mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - People also ask agents for work in their existing chat tools. > - Each external conversation needs one task and a current authorized source. > - Retries, Stop, and provider failures must not duplicate work or expose private data. > - The first chat PR establishes the opt-in provider and data contracts. > - This PR adds experimental channel integration and its durable control plane. > - Users can request work from connected channels and inspect delivery in Paperclip. ## Linked Issues or Issue Description Refs #13100 and #13092. This is the second of exactly two chat PRs. Foundation #13100 is merged and changed 143 files. Runner prerequisite #13092 is also merged. This PR changes 400 files against master, below the 500-file review limit. It contains no wireframe images or HTML galleries. ## What Changed - Add native Slack, GitHub, Microsoft Teams, Telegram, and Discord chat connections. Keep chat disabled unless the operator enables experimental chat connectors. Preserve the production GitHub tool connection and its normal setup path. - Bind each provider bot identity to one immutable Paperclip agent. Bind each admitted external conversation to one task. Paperclip owns tasks, runs, permissions, and audit records. - Add durable admission, per-conversation queues, questions, task controls, progress, final replies, images, files, and delivery receipts. Board comments remain internal unless explicitly sent to the channel. - Check current identity, provider reach, resource access, credentials, runtime generation, and exact source before provider effects. Keep private responses private. Never send raw reasoning, private logs, credentials, or tool arguments. - Hold uncertain sends for explicit audited resolution. Make Board Send-to-channel atomic and idempotent. Keep reconnect and setup credentials in Paperclip secret storage. - Preserve current native-runner authority across retries, lost acknowledgements, and recovery. Keep immutable input and completion contracts separate from newer user input. Receipt reconciliation cannot launch a provider. - Reconcile chat close/new ordering and provider-effect lock order. Audit resource access changes in the same transaction. Submit only the selected resource from each UI toggle so stale pages cannot undo unrelated access changes. - Drain Codex stdout before certifying process exit. Bound the drain with the existing shutdown grace. Preserve observed terminal authority without treating an undrained process as successful or reusable. - Incorporate master `018ca5da` with its ACP Stop, mobile task layout, runner packaging, and official lock changes. Preserve dedicated chat-answer continuations in both directions when ordinary queued comments are adopted after Stop. - Fence late adapter readiness behind an earlier Stop for the same run. Preserve verified cleanup for registered adapters. Handle single Stop, agent pause, duplicate Stops, and failure release without creating a false cancellation receipt. - Incorporate master's `6dd48cad4` wake-queue extraction. Preserve exact failed-chat retry authorization and lineage, retired question-source suppression, and the block on generic recovery that would discard the admitted source. Fresh deferred input retains its separate promotion path. - Incorporate master `2a05b5ed3` and its queue-admission extraction, simplified transaction ports, and separate runner CI job. Preserve exact durable receipts, actor separation, and dedicated-answer isolation through the new module. A failed receipt insert rolls back the accompanying deferred-wake merge. ## Verification Current head: `afe19299d06253cb628eb398e91d1200ea9f412a`, incorporating master `2a05b5ed3457ea33efd6895520447d1d97fe98d8`. The conflicts are resolved. This successor fixes two test-harness boundaries exposed by CI: per-case route-module preparation and actual durable-save completion before intentional runner termination. Production code and all existing test/turn deadlines are unchanged. [Exact-head Greptile review](https://github.com/paperclipai/paperclip/pull/13038#issuecomment-5587250594) is **5/5**, completed September 10 at 13:20:55 UTC, with no actionable findings or open review threads. [Fresh exact-head CI](https://github.com/paperclipai/paperclip/actions/runs/34481724341) passes **all 24 jobs**, including Build and both required aggregates. Normal exact-head guarded merge was attempted and rejected by the remaining branch approval policy: CODEOWNER review is required and no human approval is present. Normal **squash auto-merge is enabled** as of September 10 at 13:36:26 UTC. Requested CODEOWNERS have been notified; no approval bypass or self-approval was used. Earlier-head results below remain historical evidence, not qualification of this successor. - Final exact-head Linux evidence: 995/995 chat integration cases; 36/36 agent-skills routes; 35/35 runner live-session cases, including real process kill/resume; 1948 runner Vitest cases with three existing benchmark/platform guards; 870/870 API-authority cases; and 104 browser cases with four existing optional skips. Rust, conformance/replay, full repository build, typecheck, canary, all server/workspace shards, and both required aggregates pass with normal CI concurrency. Earlier failed attempts remain recorded below. - Latest test-only qualification: 141/141 route/permissions/authentication cases pass in separate cold forks, with plain server types and independent review clear. The real-runner suite passes 35/35, with plain runner types and independent review clear. A controlled premature-save acknowledgement fails as expected; matching ownership/effect/process evidence, rejected saves, real turn outcome, test abort, and pre-kill liveness are covered. No local reproduction of the original CI scheduling failure is claimed. The preceding [CI run](https://github.com/paperclipai/paperclip/actions/runs/34479680858) passes 21/24 jobs, including all 995 Linux chat cases and browser aggregate (104 passed, four existing optional skips); only Build, the skills serialized shard, and the required verification aggregate fail. Its exact-head Greptile review was 5/5. Both failed job logs are retained. - Final fixture qualification: all eight focused Discord cases and all 995 chat integration cases pass. The exact modal statement/PID is observed before taking the real connection lock; the test then proves its actual blocking relationship before mutation. Original SQL execution, provider behavior, negative assertions, and 1s/15s timeouts remain unchanged. Independent review is clear and test/production hashes remain frozen. The preceding [CI attempt](https://github.com/paperclipai/paperclip/actions/runs/34477184777) passed 22 jobs, including Build/runner, typecheck, canary, all other test shards, and browser aggregate (104 passed, four existing optional skips); the two fixture failures and failed verification aggregate remain recorded, not relabeled as a pass. - Current queue-module composition: 308/308 recovery/batching/queue/Stop tests; 995/995 full chat integration; 89/89 module tests, including real PostgreSQL receipt-insert rollback; 24/24 workflow/module-boundary tests; plain server and UI types. All four actual local process/ACP browser paths pass in 1.4 minutes. Fresh databases, no skips or retries, stable reviewed source hashes. The initial boundary failure is retained; its no-op service wrapper was removed without changing recovery context or weakening the check. An exploratory standalone test-directory typecheck fails because its new upstream transformation config is not a standalone typechecking project; standard CI/build does not invoke it, and no configuration was weakened to suppress those diagnostics. - The preceding head `e02a63d462ce5d47433b0aeb632bb6fd20aab1ba` passed [all 24 CI jobs](https://github.com/paperclipai/paperclip/actions/runs/34436462958) and exact-head Greptile review at 5/5. Required CODEOWNER review prevented its normal merge before master advanced again. - Final extracted-module composition: 307/307 recovery, batching, queue and Stop-control tests; 995/995 full chat integration; 49/49 module tests including eight PostgreSQL adapter cases; and 19/19 issue-update tests. Plain server types pass. All four actual local process/ACP browser paths pass in 1.3 minutes. Fresh databases, no skips or retries in these cohorts, frozen source hashes, and independent review clear. - The preceding head `3e4e1c1c` passes [all PR CI jobs](https://github.com/paperclipai/paperclip/actions/runs/34415826820), including Build and required `ci / verify` and `ci / e2e`. Both the original Rust failure and the previously load-sensitive lineage fixture pass with unchanged Linux concurrency. Master advanced afterward and required this reconciliation. - Final master composition: 448/448 focused UI tests, 186/186 adapter tests, 24/24 queue/control tests, and 11/11 packaging tests. Plain UI, server, shared, and adapter types pass. Token gates and diff checks pass. Independent server and UI reviews are clear. - Stop-registration regression: both real-service cases fail against exact `a95` source and pass with the fix. The full corrected recovery/control suite passes 265/265. Duplicate-owner and failed-Stop controls also pass. Plain server types pass. The readiness barrier prevents provider startup without adding an acknowledgment to an already terminal run. - Final qualification strengthens terminal-field equality and repeats both affected cases successfully on a fresh database. All four actual local process/ACP browser paths pass again in 1.3 minutes, without skips or retries. The final screenshot shows Cancelled, a paused subtree, retained input, and no error toast. - Two new actual-service regressions fail before the merge fix. They prove that queued-comment adoption could consume a dedicated chat answer or add unrelated input to that answer. The fixed four-case cohort passes, including ordinary upstream continuation and adapter Stop controls. Full recovery passes 257/257. All four actual local process/ACP Stop browser flows pass in 1.4 minutes, without skips or retries, on a fresh database. - The unchanged runner artifact was qualified with 171/171 transport tests, 870/870 API-authority tests, conformance 1/1, and replay 11/11. Six controlled reader tests prove the exit/drain repair. Its local serial Rust workspace passed 546 top-level cases plus two invoked helpers; the later passing Linux CI supplies default-concurrency evidence. - Prior exact-source full chat integration passes 995/995. Settings regressions cover concurrent stale pages, 501 destinations, pending state, rejected updates, and explicit retry. These deterministic tests do not prove live provider behavior. - Retained failed attempts and their causes are in the [qualification log](https://github.com/paperclipai/paperclip/blob/afe19299d06253cb628eb398e91d1200ea9f412a/doc/plans/chat-adapters/2026-09-08-chat-queue-and-webhook-repair.md). The first merge adapter run timed out while macOS slept for 290 seconds. Its unchanged repeat passed with a temporary sleep guard. No assertion, deadline, or CI gate was weakened. Review commands include `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-process-recovery.test.ts src/__tests__/issue-queued-comments-routes.test.ts` and `pnpm exec playwright test --config tests/e2e/playwright.config.ts tests/e2e/acp-stop-continuation.spec.ts`. Database suites require fresh disposable databases. See the [browser runbook](https://github.com/paperclipai/paperclip/blob/afe19299d06253cb628eb398e91d1200ea9f412a/doc/plans/chat-adapters/2026-09-04-chat-adapters-browser-e2e-runbook.md) for provider setup and separate live acceptance steps. ## Risks - This remains experimental. Deterministic tests and bounded live evidence do not establish every provider feature, tenant, permission layout, or media shape. Teams work-tenant qualification is still open. - Failed and uncertain provider effects remain visible and can require operator action. A transport receipt does not prove recipient visibility. - Native controller and runner artifacts must remain compatible. Preserve lease ownership, terminal authority, source binding, and quarantine during future changes. - Access and audit rows commit together, but activity notifications remain best-effort. This is not a new durable event outbox. - The PR operation does not deploy a live server, replace its runner, or change provider permissions. Remaining live qualification is documented in the [temporary handoff](https://github.com/paperclipai/paperclip/blob/afe19299d06253cb628eb398e91d1200ea9f412a/doc/plans/chat-adapters/2026-09-08-open-qualification-followups.md). ## Model Used OpenAI Codex assisted with implementation, tool execution, testing, and review. The work records `gpt-6-astra` assistance. The environment does not report a context-window size. No private reasoning traces are included. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
147 lines
12 KiB
JavaScript
147 lines
12 KiB
JavaScript
export const providerScreens = [
|
|
{
|
|
id: "13", slug: "slack-setup", provider: "Slack", phase: "Setup", group: "Slack", kind: "providerSetup",
|
|
title: "Invite Maya to Slack", subtitle: "Create or select a Slack app, then verify its workspace installation.",
|
|
rationale: "Paperclip generates the exact provider handoff while keeping Slack-owned installation and workspace policy visible.",
|
|
annotations: [
|
|
"The selected Paperclip agent and derived Slack bot identity stay fixed throughout setup.",
|
|
"Direct webhook is the default; relay and Socket Mode are advanced alternatives for private deployments.",
|
|
"The generated manifest owns the exact scopes, events, interactivity URL, and optional command configuration.",
|
|
"Secrets are masked references; workspace install or OAuth happens in Slack, not inside a Paperclip imitation.",
|
|
"Verification separates identity, signature, scopes, events, and workspace membership so failures are actionable."
|
|
]
|
|
},
|
|
{
|
|
id: "14", slug: "slack-settings", provider: "Slack", phase: "Configuration", group: "Slack", kind: "providerSettings",
|
|
title: "Slack settings", subtitle: "Choose reach and rich behavior after the bot is connected.",
|
|
rationale: "Slack exposes the richest optional surface, but least-privilege thread behavior remains the default.",
|
|
annotations: [
|
|
"Reach is the intersection of the saved allowlist and channels where Slack has actually added the bot.",
|
|
"Root mention → Slack thread → one Paperclip issue is fixed; bound-thread replies continue without mentions.",
|
|
"DMs, Agent Sessions, progress cadence, files, Block Kit, modals, commands, and ephemeral replies are independent controls.",
|
|
"OAuth/Grid identity, token rotation, scope drift, and optional Socket Mode live under Security and delivery.",
|
|
"Unsupported or ungranted features show a precise fallback and reinstall action instead of failing silently."
|
|
]
|
|
},
|
|
{
|
|
id: "15", slug: "slack-interactions", provider: "Slack", phase: "Interactions", group: "Slack", kind: "providerInteractions",
|
|
title: "Slack interaction model", subtitle: "A root mention moves the work into one native thread and one Paperclip issue.",
|
|
rationale: "This makes the Hermes thread contract and Slack-specific acknowledgement/action deadlines inspectable.",
|
|
annotations: [
|
|
"A human mentions @maya in a channel root; an unmentioned fresh root message is ignored.",
|
|
"Paperclip durably records and acknowledges the event before task work begins.",
|
|
"Maya replies under the activation message; that Slack thread binds exactly one assigned Paperclip issue.",
|
|
"Later human replies, files, and actions in the bound thread become turns after current permission checks.",
|
|
"Safe streaming, stop/actions, final delivery, and error fallback stay in the thread; internal traces never publish."
|
|
]
|
|
},
|
|
{
|
|
id: "16", slug: "github-setup", provider: "GitHub", phase: "Setup", group: "GitHub", kind: "providerSetup",
|
|
title: "Connect Maya to GitHub conversations", subtitle: "Install a least-privilege GitHub App on selected repositories.",
|
|
rationale: "GitHub chat setup deliberately excludes code/tool authority and makes repository installation scope explicit.",
|
|
annotations: [
|
|
"The purpose is Chat with an agent; repository code access remains a separate GitHub tool connection.",
|
|
"GitHub App is recommended; PAT is marked testing-only and GitHub Enterprise adds an API base URL.",
|
|
"Paperclip provides the webhook URL/secret and the minimum Issues, Pull requests, and Metadata permissions.",
|
|
"The operator installs the App on selected repositories and stores the App ID/private key as secret references.",
|
|
"Verification checks signature delivery, bot identity, subscribed events, installation, and selected repositories."
|
|
]
|
|
},
|
|
{
|
|
id: "17", slug: "github-settings", provider: "GitHub", phase: "Configuration", group: "GitHub", kind: "providerSettings",
|
|
title: "GitHub conversation settings", subtitle: "Choose repositories, activation surfaces, and comment behavior.",
|
|
rationale: "The settings reflect GitHub's object-based threads and its narrower non-realtime interaction surface.",
|
|
annotations: [
|
|
"The Paperclip repository allowlist can only narrow the repositories selected in the GitHub App installation.",
|
|
"Issues, PR conversations, and inline review-comment threads are distinct activation surfaces and bindings.",
|
|
"Mention-only activation is the default; labels or trusted-author automation are explicit advanced policies.",
|
|
"Output uses GFM, reactions, and coarse comment edits; files and governed actions become Paperclip links.",
|
|
"Permission drift, installation suspension, GHES URL, rate limits, and self-message suppression are operational settings."
|
|
]
|
|
},
|
|
{
|
|
id: "18", slug: "github-interactions", provider: "GitHub", phase: "Interactions", group: "GitHub", kind: "providerInteractions",
|
|
title: "GitHub interaction model", subtitle: "A mention binds the existing issue, PR, or review thread to one Paperclip issue.",
|
|
rationale: "GitHub supplies the conversation object, so Paperclip binds it rather than manufacturing a new native thread.",
|
|
annotations: [
|
|
"A user mentions the bot in an issue, PR conversation, or inline review comment.",
|
|
"Webhook signature and delivery ID are verified before principal, repository, and activation checks.",
|
|
"The existing GitHub object/thread maps once to a Paperclip issue; an inline review thread remains separate from the PR conversation.",
|
|
"Maya reacts, posts or edits one GFM progress comment, and publishes the final answer without token streaming.",
|
|
"Buttons, modals, ephemeral replies, DMs, and uploads fall back to text plus authenticated Paperclip URLs."
|
|
]
|
|
},
|
|
{
|
|
id: "19", slug: "teams-setup", provider: "Microsoft Teams", phase: "Setup", group: "Teams", kind: "providerSetup",
|
|
title: "Install Maya in Microsoft Teams", subtitle: "Register the app and bot, then install its package in the tenant.",
|
|
rationale: "Teams setup exposes every external ownership boundary: Entra/bot registration, endpoint, package, tenant policy, and install.",
|
|
annotations: [
|
|
"Paperclip fixes Maya and supplies the public messaging endpoint before the operator enters Microsoft tooling.",
|
|
"Teams Developer CLI is the recommended handoff; manual Azure/Developer Portal setup remains available.",
|
|
"Client secret and federated identity are mutually exclusive; single-tenant, multi-tenant, and sovereign cloud are explicit.",
|
|
"Custom-app upload or tenant approval may block installation and is reported as an external admin action.",
|
|
"Verification covers Entra/bot identity, manifest, endpoint reachability, install scope, and tenant."
|
|
]
|
|
},
|
|
{
|
|
id: "20", slug: "teams-settings", provider: "Microsoft Teams", phase: "Configuration", group: "Teams", kind: "providerSettings",
|
|
title: "Microsoft Teams settings", subtitle: "Configure chat scopes and add privileged Graph access only when needed.",
|
|
rationale: "Teams permissions are layered; basic mention/reply must work without broad directory or history grants.",
|
|
annotations: [
|
|
"Personal, team/channel, and group-chat reach is bounded by app installation and Paperclip allowlists.",
|
|
"Channel post/reply threads map one issue; DMs and group chats use the stable Teams conversation.",
|
|
"Mention-only is default. RSC all-message/history access is a per-resource, off-by-default grant.",
|
|
"User directory lookup and DM history show their broader Entra application permission and admin-consent status.",
|
|
"Adaptive Cards, task modules, targeted messages, files, and DM streaming expose exact group/channel fallbacks."
|
|
]
|
|
},
|
|
{
|
|
id: "21", slug: "teams-interactions", provider: "Microsoft Teams", phase: "Interactions", group: "Teams", kind: "providerInteractions",
|
|
title: "Microsoft Teams interaction model", subtitle: "The native conversation type determines threading, streaming, and permissions.",
|
|
rationale: "Teams channel posts, group chats, and DMs need visibly different runtime behavior behind one endpoint.",
|
|
annotations: [
|
|
"A channel root mention starts work in that post's reply thread; the original post is the stable thread root.",
|
|
"A DM or group-chat message binds the stable Teams conversation according to the configured task-boundary policy.",
|
|
"Paperclip verifies the bot activity, resolves tenant/member identity, and applies current access before waking Maya.",
|
|
"DMs can stream natively; group/channel output buffers or edits and uses Adaptive Cards/task modules for actions.",
|
|
"RSC-disabled unmentioned traffic is ignored; denied or unsupported actions use targeted/DM or text-link fallback."
|
|
]
|
|
},
|
|
{
|
|
id: "22", slug: "telegram-setup", provider: "Telegram", phase: "Setup", group: "Telegram", kind: "providerSetup",
|
|
title: "Connect Maya to Telegram", subtitle: "Create a dedicated bot with BotFather, then choose webhook or polling delivery.",
|
|
rationale: "Telegram has no managed installation object, so bot identity, delivery mode, privacy, and chat membership are separate checks.",
|
|
annotations: [
|
|
"One BotFather bot represents one Paperclip agent; name, username, avatar, and token come from Telegram.",
|
|
"Privacy mode stays on and group joining is allowed; commands and forum-topic rights are optional provider setup.",
|
|
"Verified webhook is production default; polling is for local long-running development and cannot run simultaneously.",
|
|
"Paperclip supplies the HTTPS webhook URL and secret token, while the operator adds the bot to intended chats.",
|
|
"Verification checks getMe identity, webhook/polling exclusivity, pending updates/errors, privacy guidance, and chat reach."
|
|
]
|
|
},
|
|
{
|
|
id: "23", slug: "telegram-settings", provider: "Telegram", phase: "Configuration", group: "Telegram", kind: "providerSettings",
|
|
title: "Telegram settings", subtitle: "Make task boundaries explicit for DMs, groups, and forum topics.",
|
|
rationale: "Telegram's privacy mode and mostly linear chats require different continuation rules from Slack-style subscribed threads.",
|
|
annotations: [
|
|
"Allowed chats, topics, and users narrow the bot token's reach; privacy mode remains a visible safety assumption.",
|
|
"DMs keep one active issue; /new or New task starts another, and /close ends the active binding.",
|
|
"Groups activate on @maya and continue only through replies to the bot or new mentions; forum topics can map one issue each.",
|
|
"Post-and-edit is default; native draft previews are private-chat-only and opt-in with a rate-safe cadence.",
|
|
"Inline buttons, files, callback limits, no ephemeral/modal/select support, flood control, and bot-to-bot off are explicit."
|
|
]
|
|
},
|
|
{
|
|
id: "24", slug: "telegram-interactions", provider: "Telegram", phase: "Interactions", group: "Telegram", kind: "providerInteractions",
|
|
title: "Telegram interaction model", subtitle: "Privacy-safe replies and explicit New task controls replace universal native threads.",
|
|
rationale: "The flow distinguishes private chats, ordinary groups, and forum topics rather than pretending Telegram behaves like Slack.",
|
|
annotations: [
|
|
"In a DM, the first message creates the active issue; /new or an inline button deliberately starts a fresh one.",
|
|
"In a privacy-on group, @maya activates and a reply to Maya continues; unrelated group traffic is not consumed.",
|
|
"In a forum, message_thread_id provides a stable topic-to-issue boundary when the bot is present.",
|
|
"Paperclip deduplicates update_id, enforces actor/chat scope, then uses typing/reaction and throttled output.",
|
|
"Inline callbacks carry opaque IDs; unsupported or governed interactions return concise text/DM plus a Paperclip link."
|
|
]
|
|
}
|
|
];
|