mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-10 20:50:08 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Managed worktree services run isolated Paperclip instances with cloned databases. > - A reachable service was reported as ready even when its database, runtime identity, or login path was not usable. > - The first candidate added verified database seeding and managed repair in #11665. > - This pull request consolidates that candidate with signed login handoff and a complete readiness contract. > - Post-QA fixes close five defects in repair identity, repair responses, UI retry, seed journal handling, and seed-source trust. > - The benefit is a workspace that either opens safely or reports one accurate recovery action. ## Linked Issues or Issue Description No public GitHub issue exists for this work, so the problem is described here. **What happened** Managed workspace URLs could return HTTP 200 and report ready while login failed. QA also found cases where repair used the wrong instance identity, returned a generic error, left the UI stuck, rejected a safe journal lag, or trusted a mutable workspace manifest. **Expected behavior** Opening a ready workspace signs the board user in to the correct isolated instance. Provisioning and repair use a registered source and report a structured recovery state. **Actual behavior** Entry depended on a password copied into the clone. Several failure paths could publish stale readiness, hide the repair precondition, or trust state that the workspace could modify. **Additional context** This pull request includes the commits first published in #11665. That pull request keeps the original base head for review history. This consolidated pull request is the merge candidate. Related open readiness work includes #11575 and #11621. ## What Changed - Adds a short-lived, signed, single-use login ticket. It binds the user, workspace, instance, and runtime origin. - Exchanges the ticket through Better Auth. It creates the session and cookie through the supported adapter path. - Adds protected workspace readiness fields for the database, clone data, login handoff, seed phase, and runtime identity. - Fails readiness closed when the guest has no company or execution-workspace binding. - Binds ticket issuance to the exact cloned user and active company membership selected for the handoff. - Verifies every current active board identity through the exact-user handoff before publication or reuse. - Gates managed runtime publication on the readiness contract and the recorded worktree instance identity. - Refreshes runtime work products from the live runtime row after a port change. - Adds one workspace access card with ready, degraded, repairing, and failed states. - Uses the runtime response identity for repair. It returns structured repair precondition errors. - Lets a valid source journal lag converge during provisioning. - Binds seed and repair manifests to a source registered outside the agent-writable worktree. - Clears recovered UI errors so a successful retry can open the workspace. - Makes runtime tests register canonical sources and avoid ports owned by live host listeners. - Keeps Vitest on source suites when compiled `dist` trees exist. - Isolates CLI and adapter tests from ambient AWS and runtime API environment variables. - Preserves a 404 response for cross-company workspace ID lookups before runtime authorization. - Makes concurrent single-flight coverage independent of path-canonicalization scheduling order. ## Verification The following checks passed on the integrated head: ```sh pnpm -r typecheck pnpm build pnpm check:token-gates pnpm --filter @paperclipai/db check:migrations ``` - The server source lane passed 420 files and 4,953 tests. Five tests were skipped. - The CLI lane passed 57 files and 385 tests. - The database lane passed 26 files and 97 tests. - The shared package passed 58 files and 506 tests. - The adapter utility lane passed 640 tests. Four tests were skipped. - The Claude adapter passed 220 tests. One test was skipped. - The Codex adapter passed 323 tests. - The OpenClaw adapter passed 13 tests. - The OpenCode adapter passed 42 tests. - The plugin SDK passed 45 tests. - The workspace runtime suite passed 124 tests. - The caller-scoped readiness and handoff suite passed 52 tests. - The workspace provisioning shell suite passed 7 tests. - The runtime exposure suite passed 17 tests while live host mappings occupied fixed test ports. - `git diff --check` passed and the worktree is clean. The serialized route lane will run in GitHub CI with its normal shards. No deployment or active-workspace migration was performed. ## Risks - This is a medium-risk authentication and runtime-readiness change. - The login ticket uses exact origin, workspace, instance, and user binding. It has a short expiry and a one-time nonce. - Runtime publication is stricter. A real readiness, identity, per-user handoff, or control-plane database disagreement now blocks publication. - This pull request supersedes #11665 as the merge candidate. Close #11665 after this pull request merges. - No new database migration is included. The lockfile and workflow files are unchanged. - Deployment and active-workspace migration are intentionally outside this pull request. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used Claude Opus 5 (`claude-opus-5[1m]`), 1M context, extended thinking, tool use, and code execution produced the main candidate. OpenAI GPT-5 (`gpt-5`) through Codex, with agentic reasoning, tool use, and code execution, integrated the post-QA fixes and hardened the test gates. The Codex context-window size was not exposed. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
339 lines
11 KiB
TypeScript
339 lines
11 KiB
TypeScript
import { Command } from "commander";
|
|
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
|
import type { Agent, CompanySecret } from "@paperclipai/shared";
|
|
import type { PaperclipConfig } from "../config/schema.js";
|
|
import { secretsCheck } from "../checks/secrets-check.js";
|
|
import {
|
|
buildInlineMigrationSecretName,
|
|
buildMigratedAgentEnv,
|
|
collectInlineSecretMigrationCandidates,
|
|
parseSecretsInclude,
|
|
registerSecretCommands,
|
|
toPlainEnvValue,
|
|
} from "../commands/client/secrets.js";
|
|
|
|
function agent(partial: Partial<Agent>): Agent {
|
|
return {
|
|
id: "agent-12345678",
|
|
companyId: "company-1",
|
|
name: "Coder",
|
|
urlKey: "coder",
|
|
role: "engineer",
|
|
title: null,
|
|
icon: null,
|
|
status: "idle",
|
|
reportsTo: null,
|
|
capabilities: null,
|
|
adapterType: "codex_local",
|
|
adapterConfig: {},
|
|
runtimeConfig: {},
|
|
budgetMonthlyCents: 0,
|
|
spentMonthlyCents: 0,
|
|
pauseReason: null,
|
|
pausedAt: null,
|
|
permissions: {
|
|
canCreateAgents: false,
|
|
},
|
|
lastHeartbeatAt: null,
|
|
metadata: null,
|
|
createdAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
updatedAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
...partial,
|
|
};
|
|
}
|
|
|
|
function secret(partial: Partial<CompanySecret>): CompanySecret {
|
|
return {
|
|
id: "secret-1",
|
|
companyId: "company-1",
|
|
scope: "company",
|
|
ownerUserId: null,
|
|
userSecretDefinitionId: null,
|
|
key: "agent_agent-12_anthropic_api_key",
|
|
name: "agent_agent-12_anthropic_api_key",
|
|
provider: "local_encrypted",
|
|
status: "active",
|
|
managedMode: "paperclip_managed",
|
|
externalRef: null,
|
|
providerConfigId: null,
|
|
providerMetadata: null,
|
|
latestVersion: 1,
|
|
description: null,
|
|
lastResolvedAt: null,
|
|
lastRotatedAt: null,
|
|
deletedAt: null,
|
|
createdByAgentId: null,
|
|
createdByUserId: null,
|
|
createdAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
updatedAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
...partial,
|
|
};
|
|
}
|
|
|
|
function configWithSecretsProvider(provider: PaperclipConfig["secrets"]["provider"]): PaperclipConfig {
|
|
return {
|
|
$meta: {
|
|
version: 1,
|
|
updatedAt: "2026-05-02T00:00:00.000Z",
|
|
source: "configure",
|
|
},
|
|
database: {
|
|
mode: "embedded-postgres",
|
|
embeddedPostgresDataDir: "/tmp/paperclip/db",
|
|
embeddedPostgresPort: 55432,
|
|
backup: {
|
|
enabled: true,
|
|
intervalMinutes: 60,
|
|
retentionDays: 30,
|
|
dir: "/tmp/paperclip/backups",
|
|
},
|
|
},
|
|
logging: {
|
|
mode: "file",
|
|
logDir: "/tmp/paperclip/logs",
|
|
},
|
|
server: {
|
|
deploymentMode: "local_trusted",
|
|
exposure: "private",
|
|
host: "127.0.0.1",
|
|
port: 3100,
|
|
allowedHostnames: [],
|
|
serveUi: true,
|
|
},
|
|
auth: {
|
|
baseUrlMode: "auto",
|
|
disableSignUp: false,
|
|
},
|
|
telemetry: {
|
|
enabled: true,
|
|
},
|
|
storage: {
|
|
provider: "local_disk",
|
|
localDisk: {
|
|
baseDir: "/tmp/paperclip/storage",
|
|
},
|
|
s3: {
|
|
bucket: "paperclip",
|
|
region: "us-east-1",
|
|
prefix: "",
|
|
forcePathStyle: false,
|
|
},
|
|
},
|
|
secrets: {
|
|
provider,
|
|
strictMode: true,
|
|
localEncrypted: {
|
|
keyFilePath: "/tmp/paperclip/secrets/master.key",
|
|
},
|
|
},
|
|
};
|
|
}
|
|
|
|
describe("secrets CLI helpers", () => {
|
|
const originalEnv = { ...process.env };
|
|
|
|
beforeEach(() => {
|
|
process.env = { ...originalEnv };
|
|
delete process.env.PAPERCLIP_SECRETS_AWS_REGION;
|
|
delete process.env.AWS_REGION;
|
|
delete process.env.AWS_DEFAULT_REGION;
|
|
delete process.env.PAPERCLIP_SECRETS_AWS_DEPLOYMENT_ID;
|
|
delete process.env.PAPERCLIP_SECRETS_AWS_KMS_KEY_ID;
|
|
delete process.env.AWS_ACCESS_KEY_ID;
|
|
delete process.env.AWS_SECRET_ACCESS_KEY;
|
|
delete process.env.AWS_SESSION_TOKEN;
|
|
});
|
|
|
|
afterEach(() => {
|
|
process.env = { ...originalEnv };
|
|
});
|
|
|
|
it("parses declaration include filters", () => {
|
|
expect(parseSecretsInclude("agents,projects,tasks")).toEqual({
|
|
company: false,
|
|
agents: true,
|
|
projects: true,
|
|
issues: true,
|
|
skills: false,
|
|
});
|
|
});
|
|
|
|
it("detects inline sensitive env values that need migration", () => {
|
|
const rows = collectInlineSecretMigrationCandidates(
|
|
[
|
|
agent({
|
|
id: "agent-12345678",
|
|
adapterConfig: {
|
|
env: {
|
|
ANTHROPIC_API_KEY: "sk-ant-test",
|
|
GH_TOKEN: {
|
|
type: "plain",
|
|
value: "ghp-test",
|
|
},
|
|
PATH: {
|
|
type: "plain",
|
|
value: "/usr/bin",
|
|
},
|
|
OPENAI_API_KEY: {
|
|
type: "secret_ref",
|
|
secretId: "secret-existing",
|
|
},
|
|
},
|
|
},
|
|
}),
|
|
],
|
|
[
|
|
secret({
|
|
id: "secret-gh-token",
|
|
name: buildInlineMigrationSecretName("agent-12345678", "GH_TOKEN"),
|
|
}),
|
|
],
|
|
);
|
|
|
|
expect(rows).toEqual([
|
|
{
|
|
agentId: "agent-12345678",
|
|
agentName: "Coder",
|
|
envKey: "ANTHROPIC_API_KEY",
|
|
secretName: "agent_agent-12_anthropic_api_key",
|
|
existingSecretId: null,
|
|
},
|
|
{
|
|
agentId: "agent-12345678",
|
|
agentName: "Coder",
|
|
envKey: "GH_TOKEN",
|
|
secretName: "agent_agent-12_gh_token",
|
|
existingSecretId: "secret-gh-token",
|
|
},
|
|
]);
|
|
});
|
|
|
|
it("builds migrated env bindings without preserving secret values", () => {
|
|
const next = buildMigratedAgentEnv(
|
|
{
|
|
ANTHROPIC_API_KEY: "sk-ant-test",
|
|
NODE_ENV: {
|
|
type: "plain",
|
|
value: "development",
|
|
},
|
|
},
|
|
new Map([["ANTHROPIC_API_KEY", "secret-1"]]),
|
|
);
|
|
|
|
expect(next).toEqual({
|
|
ANTHROPIC_API_KEY: {
|
|
type: "secret_ref",
|
|
secretId: "secret-1",
|
|
version: "latest",
|
|
},
|
|
NODE_ENV: {
|
|
type: "plain",
|
|
value: "development",
|
|
},
|
|
});
|
|
expect(JSON.stringify(next)).not.toContain("sk-ant-test");
|
|
});
|
|
|
|
it("reads only explicit plain env values", () => {
|
|
expect(toPlainEnvValue("plain-value")).toBe("plain-value");
|
|
expect(toPlainEnvValue({ type: "plain", value: "wrapped" })).toBe("wrapped");
|
|
expect(toPlainEnvValue({ type: "secret_ref", secretId: "secret-1" })).toBeNull();
|
|
});
|
|
|
|
it("reports the AWS bootstrap config required by doctor", () => {
|
|
const result = secretsCheck(configWithSecretsProvider("aws_secrets_manager"));
|
|
|
|
expect(result.status).toBe("fail");
|
|
expect(result.message).toContain("PAPERCLIP_SECRETS_AWS_DEPLOYMENT_ID");
|
|
expect(result.repairHint).toContain("AWS SDK default credential chain");
|
|
expect(result.repairHint).toContain("Do not store AWS root credentials");
|
|
});
|
|
|
|
it("passes AWS doctor checks when non-secret provider config is present", () => {
|
|
process.env.PAPERCLIP_SECRETS_AWS_REGION = "us-east-1";
|
|
process.env.PAPERCLIP_SECRETS_AWS_DEPLOYMENT_ID = "prod-us-1";
|
|
process.env.PAPERCLIP_SECRETS_AWS_KMS_KEY_ID =
|
|
"arn:aws:kms:us-east-1:123456789012:key/test";
|
|
process.env.AWS_PROFILE = "paperclip-prod";
|
|
|
|
const result = secretsCheck(configWithSecretsProvider("aws_secrets_manager"));
|
|
|
|
expect(result.status).toBe("pass");
|
|
expect(result.message).toContain("prod-us-1");
|
|
expect(result.message).toContain("AWS_PROFILE/shared config");
|
|
});
|
|
});
|
|
|
|
describe("secrets API parity commands", () => {
|
|
beforeEach(() => {
|
|
vi.restoreAllMocks();
|
|
delete process.env.PAPERCLIP_API_KEY;
|
|
delete process.env.PAPERCLIP_API_URL;
|
|
vi.spyOn(console, "log").mockImplementation(() => {});
|
|
});
|
|
|
|
afterEach(() => {
|
|
vi.restoreAllMocks();
|
|
});
|
|
|
|
it("wraps provider config and remote import endpoints", async () => {
|
|
const fetchMock = vi.fn().mockImplementation(() => Promise.resolve(jsonResponse()));
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
await runSecretCommand(["secrets", "provider-configs", "--company-id", "company-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:create", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "provider-config:discovery-preview", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "provider-config:get", "config-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:update", "config-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "provider-config:default", "config-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:health", "config-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:delete", "config-1"]);
|
|
await runSecretCommand(["secrets", "remote-import:preview", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "remote-import", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
|
|
expect(fetchMock.mock.calls.map((call) => [call[1]?.method ?? "GET", call[0]])).toEqual([
|
|
["GET", "http://localhost:3100/api/companies/company-1/secret-provider-configs"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secret-provider-configs"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secret-provider-configs/discovery/preview"],
|
|
["GET", "http://localhost:3100/api/secret-provider-configs/config-1"],
|
|
["PATCH", "http://localhost:3100/api/secret-provider-configs/config-1"],
|
|
["POST", "http://localhost:3100/api/secret-provider-configs/config-1/default"],
|
|
["POST", "http://localhost:3100/api/secret-provider-configs/config-1/health"],
|
|
["DELETE", "http://localhost:3100/api/secret-provider-configs/config-1"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secrets/remote-import/preview"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secrets/remote-import"],
|
|
]);
|
|
});
|
|
|
|
it("wraps secret metadata, rotation, usage, access event, and delete endpoints", async () => {
|
|
const fetchMock = vi.fn().mockImplementation(() => Promise.resolve(jsonResponse()));
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
await runSecretCommand(["secrets", "update", "secret-1", "--payload-json", "{\"description\":\"updated\"}"]);
|
|
await runSecretCommand(["secrets", "rotate", "secret-1", "--value", "new-value"]);
|
|
await runSecretCommand(["secrets", "usage", "secret-1"]);
|
|
await runSecretCommand(["secrets", "access-events", "secret-1"]);
|
|
await runSecretCommand(["secrets", "delete", "secret-1", "--yes", "--confirm", "secret-1"]);
|
|
|
|
expect(fetchMock.mock.calls.map((call) => [call[1]?.method ?? "GET", call[0]])).toEqual([
|
|
["PATCH", "http://localhost:3100/api/secrets/secret-1"],
|
|
["POST", "http://localhost:3100/api/secrets/secret-1/rotate"],
|
|
["GET", "http://localhost:3100/api/secrets/secret-1/usage"],
|
|
["GET", "http://localhost:3100/api/secrets/secret-1/access-events"],
|
|
["DELETE", "http://localhost:3100/api/secrets/secret-1"],
|
|
]);
|
|
});
|
|
});
|
|
|
|
async function runSecretCommand(args: string[]): Promise<void> {
|
|
const program = new Command();
|
|
program.exitOverride();
|
|
program.configureOutput({ writeOut: () => {}, writeErr: () => {} });
|
|
registerSecretCommands(program);
|
|
await program.parseAsync([...args, "--api-base", "http://localhost:3100", "--api-key", "board-token"], { from: "user" });
|
|
}
|
|
|
|
function jsonResponse(body: unknown = { ok: true }, init: ResponseInit = { status: 200 }): Response {
|
|
return new Response(JSON.stringify(body), init);
|
|
}
|