mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - App connections need both direct providers and managed provider hubs. > - The grant layer now defines safe credential ownership. > - Composio needs parent and child connection lifecycle rules, and Gmail needs governed setup. > - This pull request adds both connector families on the grant foundation. > - The benefit is broader app access without weakening credential isolation. ## Linked Issues or Issue Description Refs #11965 This is stack 4 of 11. It depends on stack 3 and replaces another reviewable part of #11965. ## What Changed - Add Composio parent and child connection support. - Add Gmail connection setup and governance. - Preserve credential paths and remove duplicate binding declarations. - Cascade Composio pause and restore actions to child connections. ## Verification - `pnpm --filter @paperclipai/server typecheck` - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/tool-access-service.test.ts` - Result: 164 tests passed. - `pnpm build` ## Risks - Parent lifecycle changes can affect every Composio child. - The service restores only children whose provider accounts remain active. - Credential binding paths are normalized before secret resolution. > I checked `ROADMAP.md`. This stack continues the existing app connection work from #11965 and does not duplicate another planned item. ## Model Used OpenAI Codex, GPT-5. The runtime model ID and context window were not exposed. The model used reasoning, tool use, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
23 lines
1.0 KiB
Bash
23 lines
1.0 KiB
Bash
DATABASE_URL=postgres://paperclip:paperclip@localhost:5432/paperclip
|
|
PORT=3100
|
|
SERVE_UI=false
|
|
BETTER_AUTH_SECRET=paperclip-dev-secret
|
|
PAPERCLIP_TOOL_ACTION_SIGNING_SECRET=paperclip-dev-tool-action-signing-secret-change-me
|
|
|
|
# Optional Paperclip ID Gmail OAuth broker. Enroll the instance first; keep both
|
|
# private keys in the deployment secret manager. HTTP base URLs must be loopback.
|
|
# PAPERCLIP_ID_CONNECTOR_BASE_URL=http://localhost:3000
|
|
# PAPERCLIP_ID_CONNECTOR_ENVIRONMENT=development
|
|
# PAPERCLIP_ID_CONNECTOR_INSTANCE_ID=inst_example
|
|
# PAPERCLIP_ID_CONNECTOR_SIGN_PRIVATE_KEY=
|
|
# PAPERCLIP_ID_CONNECTOR_SEAL_PRIVATE_KEY=
|
|
|
|
# Process-wide protection for expensive full-tree workspace Git scans.
|
|
# PAPERCLIP_WORKSPACE_GIT_SCAN_CONCURRENCY=2
|
|
# PAPERCLIP_WORKSPACE_GIT_SCAN_QUEUE_CAPACITY=32
|
|
# PAPERCLIP_WORKSPACE_GIT_SCAN_TIMEOUT_MS=8000
|
|
# PAPERCLIP_WORKSPACE_GIT_SCAN_CACHE_TTL_MS=10000
|
|
|
|
# Discord webhook for daily merge digest (scripts/discord-daily-digest.sh)
|
|
# DISCORD_WEBHOOK_URL=https://discord.com/api/webhooks/...
|