mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:24:09 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Agents use connections to reach external services. > - A fresh native task can have no service tools installed. > - The agent needs a way to discover services and ask the responsible person for access. > - This pull request brings the existing connection-intent flow into native task execution. > - The person can connect from the task, and the agent can continue with updated tools. ## Linked Issues or Issue Description **Subsystem affected** Native runner tool authority, connection intents, task interactions, and shared connection setup. **Problem or motivation** A task that needs an unconnected service cannot finish its work. Leaving the task to configure access also loses context. A resolved request must survive a restart and resume the correct agent once. **Proposed solution** Expose connection discovery and access requests as server-owned native tools. Render a durable task card and use the shared setup dialog. Persist outcome delivery and start a fresh provider session after access is ready. **Alternatives considered** Sending the person to the Connections page adds navigation and does not solve continuation. Polling for authorization consumes runs and can create duplicate requests. **Roadmap alignment** This extends the existing connection-intent runtime and setup experience. It reuses the shared access model and the native runner. Related: #12345, #12347. The service-slug fix in #12906 is related but separate. Companion evaluation PR: https://github.com/paperclipai/paperclip-evals/pull/21. ## What Changed - Expose `connections_search` and `connection_request` with server-bound company, task, agent, and responsible user. Preserve the legacy entry points. - Discover catalog services and authorized custom connections. Check installation, identity, health, and executable permissions before reporting ready. - Keep pending cards through ordinary messages. Reuse requests and retire stale ownership. Put Connect at the right of Not now. - Reuse the shared setup flow in a task dialog. Keep access additive and default to the requesting agent. Recover from cancelled or blocked OAuth windows with a new-tab fallback. - Persist outcome delivery with an idempotent wake key. Resume in a fresh session and recheck ownership before dispatch. - Add native browser fixtures, offline Storybook states, server contracts, and evaluation fixtures. Update guidance and documentation. ## Verification - `pnpm build`: passed after replaying the change on current master. - `pnpm -r typecheck`: passed. - `pnpm check:token-gates`: passed. - `pnpm --filter @paperclipai/ui build-storybook`: passed. - New continuation-policy regression cases: 16 passed. - Docker-backed PostgreSQL regressions passed for requester-only OAuth access, assignment-only expiry, terminal expiry, and credential-free setup metadata. - Shared setup and task-card UI tests: 121 passed, including configured MCP reconnect URL recovery and preserving user edits across refetch. - Storybook browser checks: all 119 passed on the latest reconnect fix. - `pnpm test:run`: 4,734 tests passed in the first server group, but embedded PostgreSQL startup failures and resulting cleanup errors prevented a complete local pass. All Linux CI lanes passed on the latest reviewed commit. One external-object route test returned an unexplained 500 on the first run; it passed twice locally and the failed shard passed on retry without code changes. - Earlier feature-checkout evidence: three deterministic native browser journeys passed, including restart delivery and an actual fixture tool result. Legacy scripted coverage also passed. All 59 added stories were inspected in light and dark themes. - Live Notion testing recorded successful provider reads. The manual test used a local-trusted instance. It does not prove authenticated/cloud deployment or every provider journey. - Native browser rerun reached the embedded PostgreSQL startup limit before bootstrap, so the latest checkout’s full native browser journey remains unverified. Both OAuth page/task regression cases passed against isolated Docker-backed PostgreSQL 17. They verify no premature task access, requester-only completion, additive retries, and reconnect preservation. - Applied both new migrations twice to isolated PostgreSQL 17. Foreign keys remained intact, duplicate active delivery keys were rejected, and failed delivery records did not block retries. Reviewer path: start a fresh test drive, enable the native runner, use an agent that can perform work directly, and ask it to summarize a Notion page. Connect from the card, then verify the resumed provider call and source-linked answer. The default test-drive CEO is instructed to delegate, so it can introduce an unrelated hiring step. ## Risks - Two additive migrations create durable deliveries and a partial unique wake index. They are idempotent. The wake index can require a maintenance window on large tables because migrations run in a transaction. - OAuth and continuation cross asynchronous boundaries. Tests cover ownership changes, retries, additive access, and restart delivery; live provider behavior still varies. - The latest requester-scope fix has not yet been exercised through live OAuth. GitHub, API-key, authenticated-user, and all recovery journeys are not claimed as verified. ## Model Used OpenAI GPT-6-based Codex assisted with implementation, tests, and review using tools and code execution. The runtime does not expose the exact model version, context window, or reasoning setting. Live evaluation used `gpt-5.6-luna`; manual native testing used `gpt-5.6-sol`. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used and disclosed unavailable runtime details - [x] I have checked ROADMAP.md and confirmed this extends existing connection work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have described the issue in-PR following the feature issue template - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal ticket id - [ ] I have run all required tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation - [x] I have considered and documented risks - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
60 lines
2.7 KiB
JavaScript
60 lines
2.7 KiB
JavaScript
import { readdirSync } from "node:fs";
|
|
import path from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
import { loadShardDurations, partitionGeneralServerSuites } from "./general-server-shard.mjs";
|
|
|
|
const HERE = path.dirname(fileURLToPath(import.meta.url));
|
|
const REPO_ROOT = path.resolve(HERE, "..");
|
|
const E2E_DIR = path.join(REPO_ROOT, "tests", "e2e");
|
|
const DURATIONS_MANIFEST = path.join(HERE, "e2e-shard-durations.json");
|
|
|
|
// Specs the default local_trusted Playwright project deliberately skips. Keep
|
|
// this in sync with `testIgnore` in tests/e2e/playwright.config.ts — the unit
|
|
// test in scripts/__tests__/e2e-shard.test.mjs fails if the two ever drift.
|
|
export const IGNORED_SPECS = ["in-feed-native/**", "multi-user.spec.ts", "multi-user-authenticated.spec.ts"];
|
|
|
|
// Enumerates the specs the default e2e lane actually runs, as repo-relative
|
|
// paths so the output can be handed straight to `playwright test`.
|
|
export function listE2eSpecs(e2eDir = E2E_DIR, repoRoot = REPO_ROOT) {
|
|
return readdirSync(e2eDir)
|
|
.filter((entry) => entry.endsWith(".spec.ts") && !IGNORED_SPECS.includes(entry))
|
|
.map((entry) => path.relative(repoRoot, path.join(e2eDir, entry)).split(path.sep).join("/"))
|
|
.sort((a, b) => a.localeCompare(b));
|
|
}
|
|
|
|
// Playwright's own --shard balances by test count, which is useless here: one
|
|
// spec (smoke-lab) is ~40% of the lane's wall clock. Reuse the deterministic
|
|
// longest-processing-time partition already proven on the general-server lane
|
|
// so every runner computes the identical, non-overlapping split.
|
|
export function selectE2eShard(files, shardIndex, shardCount, durations = {}) {
|
|
return partitionGeneralServerSuites(files, shardCount, durations)[shardIndex].files;
|
|
}
|
|
|
|
function parseArgs(argv) {
|
|
const args = { shardIndex: 0, shardCount: 1 };
|
|
for (let index = 0; index < argv.length; index += 1) {
|
|
if (argv[index] === "--shard-index") args.shardIndex = Number(argv[index + 1]);
|
|
if (argv[index] === "--shard-count") args.shardCount = Number(argv[index + 1]);
|
|
}
|
|
return args;
|
|
}
|
|
|
|
function main(argv) {
|
|
const { shardIndex, shardCount } = parseArgs(argv);
|
|
if (!Number.isInteger(shardCount) || shardCount < 1) {
|
|
throw new Error(`--shard-count must be a positive integer, got ${shardCount}`);
|
|
}
|
|
if (!Number.isInteger(shardIndex) || shardIndex < 0 || shardIndex >= shardCount) {
|
|
throw new Error(`--shard-index must be in [0, ${shardCount}), got ${shardIndex}`);
|
|
}
|
|
|
|
const specs = listE2eSpecs();
|
|
const durations = loadShardDurations(DURATIONS_MANIFEST);
|
|
process.stdout.write(`${selectE2eShard(specs, shardIndex, shardCount, durations).join(" ")}\n`);
|
|
}
|
|
|
|
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
|
|
main(process.argv.slice(2));
|
|
}
|