);
await expect(page.getByRole("alert")).toContainText("This connection pool plugin is unavailable. Enable it in Plugins.");
await expect(page).toHaveURL(/\/apps\/connect\?/);
});
test("a saved pool shows its configured agents with avatars and profile links", async ({ page, request }) => {
const pools = await listPools(request);
const response = await request.get(`/api/companies/${companyId}/agents`);
expect(response.ok()).toBe(true);
const agents = await response.json() as Array<{ id: string; name: string; status: string; runtimeConfig: { aiConnection?: { mode: string; connectionId?: string } } }>;
const pool = pools.find(candidate => agents.some(agent => agent.status !== "terminated" && agent.runtimeConfig.aiConnection?.mode === "router" && agent.runtimeConfig.aiConnection.connectionId === candidate.id));
test.skip(!pool, "Bind a test agent to a saved pool to verify populated usage");
const expected = agents.filter(agent => agent.status !== "terminated" && agent.runtimeConfig.aiConnection?.mode === "router" && agent.runtimeConfig.aiConnection.connectionId === pool!.id).sort((a, b) => a.name.localeCompare(b.name));
await page.goto(`/${prefix}/apps/${pool!.id}/permissions`);
const usedBy = page.getByRole("region", { name: "Used by", exact: true });
await expect(usedBy.getByRole("link")).toHaveCount(expected.length);
for (const agent of expected) {
const link = usedBy.getByRole("link", { name: agent.name, exact: true });
await expect(link).toHaveAttribute("href", `/${prefix}/agents/${agent.id}`);
await expect(link.locator('[data-slot="agent-avatar"]')).toBeVisible();
}
});