mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-10 03:08:10 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agent runs often need provider credentials, API tokens, and other environment-bound secrets. > - Company-level secrets work for shared credentials, but they do not model values that should differ by human operator. > - Without a user-scoped model, a run can dispatch without knowing whether the responsible human has supplied the needed value. > - Paperclip also needs run attribution to make those user-scoped runtime checks deterministic and auditable. > - This pull request adds user-specific secret definitions, per-user values, environment bindings, responsible-user attribution, and runtime resolution gates. > - The benefit is that teams can define the secret once, let each user provide their own value, and block runs before dispatch when required user secrets or active definitions are unavailable. ## Linked Issues or Issue Description Refs #224 Refs #6057 This PR implements user-specific secret support as a core secret-management capability rather than a one-off adapter setting. It is related to existing public work on company secrets UI and runtime secret refs, but is distinct because the value is owned by the responsible user and resolved at run dispatch time. Related PR search before opening found existing secrets work such as #1550, #8256, #8614, #8634, and #8647; none of those add the full user-secret definition/value/runtime gate covered here. ## What Changed - Added user-secret definitions and per-user "My secrets" values, keeping stored values out of access metadata. - Added `user_secret_ref` environment bindings and UI affordances to pick them alongside existing secret refs. - Added responsible-user runtime resolution so user-secret refs resolve against the human responsible for the run. - Added pre-dispatch missing-secret gates so runs fail before adapter dispatch when required user values are absent or definitions are inactive. - Added low-trust allowlist hardening for user-secret runtime access. - Added issue, routine, run, and agent API key responsible-user attribution and fail-closed dispatch behavior when attribution cannot be resolved. - Added denial-copy mapping so responsible-user authorization failures surface as actionable run outcomes instead of opaque setup failures. - Added OpenAPI documentation for the user-secret routes. - Rebases cleanly on current `master`; migrations were renumbered incrementally as `0128_user_specific_secrets`, `0129_agent_api_key_responsible_user`, and `0130_run_responsible_user_invariant` after upstream `0126`/`0127` migrations. - Removed previously committed local design screenshots so the PR contains code/docs/tests only. ## Verification - PASS: PR head `2527febd106bcf3ca264ca0da7fca491084192d6` is based on `paperclipai/paperclip:master`. - PASS: `git diff --check` - PASS: `git diff --name-only public/master...HEAD | rg '^(pnpm-lock\\.yaml|\\.github/workflows/|screenshots/)' || true` produced no files. - PASS: migration journal audit confirmed unique indexes through `130` with tail entries `0126_issue_comment_derived_attribution`, `0127_environment_custom_images_instance_scoped`, `0128_user_specific_secrets`, `0129_agent_api_key_responsible_user`, and `0130_run_responsible_user_invariant`. - PASS: `pnpm --filter @paperclipai/ui typecheck` - PASS: `pnpm --filter @paperclipai/server typecheck` - PASS: `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-responsible-user-invariant.test.ts` - PASS: `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-active-run-output-watchdog.test.ts src/__tests__/heartbeat-stale-queue-invalidation.test.ts src/__tests__/heartbeat-workspace-finalize-branch.test.ts src/__tests__/issue-monitor-scheduler.test.ts` - PASS: `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-comment-wake-batching.test.ts src/__tests__/heartbeat-retry-scheduling.test.ts src/__tests__/heartbeat-accepted-plan-workspace-refresh.test.ts src/__tests__/heartbeat-plugin-environment.test.ts` - PASS: `pnpm --filter @paperclipai/server exec vitest run src/__tests__/low-trust-red-team-routes.test.ts` - PASS: `pnpm --filter @paperclipai/server exec vitest run src/__tests__/secrets-service.test.ts` (55 tests) - PASS: `pnpm vitest run server/src/__tests__/secrets-routes.test.ts server/src/__tests__/secrets-service.test.ts` (89 tests after final Greptile cleanup fixes) - PASS: `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-issue-liveness-escalation.test.ts` (17 tests after the final rebase CI fix) - PASS: focused server Vitest batches covering heartbeat recovery, project env, plugin env, routines, low-trust, pipelines, monitors, watchdog, and stale queue paths. - PASS: GitHub checks are green on `2527febd106bcf3ca264ca0da7fca491084192d6`, including Typecheck + Release Registry, Build, General tests, serialized server suites, e2e, Canary Dry Run, verify, security checks, and Greptile Review. - PASS: Greptile Review completed successfully on `2527febd106bcf3ca264ca0da7fca491084192d6` with Confidence Score 5/5, and GraphQL review-thread audit returned zero unresolved non-outdated threads. ## Risks - Runtime behavior now depends on a run having a correct responsible user; missing or incorrect responsibility assignment can block runs before adapter dispatch. - `user_secret_ref` bindings intentionally expose metadata without values, but UI/API callers may need to handle the new binding kind explicitly. - External secret providers and IAM policies are not automatically provisioned by this PR; operators still need to configure provider-side access for non-local vaults. - The PR is broad across db/shared/server/UI/runtime paths, so release validation should include both API and UI secret workflows before merge. - The migration renumbering is intentionally incremental after upstream migrations; the branch migrations use guarded column/table/index/constraint creation so users who tested the older draft numbering should not hit duplicate DDL for the existing objects. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, GPT-5-based coding agent (`gpt-5`), Codex local adapter with shell/tool use and code execution. Context window and internal reasoning mode are not exposed by the runtime. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
336 lines
11 KiB
TypeScript
336 lines
11 KiB
TypeScript
import { Command } from "commander";
|
|
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
|
import type { Agent, CompanySecret } from "@paperclipai/shared";
|
|
import type { PaperclipConfig } from "../config/schema.js";
|
|
import { secretsCheck } from "../checks/secrets-check.js";
|
|
import {
|
|
buildInlineMigrationSecretName,
|
|
buildMigratedAgentEnv,
|
|
collectInlineSecretMigrationCandidates,
|
|
parseSecretsInclude,
|
|
registerSecretCommands,
|
|
toPlainEnvValue,
|
|
} from "../commands/client/secrets.js";
|
|
|
|
function agent(partial: Partial<Agent>): Agent {
|
|
return {
|
|
id: "agent-12345678",
|
|
companyId: "company-1",
|
|
name: "Coder",
|
|
urlKey: "coder",
|
|
role: "engineer",
|
|
title: null,
|
|
icon: null,
|
|
status: "idle",
|
|
reportsTo: null,
|
|
capabilities: null,
|
|
adapterType: "codex_local",
|
|
adapterConfig: {},
|
|
runtimeConfig: {},
|
|
budgetMonthlyCents: 0,
|
|
spentMonthlyCents: 0,
|
|
pauseReason: null,
|
|
pausedAt: null,
|
|
permissions: {
|
|
canCreateAgents: false,
|
|
},
|
|
lastHeartbeatAt: null,
|
|
metadata: null,
|
|
createdAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
updatedAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
...partial,
|
|
};
|
|
}
|
|
|
|
function secret(partial: Partial<CompanySecret>): CompanySecret {
|
|
return {
|
|
id: "secret-1",
|
|
companyId: "company-1",
|
|
scope: "company",
|
|
ownerUserId: null,
|
|
userSecretDefinitionId: null,
|
|
key: "agent_agent-12_anthropic_api_key",
|
|
name: "agent_agent-12_anthropic_api_key",
|
|
provider: "local_encrypted",
|
|
status: "active",
|
|
managedMode: "paperclip_managed",
|
|
externalRef: null,
|
|
providerConfigId: null,
|
|
providerMetadata: null,
|
|
latestVersion: 1,
|
|
description: null,
|
|
lastResolvedAt: null,
|
|
lastRotatedAt: null,
|
|
deletedAt: null,
|
|
createdByAgentId: null,
|
|
createdByUserId: null,
|
|
createdAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
updatedAt: new Date("2026-04-26T00:00:00.000Z"),
|
|
...partial,
|
|
};
|
|
}
|
|
|
|
function configWithSecretsProvider(provider: PaperclipConfig["secrets"]["provider"]): PaperclipConfig {
|
|
return {
|
|
$meta: {
|
|
version: 1,
|
|
updatedAt: "2026-05-02T00:00:00.000Z",
|
|
source: "configure",
|
|
},
|
|
database: {
|
|
mode: "embedded-postgres",
|
|
embeddedPostgresDataDir: "/tmp/paperclip/db",
|
|
embeddedPostgresPort: 55432,
|
|
backup: {
|
|
enabled: true,
|
|
intervalMinutes: 60,
|
|
retentionDays: 30,
|
|
dir: "/tmp/paperclip/backups",
|
|
},
|
|
},
|
|
logging: {
|
|
mode: "file",
|
|
logDir: "/tmp/paperclip/logs",
|
|
},
|
|
server: {
|
|
deploymentMode: "local_trusted",
|
|
exposure: "private",
|
|
host: "127.0.0.1",
|
|
port: 3100,
|
|
allowedHostnames: [],
|
|
serveUi: true,
|
|
},
|
|
auth: {
|
|
baseUrlMode: "auto",
|
|
disableSignUp: false,
|
|
},
|
|
telemetry: {
|
|
enabled: true,
|
|
},
|
|
storage: {
|
|
provider: "local_disk",
|
|
localDisk: {
|
|
baseDir: "/tmp/paperclip/storage",
|
|
},
|
|
s3: {
|
|
bucket: "paperclip",
|
|
region: "us-east-1",
|
|
prefix: "",
|
|
forcePathStyle: false,
|
|
},
|
|
},
|
|
secrets: {
|
|
provider,
|
|
strictMode: true,
|
|
localEncrypted: {
|
|
keyFilePath: "/tmp/paperclip/secrets/master.key",
|
|
},
|
|
},
|
|
};
|
|
}
|
|
|
|
describe("secrets CLI helpers", () => {
|
|
const originalEnv = { ...process.env };
|
|
|
|
beforeEach(() => {
|
|
process.env = { ...originalEnv };
|
|
delete process.env.PAPERCLIP_SECRETS_AWS_REGION;
|
|
delete process.env.AWS_REGION;
|
|
delete process.env.AWS_DEFAULT_REGION;
|
|
delete process.env.PAPERCLIP_SECRETS_AWS_DEPLOYMENT_ID;
|
|
delete process.env.PAPERCLIP_SECRETS_AWS_KMS_KEY_ID;
|
|
});
|
|
|
|
afterEach(() => {
|
|
process.env = { ...originalEnv };
|
|
});
|
|
|
|
it("parses declaration include filters", () => {
|
|
expect(parseSecretsInclude("agents,projects,tasks")).toEqual({
|
|
company: false,
|
|
agents: true,
|
|
projects: true,
|
|
issues: true,
|
|
skills: false,
|
|
});
|
|
});
|
|
|
|
it("detects inline sensitive env values that need migration", () => {
|
|
const rows = collectInlineSecretMigrationCandidates(
|
|
[
|
|
agent({
|
|
id: "agent-12345678",
|
|
adapterConfig: {
|
|
env: {
|
|
ANTHROPIC_API_KEY: "sk-ant-test",
|
|
GH_TOKEN: {
|
|
type: "plain",
|
|
value: "ghp-test",
|
|
},
|
|
PATH: {
|
|
type: "plain",
|
|
value: "/usr/bin",
|
|
},
|
|
OPENAI_API_KEY: {
|
|
type: "secret_ref",
|
|
secretId: "secret-existing",
|
|
},
|
|
},
|
|
},
|
|
}),
|
|
],
|
|
[
|
|
secret({
|
|
id: "secret-gh-token",
|
|
name: buildInlineMigrationSecretName("agent-12345678", "GH_TOKEN"),
|
|
}),
|
|
],
|
|
);
|
|
|
|
expect(rows).toEqual([
|
|
{
|
|
agentId: "agent-12345678",
|
|
agentName: "Coder",
|
|
envKey: "ANTHROPIC_API_KEY",
|
|
secretName: "agent_agent-12_anthropic_api_key",
|
|
existingSecretId: null,
|
|
},
|
|
{
|
|
agentId: "agent-12345678",
|
|
agentName: "Coder",
|
|
envKey: "GH_TOKEN",
|
|
secretName: "agent_agent-12_gh_token",
|
|
existingSecretId: "secret-gh-token",
|
|
},
|
|
]);
|
|
});
|
|
|
|
it("builds migrated env bindings without preserving secret values", () => {
|
|
const next = buildMigratedAgentEnv(
|
|
{
|
|
ANTHROPIC_API_KEY: "sk-ant-test",
|
|
NODE_ENV: {
|
|
type: "plain",
|
|
value: "development",
|
|
},
|
|
},
|
|
new Map([["ANTHROPIC_API_KEY", "secret-1"]]),
|
|
);
|
|
|
|
expect(next).toEqual({
|
|
ANTHROPIC_API_KEY: {
|
|
type: "secret_ref",
|
|
secretId: "secret-1",
|
|
version: "latest",
|
|
},
|
|
NODE_ENV: {
|
|
type: "plain",
|
|
value: "development",
|
|
},
|
|
});
|
|
expect(JSON.stringify(next)).not.toContain("sk-ant-test");
|
|
});
|
|
|
|
it("reads only explicit plain env values", () => {
|
|
expect(toPlainEnvValue("plain-value")).toBe("plain-value");
|
|
expect(toPlainEnvValue({ type: "plain", value: "wrapped" })).toBe("wrapped");
|
|
expect(toPlainEnvValue({ type: "secret_ref", secretId: "secret-1" })).toBeNull();
|
|
});
|
|
|
|
it("reports the AWS bootstrap config required by doctor", () => {
|
|
const result = secretsCheck(configWithSecretsProvider("aws_secrets_manager"));
|
|
|
|
expect(result.status).toBe("fail");
|
|
expect(result.message).toContain("PAPERCLIP_SECRETS_AWS_DEPLOYMENT_ID");
|
|
expect(result.repairHint).toContain("AWS SDK default credential chain");
|
|
expect(result.repairHint).toContain("Do not store AWS root credentials");
|
|
});
|
|
|
|
it("passes AWS doctor checks when non-secret provider config is present", () => {
|
|
process.env.PAPERCLIP_SECRETS_AWS_REGION = "us-east-1";
|
|
process.env.PAPERCLIP_SECRETS_AWS_DEPLOYMENT_ID = "prod-us-1";
|
|
process.env.PAPERCLIP_SECRETS_AWS_KMS_KEY_ID =
|
|
"arn:aws:kms:us-east-1:123456789012:key/test";
|
|
process.env.AWS_PROFILE = "paperclip-prod";
|
|
|
|
const result = secretsCheck(configWithSecretsProvider("aws_secrets_manager"));
|
|
|
|
expect(result.status).toBe("pass");
|
|
expect(result.message).toContain("prod-us-1");
|
|
expect(result.message).toContain("AWS_PROFILE/shared config");
|
|
});
|
|
});
|
|
|
|
describe("secrets API parity commands", () => {
|
|
beforeEach(() => {
|
|
vi.restoreAllMocks();
|
|
delete process.env.PAPERCLIP_API_KEY;
|
|
delete process.env.PAPERCLIP_API_URL;
|
|
vi.spyOn(console, "log").mockImplementation(() => {});
|
|
});
|
|
|
|
afterEach(() => {
|
|
vi.restoreAllMocks();
|
|
});
|
|
|
|
it("wraps provider config and remote import endpoints", async () => {
|
|
const fetchMock = vi.fn().mockImplementation(() => Promise.resolve(jsonResponse()));
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
await runSecretCommand(["secrets", "provider-configs", "--company-id", "company-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:create", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "provider-config:discovery-preview", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "provider-config:get", "config-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:update", "config-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "provider-config:default", "config-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:health", "config-1"]);
|
|
await runSecretCommand(["secrets", "provider-config:delete", "config-1"]);
|
|
await runSecretCommand(["secrets", "remote-import:preview", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
await runSecretCommand(["secrets", "remote-import", "--company-id", "company-1", "--payload-json", "{}"]);
|
|
|
|
expect(fetchMock.mock.calls.map((call) => [call[1]?.method ?? "GET", call[0]])).toEqual([
|
|
["GET", "http://localhost:3100/api/companies/company-1/secret-provider-configs"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secret-provider-configs"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secret-provider-configs/discovery/preview"],
|
|
["GET", "http://localhost:3100/api/secret-provider-configs/config-1"],
|
|
["PATCH", "http://localhost:3100/api/secret-provider-configs/config-1"],
|
|
["POST", "http://localhost:3100/api/secret-provider-configs/config-1/default"],
|
|
["POST", "http://localhost:3100/api/secret-provider-configs/config-1/health"],
|
|
["DELETE", "http://localhost:3100/api/secret-provider-configs/config-1"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secrets/remote-import/preview"],
|
|
["POST", "http://localhost:3100/api/companies/company-1/secrets/remote-import"],
|
|
]);
|
|
});
|
|
|
|
it("wraps secret metadata, rotation, usage, access event, and delete endpoints", async () => {
|
|
const fetchMock = vi.fn().mockImplementation(() => Promise.resolve(jsonResponse()));
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
await runSecretCommand(["secrets", "update", "secret-1", "--payload-json", "{\"description\":\"updated\"}"]);
|
|
await runSecretCommand(["secrets", "rotate", "secret-1", "--value", "new-value"]);
|
|
await runSecretCommand(["secrets", "usage", "secret-1"]);
|
|
await runSecretCommand(["secrets", "access-events", "secret-1"]);
|
|
await runSecretCommand(["secrets", "delete", "secret-1", "--yes", "--confirm", "secret-1"]);
|
|
|
|
expect(fetchMock.mock.calls.map((call) => [call[1]?.method ?? "GET", call[0]])).toEqual([
|
|
["PATCH", "http://localhost:3100/api/secrets/secret-1"],
|
|
["POST", "http://localhost:3100/api/secrets/secret-1/rotate"],
|
|
["GET", "http://localhost:3100/api/secrets/secret-1/usage"],
|
|
["GET", "http://localhost:3100/api/secrets/secret-1/access-events"],
|
|
["DELETE", "http://localhost:3100/api/secrets/secret-1"],
|
|
]);
|
|
});
|
|
});
|
|
|
|
async function runSecretCommand(args: string[]): Promise<void> {
|
|
const program = new Command();
|
|
program.exitOverride();
|
|
program.configureOutput({ writeOut: () => {}, writeErr: () => {} });
|
|
registerSecretCommands(program);
|
|
await program.parseAsync([...args, "--api-base", "http://localhost:3100", "--api-key", "board-token"], { from: "user" });
|
|
}
|
|
|
|
function jsonResponse(body: unknown = { ok: true }, init: ResponseInit = { status: 200 }): Response {
|
|
return new Response(JSON.stringify(body), init);
|
|
}
|