Files
PaperClipAI/server/src/services/source-trust.ts
T
DottaandPaperclip dbebf30c89 Add low-trust review containment (#7530)
## Thinking Path

> - Paperclip is a control plane for AI-agent companies, so execution
policy and trust boundaries are part of the product's safety contract.
> - Low-trust review work needs narrower authority than normal
same-company agents because hostile PRs, comments, attachments, and
generated output can carry prompt-injection payloads.
> - The current V1 shape gives trusted workers broad company context,
which is useful for normal execution but too permissive for a reviewer
assigned to hostile content.
> - This branch adds a `low_trust_review` preset, source-trust tagging,
route-level containment, and quarantine handling so low-trust output
does not automatically flow into higher-trust wake context.
> - The branch has been rebased onto current `origin/master`, and the
low-trust migration was renumbered to `0097_low_trust_source_trust.sql`
to avoid collisions with existing `0091` through `0096` migrations.
> - Greptile feedback was addressed by tightening low-trust detection,
preserving project-level trust policy checks, fixing issue-kind
promotion lookup, removing duplicate post-lease isolation assertion,
documenting fail-closed source-trust behavior, bounding ancestry checks,
enforcing runtime issue context for CEOs, awaiting accepted-plan monitor
authorization, and making low-trust issue source-trust tagging atomic.
> - The benefit is a first production slice of deny-by-default review
containment with regression coverage for the main control-plane pivot
surfaces.

Fixes #7531.

## What Changed

- Added shared trust-policy types and validators, plus
database/source-trust fields for issues, comments, documents, and work
products.
- Implemented server enforcement for low-trust issue scope, agent
self-view redaction, secret/plugin/runtime denial paths, promotion
checks, and quarantined continuation/wake context.
- Added focused low-trust regression tests for resolver behavior, source
trust, route authorization, heartbeat preflight ordering, runtime
containment, and quarantine redaction.
- Added board UI affordances for selecting/reviewing the low-trust
preset and surfacing source-trust badges in relevant issue views.
- Added `doc/LOW-TRUST-PRESETS.md`, updated
`doc/SPEC-implementation.md`, and committed the low-trust review
contract plan under `doc/plans/`.
- Rebasing note: the original `0097_low_trust_source_trust.sql`
migration was renamed to `0097_low_trust_source_trust.sql`; the SQL uses
`ADD COLUMN IF NOT EXISTS` so users who already applied the old-numbered
migration are not broken by the renumbered migration.

## Verification

- Rebased branch onto current `origin/master` and force-pushed with
lease to `origin/PAP-10211-low-trust-agent` at head `2719f31e3`.
- Confirmed the PR diff does not include `pnpm-lock.yaml` or
`.github/workflows` changes.
- Resolved upstream UI/comment conflicts by preserving deleted-comment
tombstone behavior and low-trust source-trust badges/metadata.
- Renumbered the low-trust source-trust migration to
`0097_low_trust_source_trust.sql`; the SQL uses `ADD COLUMN IF NOT
EXISTS` so users who already applied an old-numbered copy are not
broken.
- `pnpm exec vitest run ui/src/lib/issue-chat-messages.test.ts
server/src/__tests__/heartbeat-workspace-session.test.ts`
- `pnpm exec vitest run server/src/__tests__/source-trust.test.ts
server/src/__tests__/workspace-runtime-service-authz.test.ts
ui/src/lib/trust-policy-ui.test.ts
ui/src/components/TrustPresetSection.test.tsx`
- `pnpm run typecheck:build-gaps`
- `git diff --check`
- GitHub checks pass on head `2719f31e3`: build, typecheck/release
registry, general tests, serialized server suites, e2e, canary, verify,
policy/review, Socket, and Snyk.
- Greptile Review passes with Confidence Score 5/5 and zero unresolved
Greptile review threads.
- No design screenshots/images were added because the task explicitly
says not to add them unless they are specifically part of the work.

## Risks

- Medium risk: this touches shared trust-policy contracts, server
authorization paths, heartbeat context generation, migration metadata,
and UI preset controls.
- Low-trust containment is intentionally deny-by-default; legitimate
future review workflows may need explicit allowlisted exceptions.
- Plugin/runtime/security surfaces are broad, so regression tests cover
the current known routes but future integrations must route through the
same containment layer.
- The PR is ready for review; GitHub checks are green and Greptile is
5/5.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, GPT-5 coding agent, tool-enabled shell and GitHub CLI
workflow.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] UI changes are covered by focused tests; no screenshots were added
per task instruction not to add design images unless specifically
required
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-06-05 16:48:02 -05:00

174 lines
5.3 KiB
TypeScript

import { and, eq } from "drizzle-orm";
import type { Db } from "@paperclipai/db";
import { agents, heartbeatRuns, projects } from "@paperclipai/db";
import {
LOW_TRUST_REVIEW_PRESET,
type SourceTrustMetadata,
} from "@paperclipai/shared";
import { forbidden } from "../errors.js";
import { readObject } from "../lib/objects.js";
import { resolveCoreTrustPreset } from "./trust-preset-resolver.js";
export const LOW_TRUST_QUARANTINED_BODY =
"[Quarantined low-trust output omitted from higher-trust agent context. A trusted reviewer can inspect and promote a sanitized artifact.]";
export type SourceTrustActor = {
actorType: "agent" | "user";
actorId: string;
agentId: string | null;
runId: string | null;
};
export type SourceTrustIssueContext = {
id: string;
companyId: string;
projectId?: string | null;
executionPolicy?: unknown;
};
export function isLowTrustQuarantined(sourceTrust: SourceTrustMetadata | null | undefined): boolean {
return sourceTrust?.preset === LOW_TRUST_REVIEW_PRESET && sourceTrust.disposition === "quarantined";
}
export function redactQuarantinedBodyForHigherTrust<T extends { body?: string | null; sourceTrust?: SourceTrustMetadata | null }>(
value: T,
): T {
if (!isLowTrustQuarantined(value.sourceTrust)) return value;
return {
...value,
body: LOW_TRUST_QUARANTINED_BODY,
} as T;
}
export function sanitizeQuarantinedCommentForHigherTrust<
T extends {
body: string;
presentation?: unknown;
metadata?: unknown;
sourceTrust?: SourceTrustMetadata | null;
},
>(comment: T): T {
if (!isLowTrustQuarantined(comment.sourceTrust)) return comment;
return {
...comment,
body: LOW_TRUST_QUARANTINED_BODY,
presentation: null,
metadata: null,
};
}
export function buildLowTrustSourceTrust(input: {
issueId: string;
runId?: string | null;
agentId?: string | null;
}): SourceTrustMetadata {
return {
preset: LOW_TRUST_REVIEW_PRESET,
disposition: "quarantined",
sourceIssueId: input.issueId,
sourceRunId: input.runId ?? null,
sourceAgentId: input.agentId ?? null,
};
}
export function buildPromotedSourceTrust(input: {
sourceIssueId: string;
sourceArtifactKind: "comment" | "document" | "work_product" | "issue";
sourceArtifactId: string;
promotedByActorType: "agent" | "user" | "system";
promotedByActorId: string;
promotedAt?: Date;
}): SourceTrustMetadata {
return {
preset: LOW_TRUST_REVIEW_PRESET,
disposition: "promoted",
sourceIssueId: input.sourceIssueId,
promotedFrom: {
artifactKind: input.sourceArtifactKind,
artifactId: input.sourceArtifactId,
issueId: input.sourceIssueId,
},
promotedByActorType: input.promotedByActorType,
promotedByActorId: input.promotedByActorId,
promotedAt: (input.promotedAt ?? new Date()).toISOString(),
};
}
export async function resolveActorSourceTrustForIssue(input: {
db: Db;
issue: SourceTrustIssueContext;
actor: SourceTrustActor;
}): Promise<SourceTrustMetadata | null> {
if (input.actor.actorType !== "agent" || !input.actor.agentId) return null;
const [agent, project, run] = await Promise.all([
input.db
.select({
companyId: agents.companyId,
permissions: agents.permissions,
})
.from(agents)
.where(and(eq(agents.id, input.actor.agentId), eq(agents.companyId, input.issue.companyId)))
.then((rows) => rows[0] ?? null),
input.issue.projectId
? input.db
.select({
companyId: projects.companyId,
executionWorkspacePolicy: projects.executionWorkspacePolicy,
})
.from(projects)
.where(and(eq(projects.id, input.issue.projectId), eq(projects.companyId, input.issue.companyId)))
.then((rows) => rows[0] ?? null)
: Promise.resolve(null),
input.actor.runId
? input.db
.select({
companyId: heartbeatRuns.companyId,
agentId: heartbeatRuns.agentId,
contextSnapshot: heartbeatRuns.contextSnapshot,
})
.from(heartbeatRuns)
.where(and(eq(heartbeatRuns.id, input.actor.runId), eq(heartbeatRuns.companyId, input.issue.companyId)))
.then((rows) => rows[0] ?? null)
: Promise.resolve(null),
]);
if (input.actor.runId && (!run || run.agentId !== input.actor.agentId)) {
// Fail closed: an unknown or mismatched run cannot prove higher trust, so tag the write as quarantined.
return buildLowTrustSourceTrust({
issueId: input.issue.id,
runId: input.actor.runId,
agentId: input.actor.agentId,
});
}
const runContext = readObject(run?.contextSnapshot);
const runExecutionPolicy = readObject(runContext?.executionPolicy);
const resolution = resolveCoreTrustPreset({
companyId: input.issue.companyId,
agent,
project,
issue: {
companyId: input.issue.companyId,
executionPolicy: input.issue.executionPolicy,
},
run: run
? {
companyId: run.companyId,
executionPolicy: runExecutionPolicy,
}
: null,
});
if (resolution.kind === "denied") {
throw forbidden(resolution.detail);
}
if (resolution.kind !== "low_trust_review") return null;
return buildLowTrustSourceTrust({
issueId: input.issue.id,
runId: input.actor.runId,
agentId: input.actor.agentId,
});
}