Files
PaperClipAI/tests/e2e/applications-crud.spec.ts
T
DottaandPaperclip 0a511ed1b0 feat(apps): support multiple provider connections (#11060)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Apps subsystem connects company tools through governed provider
connections.
> - A company can need more than one account for the same provider.
> - The current database constraint and Apps flow assume one named
connection per company.
> - New quarantined actions also need an explicit review decision before
activation.
> - This pull request supports multiple provider connections and
complete action review decisions.
> - The benefit is safer access control and a clear multi-account Apps
workflow.

## Linked Issues or Issue Description

Refs: #11040

**Subsystem affected**

Cross-cutting. This change affects the Apps UI, the tool access API, the
shared request contract, and the database schema.

**Problem or motivation**

The connection name constraint prevents a company from keeping more than
one connection for a provider. The Apps UI also reuses an existing OAuth
connection when a user asks to connect another account. Action review
can enable selected entries without recording a decision for every
quarantined action.

**Proposed solution**

Remove the company and connection name uniqueness constraint. Let users
open, count, edit, and create multiple provider connections. Require the
finish request to cover every quarantined action exactly once before the
server activates reviewed entries.

**Alternatives considered**

The UI could generate unique internal names and keep the database
constraint. This would preserve a one-connection assumption in the data
model and would make display names part of identity. The server could
also infer review decisions from enabled actions. This would not
distinguish a reviewed disabled action from an action that the user did
not review.

**Roadmap alignment**

This change extends the completed MCP Tool Gateway and Apps milestone.
It also supports the Connected Apps roadmap item. It follows the
navigation and connection management work in #11040.

## What Changed

- Remove the company-scoped connection name uniqueness index with an
ordered and idempotent migration.
- Add a reviewed action list to the finish-app contract and reject
incomplete or duplicate review decisions.
- Activate reviewed entries and keep unreviewed quarantined entries
blocked.
- Enable a completed connection and preserve the company and connection
scope in all updates.
- Show provider connection counts and open the provider setup page from
Browse.
- Let users edit existing connections or connect another account without
reusing an active OAuth connection.
- Update focused server and UI coverage for multiple connections and
action review.

## Verification

- Ran the focused Apps UI suite. All 116 tests passed in 11 files.
- Ran the focused server and CLI suite. All 276 tests passed in 3 files.
- Ran `pnpm --filter @paperclipai/db check:migrations`. The migration
safety check passed.
- Ran `pnpm -r typecheck`. All projects passed.
- Ran `pnpm build`. All projects built successfully.
- Ran `pnpm test:run`. It passed 3,735 tests and skipped 4 tests. One
worktree-safety assertion failed because the execution workspace reloads
its worktree marker. The same test passed with an isolated non-worktree
marker.
- Ran `pnpm check:token-gates`. It reports 12 existing violations in the
unchanged `PaperclipOrbit3D.tsx` file from the target branch.
- Started the six affected Playwright specifications. Chromium could not
start because the host does not provide `libatk-1.0.so.0`. The GitHub
e2e jobs will verify these specifications.
- GitHub Actions passed every final-head CI gate, including all three
e2e shards and the aggregate `e2e` and `verify` jobs.
- Greptile reviewed final commit `9af9200426` at 5/5 with zero review
threads.

## Risks

- Removing the name uniqueness index permits duplicate display names.
Stable connection IDs and UIDs remain unique within a company.
- The finish-app endpoint accepts the new review field as optional for
backward compatibility. When clients send it, the server requires a
complete decision for all quarantined actions.
- Multiple OAuth connections depend on the explicit new-connection route
flag. Focused tests cover active and draft connection reuse.
- The migration is ordered after migration 0210. Its `DROP INDEX IF
EXISTS` statement is safe to repeat.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex with the `gpt-5.6-sol` model assisted this change. The
agent used repository tools, code execution, test execution, and agentic
reasoning. The Codex runtime manages the context window.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-08-07 16:28:04 -05:00

174 lines
8.6 KiB
TypeScript

import { expect, test, type APIRequestContext, type Page } from "@playwright/test";
// Current Apps lifecycle coverage. The legacy Tools -> Applications CRUD table
// was retired; old links now redirect to /apps. Keep this harness focused on
// the user-visible Connections list plus app detail setup/advanced flows.
type SeedResult = {
companyId: string;
prefix: string;
};
const SCREENSHOT_DIR = "test-results";
const APP_PREFIX = `QA 10820 ${Date.now().toString(36)}`;
async function discoverCompany(request: APIRequestContext): Promise<SeedResult> {
const res = await request.post("/api/companies", {
data: { name: `applications lifecycle ${Date.now()}` },
});
expect(res.ok(), `create company failed ${res.status()}: ${await res.text()}`).toBe(true);
const company = await res.json();
const flags = await request.patch("/api/instance/settings/experimental", { data: { enableApps: true } });
expect(flags.ok(), `enable apps failed ${flags.status()}: ${await flags.text()}`).toBe(true);
return {
companyId: company.id,
prefix: company.issuePrefix ?? company.prefix ?? company.urlKey ?? "E2E",
};
}
async function createApplication(
request: APIRequestContext,
companyId: string,
body: { name: string; description?: string; type?: string },
): Promise<{ id: string; name: string }> {
const res = await request.post(`/api/companies/${companyId}/tools/applications`, {
data: { type: "mcp_http", ...body },
});
if (!res.ok()) throw new Error(`create app failed ${res.status()}: ${await res.text()}`);
return res.json();
}
async function createConnection(
request: APIRequestContext,
companyId: string,
data: { applicationName?: string; applicationId?: string; name: string; transport?: string; config?: object },
): Promise<{ id: string; applicationId: string; name: string }> {
const res = await request.post(`/api/companies/${companyId}/tools/connections`, {
data: {
transport: "mcp_remote",
config: { url: "https://fixture.example/mcp" },
enabled: true,
status: "active",
...data,
},
});
if (!res.ok()) throw new Error(`create connection failed ${res.status()}: ${await res.text()}`);
return res.json();
}
async function gotoApps(page: Page, prefix: string) {
await page.goto(`/${prefix}/apps/connections`);
await expect(page.getByRole("heading", { name: "Connections" })).toBeVisible({ timeout: 30_000 });
}
test.describe.serial("applications lifecycle", () => {
let seed: SeedResult;
test.beforeAll(async ({ request }) => {
seed = await discoverCompany(request);
});
test.afterAll(async ({ request }) => {
if (!seed?.companyId) return;
await request.delete(`/api/companies/${seed.companyId}`).catch(() => undefined);
});
test("Connections list surfaces connected and not-connected apps", async ({ page, request }) => {
const connectedName = `${APP_PREFIX}-connected`;
const notConnectedName = `${APP_PREFIX}-not-connected`;
const connected = await createConnection(request, seed.companyId, {
applicationName: connectedName,
name: connectedName,
});
const notConnected = await createApplication(request, seed.companyId, { name: notConnectedName });
await gotoApps(page, seed.prefix);
// The connected app starts with a "Healthy" pill and an "Open" action. A
// background health sweep then probes the connection endpoint. The test
// endpoint is an unreachable fixture URL, so the probe fails and the pill
// becomes "Needs attention" and the action becomes "Reconnect". Both are
// connected states that navigate to the same provider setup page. This test
// proves the connected-vs-not-connected split, not the transient health
// label, so accept either connected state instead of the racy exact label.
// The pill is derived from two react-query fetches (applications +
// connections), so keep the same generous window the rest of this spec uses.
const connectedRow = page.locator("tbody tr", { hasText: connectedName });
await expect(connectedRow).toBeVisible();
await expect(connectedRow.getByText(/^(Healthy|Needs attention)$/)).toBeVisible({ timeout: 30_000 });
await expect(connectedRow.getByRole("button", { name: /^(Open|Reconnect)$/ })).toBeVisible();
// The not-connected app has no connection, so the health sweep never touches
// it and its "Not connected" pill and "Connect" action stay deterministic.
const notConnectedRow = page.locator("tbody tr", { hasText: notConnectedName });
await expect(notConnectedRow).toBeVisible();
await expect(notConnectedRow.getByText("Not connected")).toBeVisible({ timeout: 30_000 });
await expect(notConnectedRow.getByRole("button", { name: "Connect" })).toBeVisible();
await page.screenshot({ path: `${SCREENSHOT_DIR}/applications-crud-current-list.png`, fullPage: true });
await connectedRow.getByRole("button", { name: /^(Open|Reconnect)$/ }).click();
await expect(page).toHaveURL(
new RegExp(`/${seed.prefix}/apps/app/${connected.applicationId}/setup$`),
{ timeout: 20_000 },
);
await gotoApps(page, seed.prefix);
await notConnectedRow.getByRole("button", { name: "Connect" }).click();
await expect(page).toHaveURL(
new RegExp(`/${seed.prefix}/apps/app/${notConnected.id}/setup$`),
{ timeout: 20_000 },
);
});
test("connected app detail supports pause, rename, and removal", async ({ page, request }) => {
const appName = `${APP_PREFIX}-detail-app`;
const renamed = `${APP_PREFIX}-renamed-app`;
const connection = await createConnection(request, seed.companyId, {
applicationName: appName,
name: appName,
});
await page.goto(`/${seed.prefix}/apps/${connection.id}/setup`);
await expect(page.getByRole("heading", { name: appName })).toBeVisible({ timeout: 30_000 });
await expect(page.getByRole("heading", { name: "Agents can use this app" })).toBeVisible();
await page.getByRole("switch", { name: "Pause this app" }).click();
await expect(page.getByRole("heading", { name: "This app is paused" })).toBeVisible({ timeout: 15_000 });
await page.getByRole("switch", { name: "Resume this app" }).click();
await expect(page.getByRole("heading", { name: "Agents can use this app" })).toBeVisible({ timeout: 15_000 });
await page.getByRole("button", { name: "Rename app" }).click();
await page.getByLabel("App name").fill(renamed);
await page.getByRole("button", { name: "Save", exact: true }).click();
await expect(page.getByRole("heading", { name: renamed })).toBeVisible({ timeout: 15_000 });
await page.screenshot({ path: `${SCREENSHOT_DIR}/applications-crud-current-detail.png`, fullPage: true });
await page.goto(`/${seed.prefix}/apps/${connection.id}/advanced`);
await expect(page.getByText("Danger zone")).toBeVisible({ timeout: 15_000 });
await page.getByRole("button", { name: "Remove app", exact: true }).click();
await expect(page.getByRole("button", { name: "Yes, remove it" })).toBeVisible();
await page.screenshot({ path: `${SCREENSHOT_DIR}/applications-crud-current-remove-connected.png`, fullPage: true });
await page.getByRole("button", { name: "Yes, remove it" }).click();
await expect(page).toHaveURL(new RegExp(`/${seed.prefix}/apps/connections$`), { timeout: 20_000 });
await expect(page.getByText("App removed").first()).toBeVisible({ timeout: 20_000 });
await expect(page.getByRole("heading", { name: "Connections" })).toBeVisible();
await expect(page.locator("tbody tr", { hasText: renamed })).toHaveCount(0);
});
test("not-connected app advanced page removes the application", async ({ page, request }) => {
const cleanAppName = `${APP_PREFIX}-clean-remove-app`;
const cleanApp = await createApplication(request, seed.companyId, { name: cleanAppName });
await page.goto(`/${seed.prefix}/apps/app/${cleanApp.id}/advanced`);
await expect(page.getByRole("heading", { name: cleanAppName })).toBeVisible({ timeout: 30_000 });
await expect(page.getByText("Danger zone")).toBeVisible();
await page.getByRole("button", { name: "Remove app", exact: true }).click();
await page.screenshot({ path: `${SCREENSHOT_DIR}/applications-crud-current-remove-not-connected.png`, fullPage: true });
await page.getByRole("button", { name: "Yes, remove it" }).click();
await expect(page).toHaveURL(new RegExp(`/${seed.prefix}/apps/connections$`), { timeout: 20_000 });
await expect(page.getByText("App removed").first()).toBeVisible({ timeout: 20_000 });
await expect(page.getByRole("heading", { name: "Connections" })).toBeVisible();
await expect(page.locator("tbody tr", { hasText: cleanAppName })).toHaveCount(0);
});
});