Files
PaperClipAI/ui/src/lib/workspace-file-parser.ts
T
DottaandPaperclip 7ea2068ef8 fix(files): only highlight accessible workspace file links (#11090)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Task comments can contain references to files in project and
execution workspaces.
> - Paperclip detected path-shaped inline code and showed it as an
actionable file chip.
> - The UI did not first confirm that the current board session could
open the file.
> - Missing, denied, ambiguous, remote, and unsupported files therefore
looked actionable and failed after a click.
> - This pull request adds an issue-scoped availability check and
promotes only confirmed files to chips.
> - The benefit is that the task thread shows a file action only when
that action can succeed.

## Linked Issues or Issue Description

**What happened?**

Task comments promoted path-shaped inline code to file chips before
Paperclip checked the file. A chip could point to a missing, denied,
ambiguous, remote, or non-previewable file. The action then failed after
the user selected it.

**Expected behavior**

Paperclip must show a file chip only after the server confirms that the
current board session can open the exact file reference. All other
path-shaped text must stay ordinary inline code.

**Steps to reproduce**

1. Add a task comment that contains inline code with a missing or
inaccessible workspace path.
2. Open the task thread as a board user.
3. Observe that the path looks like an actionable file chip.
4. Select the chip and observe that the file cannot open.

**Paperclip version or commit**

`19be4cf927` and earlier.

**Deployment mode**

Local dev and self-hosted server.

**Access context**

Board user.

## What Changed

- Added shared request, response, and validation contracts for batched
workspace-file availability checks.
- Added an issue-scoped server endpoint that resolves file references
with company, issue, workspace, and preview-access checks.
- Added bounded batch concurrency and tests for missing, denied,
ambiguous, remote, unsupported, and available files.
- Added an issue-scoped UI availability registry that deduplicates,
batches, caches, and invalidates file checks.
- Changed task-comment markdown rendering so only confirmed files get
chip styling and file-viewer behavior.
- Bound each chip to the exact workspace target that passed the
availability check.

## Verification

- `pnpm exec vitest run
packages/shared/src/workspace-file-resource.test.ts
server/src/__tests__/file-resources.test.ts
ui/src/components/MarkdownBody.test.tsx
ui/src/components/WorkspaceFileMarkdownBody.availability.test.tsx
ui/src/lib/remark-workspace-file-refs.test.ts
ui/src/lib/workspace-file-availability.test.ts` — 93 passed, 35 skipped.
- `pnpm check:token-gates` — clean.
- `pnpm -r typecheck` — passed.
- `pnpm build` — passed.
- `pnpm test:run` — all server and UI groups passed. One unchanged CLI
test saw the run-injected static AWS credentials and expected only its
local `AWS_PROFILE`. The same test passed, 8 of 8, after removing only
`AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` from its process
environment.

## Risks

- File chips now appear after an asynchronous availability check, so
path-shaped text can briefly render as inline code.
- Availability results use the existing 30-second file-resource cache
window. File-resource invalidation forces a new check.
- The endpoint limits each request to 100 references and the client
chunks larger sets.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex with GPT-5. The service did not expose a more specific
model ID or context-window size. The agent used high-reasoning mode,
repository tools, command execution, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-08-11 12:11:45 -04:00

116 lines
4.0 KiB
TypeScript

import type { WorkspaceFileSelector } from "@paperclipai/shared";
export interface ParsedWorkspaceFileRef {
path: string;
resourceKind?: "file" | "directory";
line: number | null;
column: number | null;
projectId?: string | null;
projectName?: string | null;
workspaceId?: string | null;
/**
* Workspace selector the reference is bound to. Set once availability has
* confirmed which workspace serves the path; defaults to `auto` otherwise.
*/
workspace?: WorkspaceFileSelector;
/** The original matched text (useful for rendering) */
raw: string;
}
/**
* Match a workspace file reference inside an inline code span.
*
* Accepts POSIX-style relative paths with at least one slash or a recognizable
* file extension. Supports optional line/column suffixes:
*
* - `path/to/file.ext`
* - `path/to/file.ext:42`
* - `path/to/file.ext:42:3`
* - `path/to/file.ext#L42`
* - `path/to/file.ext#L42C3`
*/
const WORKSPACE_FILE_REF_RE =
/^([A-Za-z0-9_.\-+][A-Za-z0-9_./\-+]*\.[A-Za-z0-9_+\-]{1,10})(?::([1-9]\d*)(?::([1-9]\d*))?|#L([1-9]\d*)(?:C([1-9]\d*))?)?$/;
const BARE_NO_EXT_RE = /^([A-Za-z0-9_.\-+][A-Za-z0-9_./\-+]+\/[A-Za-z0-9_.\-+]+)(?::([1-9]\d*)(?::([1-9]\d*))?|#L([1-9]\d*)(?:C([1-9]\d*))?)?$/;
const WORKSPACE_DIRECTORY_REF_RE = /^([A-Za-z0-9_.\-+][A-Za-z0-9_./\-+]*\/)$/;
const INVALID_PREFIXES = ["/", "./", "../", "~/"];
function toPositiveInt(value: string | undefined): number | null {
if (!value) return null;
const n = Number.parseInt(value, 10);
if (!Number.isFinite(n) || n <= 0) return null;
return n;
}
function looksLikeWorkspacePath(input: string, opts: { allowTrailingSlash: boolean }): boolean {
if (!input || input.length > 512) return false;
if (input.includes("\\") || input.includes("\0")) return false;
if (input.startsWith("/") || input.startsWith("~") || /^[A-Za-z]:/.test(input)) return false;
if (input.includes("//")) return false;
if (INVALID_PREFIXES.some((prefix) => input === prefix.slice(0, -1))) return false;
const path = opts.allowTrailingSlash && input.endsWith("/") ? input.slice(0, -1) : input;
if (!path || /^\.+$/.test(path)) return false;
const segments = path.split("/");
for (const segment of segments) {
if (segment === "" || segment === "." || segment === "..") return false;
}
return true;
}
/**
* Attempt to parse the given text as a workspace file reference.
* Returns null if the text does not look like one.
*/
export function parseWorkspaceFileRef(input: string): ParsedWorkspaceFileRef | null {
if (typeof input !== "string") return null;
const trimmed = input.trim();
if (!trimmed) return null;
const directoryMatch = trimmed.match(WORKSPACE_DIRECTORY_REF_RE);
if (directoryMatch) {
const [, rawPath] = directoryMatch;
if (!rawPath || !looksLikeWorkspacePath(rawPath, { allowTrailingSlash: true })) return null;
if (!rawPath.slice(0, -1).includes("/")) return null;
return {
path: rawPath,
resourceKind: "directory",
line: null,
column: null,
raw: trimmed,
};
}
const match = trimmed.match(WORKSPACE_FILE_REF_RE) ?? trimmed.match(BARE_NO_EXT_RE);
if (!match) return null;
const [, rawPath, colonLine, colonCol, hashLine, hashCol] = match;
if (!rawPath) return null;
if (!looksLikeWorkspacePath(rawPath, { allowTrailingSlash: false })) return null;
const line = toPositiveInt(colonLine) ?? toPositiveInt(hashLine);
const column = toPositiveInt(colonCol) ?? toPositiveInt(hashCol);
// Disambiguate against plain prose filenames like `README.md`:
// require either a slash in the path or a line anchor.
if (!rawPath.includes("/") && line === null) return null;
return {
path: rawPath,
resourceKind: "file",
line,
column,
raw: trimmed,
};
}
export function formatWorkspaceFileRefDisplay(ref: ParsedWorkspaceFileRef): string {
const path = ref.line && ref.column
? `${ref.path}:${ref.line}:${ref.column}`
: ref.line
? `${ref.path}:${ref.line}`
: ref.path;
return ref.projectName ? `${ref.projectName} / ${path}` : path;
}