mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-09 06:15:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Issues use `in_review` to request a final decision from an authorized writer > - The server rejected an assignee agent that tried to close its own review, even when the issue had no independent-review rule > - This rejection stopped the default agent workflow and did not represent the configured execution-stage rules > - Paperclip needs an open default and explicit issue-level constraints for teams that require an independent or human verdict > - This pull request removes the unconditional rejection and adds `anyone`, `not_creator`, and `human_only` review policies > - The benefit is a working default path with opt-in, authenticated verdict controls ## Linked Issues or Issue Description Refs #10635, #4429, and #10671. The related public work covers execution-stage independence, self-approval fallback behavior, and durable review paths. This change is distinct. It controls who can resolve an issue review verdict. It keeps configured execution stages active. ## What Changed - Added a nullable `review_policy` issue column. Null has the same meaning as `anyone`. The migration does not backfill existing issues. - Added shared create, update, response, and compact issue contracts for `anyone`, `not_creator`, and `human_only`. - Removed the unconditional agent self-approval rejection for `in_review` issues. - Added one reusable verdict-actor check for terminal status changes and pending interaction accept or reject actions. - Used the authenticated principal type for `human_only`. Agent keys and run tokens remain agent principals. - Used the latest transition into `in_review` to identify the requester for `not_creator`. - Added actionable 403 responses that name the policy, the allowed actor, and the next step. - Kept the configured execution-stage transition and signoff behavior. - Added focused contract, helper, status-route, interaction-route, and execution-stage regression tests. - Updated the implementation specification for the new issue field. ## Verification - `pnpm exec vitest run packages/shared/src/validators/issue.test.ts server/src/__tests__/issue-review-policy.test.ts server/src/__tests__/issue-stalled-review-decision-routes.test.ts --reporter=dot` passed: 42 tests. - `pnpm --filter @paperclipai/shared typecheck` passed. - `pnpm --filter @paperclipai/db typecheck` passed, including migration numbering and safety checks. - `pnpm --filter @paperclipai/server typecheck` passed. - `pnpm run typecheck:build-gaps` passed across server, CLI, plugin SDK/examples, plugin wiki, and UI. - `git diff --check origin/master...HEAD` passed. - SecurityEngineer review approved the authenticated-principal checks and accepted policy-relaxation tradeoff with no required changes. - Greptile reviewed the latest head at 5/5 with zero inline comments or follow-ups. - The latest-head GitHub rollup passed build, typecheck, server/workspace tests, serialized suites, canary, e2e, and external security checks. ## Risks - The migration adds one nullable text column. It has no default and no backfill. - `not_creator` reads the latest recorded transition into `in_review`. It denies the verdict when it cannot identify the requester. - Agents can change or relax `reviewPolicy` when they have issue write access. This is intentional for this issue-level control. - Null and `anyone` do not add a database query to the verdict path. - Configured execution-stage checks still run after the issue-level policy check. > This work aligns with the completed "Agent Reviews and Approvals" and "Enforced Outcomes" roadmap items. It does not add a new roadmap capability. ## Model Used - OpenAI Codex, GPT-5. The exact deployment ID and context-window size are not exposed to the agent. The run used reasoning, repository tools, code execution, and GitHub CLI access. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
141 lines
4.0 KiB
TypeScript
141 lines
4.0 KiB
TypeScript
import { describe, expect, it } from "vitest";
|
|
import type { ExecutionWorkspace, Issue } from "@paperclipai/shared";
|
|
import { buildSubIssueDefaults, buildSubIssueDefaultsForViewer } from "./subIssueDefaults";
|
|
|
|
function makeExecutionWorkspace(overrides: Partial<ExecutionWorkspace> = {}): ExecutionWorkspace {
|
|
return {
|
|
id: "workspace-1",
|
|
companyId: "company-1",
|
|
projectId: "project-1",
|
|
projectWorkspaceId: "project-workspace-1",
|
|
sourceIssueId: null,
|
|
status: "active",
|
|
deliveryState: "unknown",
|
|
mode: "isolated_workspace",
|
|
strategyType: "git_worktree",
|
|
name: "Parent workspace",
|
|
cwd: "/tmp/workspace-1",
|
|
repoUrl: null,
|
|
baseRef: null,
|
|
branchName: "feature/pap-1",
|
|
providerType: "git_worktree",
|
|
providerRef: null,
|
|
derivedFromExecutionWorkspaceId: null,
|
|
openedAt: new Date("2026-04-07T00:00:00.000Z"),
|
|
closedAt: null,
|
|
cleanupEligibleAt: null,
|
|
cleanupReason: null,
|
|
config: null,
|
|
metadata: null,
|
|
lastUsedAt: new Date("2026-04-07T00:00:00.000Z"),
|
|
createdAt: new Date("2026-04-07T00:00:00.000Z"),
|
|
updatedAt: new Date("2026-04-07T00:00:00.000Z"),
|
|
...overrides,
|
|
};
|
|
}
|
|
|
|
function makeIssue(overrides: Partial<Issue> = {}): Issue {
|
|
return {
|
|
id: "issue-1",
|
|
identifier: "PAP-1",
|
|
companyId: "company-1",
|
|
projectId: "project-1",
|
|
projectWorkspaceId: "project-workspace-1",
|
|
goalId: "goal-1",
|
|
parentId: null,
|
|
title: "Parent issue",
|
|
description: null,
|
|
status: "todo",
|
|
priority: "medium",
|
|
reviewPolicy: null,
|
|
assigneeAgentId: null,
|
|
assigneeUserId: null,
|
|
responsibleUserId: null,
|
|
checkoutRunId: null,
|
|
executionRunId: null,
|
|
executionAgentNameKey: null,
|
|
executionLockedAt: null,
|
|
createdByAgentId: null,
|
|
createdByUserId: null,
|
|
issueNumber: 1,
|
|
requestDepth: 0,
|
|
billingCode: null,
|
|
assigneeAdapterOverrides: null,
|
|
executionWorkspaceId: null,
|
|
executionWorkspacePreference: "shared_workspace",
|
|
executionWorkspaceSettings: null,
|
|
currentExecutionWorkspace: null,
|
|
startedAt: null,
|
|
completedAt: null,
|
|
cancelledAt: null,
|
|
hiddenAt: null,
|
|
createdAt: new Date("2026-04-07T00:00:00.000Z"),
|
|
updatedAt: new Date("2026-04-07T00:00:00.000Z"),
|
|
...overrides,
|
|
workMode: overrides.workMode ?? "standard",
|
|
};
|
|
}
|
|
|
|
describe("buildSubIssueDefaults", () => {
|
|
it("inherits the parent agent assignee and workspace context", () => {
|
|
const defaults = buildSubIssueDefaults(
|
|
makeIssue({
|
|
assigneeAgentId: "agent-1",
|
|
executionWorkspaceId: "workspace-1",
|
|
currentExecutionWorkspace: makeExecutionWorkspace(),
|
|
}),
|
|
);
|
|
|
|
expect(defaults).toEqual({
|
|
parentId: "issue-1",
|
|
parentIdentifier: "PAP-1",
|
|
parentTitle: "Parent issue",
|
|
projectId: "project-1",
|
|
projectWorkspaceId: "project-workspace-1",
|
|
goalId: "goal-1",
|
|
executionWorkspaceId: "workspace-1",
|
|
executionWorkspaceMode: "reuse_existing",
|
|
parentExecutionWorkspaceLabel: "Parent workspace",
|
|
assigneeAgentId: "agent-1",
|
|
});
|
|
});
|
|
|
|
it("inherits a user assignee when the parent is assigned to a user", () => {
|
|
const defaults = buildSubIssueDefaults(
|
|
makeIssue({
|
|
assigneeUserId: "user-1",
|
|
}),
|
|
);
|
|
|
|
expect(defaults).toEqual({
|
|
parentId: "issue-1",
|
|
parentIdentifier: "PAP-1",
|
|
parentTitle: "Parent issue",
|
|
projectId: "project-1",
|
|
projectWorkspaceId: "project-workspace-1",
|
|
goalId: "goal-1",
|
|
executionWorkspaceMode: "shared_workspace",
|
|
assigneeUserId: "user-1",
|
|
});
|
|
});
|
|
|
|
it("leaves the sub-issue unassigned when the parent assignee is the current user", () => {
|
|
const defaults = buildSubIssueDefaultsForViewer(
|
|
makeIssue({
|
|
assigneeUserId: "user-1",
|
|
}),
|
|
"user-1",
|
|
);
|
|
|
|
expect(defaults).toEqual({
|
|
parentId: "issue-1",
|
|
parentIdentifier: "PAP-1",
|
|
parentTitle: "Parent issue",
|
|
projectId: "project-1",
|
|
projectWorkspaceId: "project-workspace-1",
|
|
goalId: "goal-1",
|
|
executionWorkspaceMode: "shared_workspace",
|
|
});
|
|
});
|
|
});
|