mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Connection intents need secure provider implementations to complete setup. > - Some providers use managed OAuth or external credential brokers. > - Those tokens must stay out of durable Paperclip state and fail closed when refresh fails. > - This pull request adds managed connector backends and the required storage contract. > - The benefit is safer provider setup with governed credential lifecycles. ## Linked Issues or Issue Description Refs #11965 This is stack 8 of 11. It depends on stack 7 and replaces another reviewable part of #11965. ## What Changed - Add managed Google Workspace and external connector backends. - Add Vercel Connect support without storing provider bearer tokens. - Add replay-safe migration 0232 and its generated snapshot. - Fail closed and clear stale token bindings when organization OAuth refresh needs reauthorization. ## Verification - `pnpm --filter @paperclipai/server typecheck` - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/tool-access-service.test.ts` - Result: 194 tests passed. - `pnpm --filter @paperclipai/db check:migrations` - `pnpm build` - `pnpm exec vitest run --project @paperclipai/server server/src/services/remote-url-credentials.test.ts` (5 passed, including URL userinfo vault extraction) ## Risks - Broker metadata errors can block provider setup. - OAuth refresh failure disables the shared organization connection until reauthorization. - Migration 0232 is generated, ordered after 0231, and safe to replay. > I checked `ROADMAP.md`. This stack continues the existing app connection work from #11965 and does not duplicate another planned item. ## Model Used OpenAI Codex, GPT-5. The runtime model ID and context window were not exposed. The model used reasoning, tool use, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have linked the public source pull request with `Refs #` - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge
76 lines
1.3 KiB
Plaintext
76 lines
1.3 KiB
Plaintext
node_modules
|
|
node_modules/
|
|
**/node_modules
|
|
**/node_modules/
|
|
dist/
|
|
ui/storybook-static/
|
|
.env
|
|
*.tsbuildinfo
|
|
drizzle/meta/
|
|
.vite/
|
|
coverage/
|
|
.DS_Store
|
|
._*
|
|
.AppleDouble
|
|
.LSOverride
|
|
data/
|
|
.paperclip/
|
|
.pnpm-store/
|
|
tmp-*
|
|
cli/tmp/
|
|
|
|
# Scratch/seed scripts (but not scripts/ dir)
|
|
check-*.mjs
|
|
!.github/scripts/check-*.mjs
|
|
!.github/scripts/tests/check-*.mjs
|
|
!scripts/check-*.mjs
|
|
new-agent*.json
|
|
newcompany.json
|
|
seed-*.mjs
|
|
server/check-*.mjs
|
|
server/seed-*.mjs
|
|
packages/db/seed-*.mjs
|
|
|
|
# npm publish build artifacts
|
|
cli/package.dev.json
|
|
|
|
# Build artifacts in src directories
|
|
server/src/**/*.js
|
|
server/src/**/*.js.map
|
|
server/src/**/*.d.ts
|
|
server/src/**/*.d.ts.map
|
|
tmp/
|
|
feedback-export-*
|
|
diagnostics/
|
|
|
|
# Editor / tool temp files
|
|
*.tmp
|
|
.vscode/
|
|
.claude/settings.local.json
|
|
.paperclip-local/
|
|
.paperclip-runtime/
|
|
/.idea/
|
|
/.agents/
|
|
|
|
# Doc maintenance cursor
|
|
.doc-review-cursor
|
|
|
|
# Playwright
|
|
tests/e2e/test-results/
|
|
tests/e2e/playwright-report/
|
|
tests/release-smoke/test-results/
|
|
tests/release-smoke/playwright-report/
|
|
test-results/issue-detail-perf/
|
|
tests/storybook-visual/.cache/
|
|
tests/storybook-visual/.snapshots/
|
|
tests/storybook-visual/baseline-review/
|
|
tests/storybook-visual/test-results/
|
|
tests/storybook-visual/playwright-report/
|
|
.superset/
|
|
.superpowers/
|
|
.claude/worktrees/
|
|
.herenow
|
|
.vercel/
|
|
.env.local
|
|
test-results/
|