mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Governed MCP access spans contracts, runtime enforcement, adapters, UI surfaces, and operator verification > - The parity reference PR #9534 is too large for effective automated or human review > - The feature therefore needs a linear stack whose individual diffs stay below the 100-file review limit > - This pull request is split 8/8 and focuses on end-to-end coverage, operator docs, evals, and release notes > - The benefit is a standalone, testable review boundary while preserving byte-for-byte parity at the top of the stack ## Linked Issues or Issue Description - Related parity reference: #9534 - Problem: The complete stack needs discoverable browser scenarios, operator guidance, threat modeling, eval coverage, and a parity proof before merge. - Proposed solution: Adds MCP user-story and Smoke Lab e2e suites, docs/evals/release notes, the skill update, and the root e2e driver script registration. - Alternatives considered: keeping #9534 as one 403-file review, or rewriting the feature to manufacture seams; both were rejected in favor of path extraction plus compile-driven boundary moves. - Roadmap alignment: this advances the existing governed MCP/tool-access work already represented by #9534; it does not introduce a separate roadmap initiative. - Stack position: base branch is `pap10341-split/07-ui-apps-activation`. - Merge policy: merge bottom-up, in order, only after the complete eight-PR stack has been reviewed and the top-of-stack parity gate remains empty. - Requested review: QA for flag audit and e2e/browser acceptance; Greptile on every PR. ## What Changed - Adds MCP user-story and Smoke Lab e2e suites, docs/evals/release notes, the skill update, and the root e2e driver script registration. - Keeps this PR below 100 changed files and independently typecheckable. - Preserves the final tree from #9534 when combined with the other seven stack levels. ## Verification - `pnpm typecheck` - `node --check scripts/e2e-mcp-user-stories.mjs` - `pnpm exec playwright test --config tests/e2e/playwright.config.ts --list` — 43 tests discovered - `git diff pap10341-split/08-e2e-docs 6b40e3876d9297105d4ec306e47e46d351c86172` — empty (0 bytes) ## Risks - Browser suites depend on runtime services and environment setup; this PR validates discovery locally while QA owns full flag-on/flag-off execution. - Stack risk: merging out of order can expose incomplete layers; mitigate by following the documented bottom-up merge policy. - Parity risk: later edits to an intermediate branch can drift from #9534; mitigate by re-running the empty top-of-stack diff before merge. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, exact model ID `gpt-5.4`; runtime-managed context window; medium reasoning with repository, shell, Git, GitHub CLI, and code-execution tools enabled. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] Internal references are omitted except the execution-plan link explicitly required for this coordinated split stack - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge ## Stack Coordination - Internal execution plan: [PAP-13874](/PAP/issues/PAP-13874#document-plan) - Parity reference: #9534 - Stack: #9556 → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563 - Merge bottom-up only after full-stack review and an empty parity diff at #9563. --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
132 lines
3.9 KiB
TypeScript
132 lines
3.9 KiB
TypeScript
export type McpUserStoryStatus = "runnable" | "dependency_gated";
|
|
|
|
export interface McpUserStory {
|
|
id: `US-${number}`;
|
|
title: string;
|
|
personas: string[];
|
|
status: McpUserStoryStatus;
|
|
gate?: string;
|
|
assertions: string[];
|
|
}
|
|
|
|
export const mcpUserStories: McpUserStory[] = [
|
|
{
|
|
id: "US-1",
|
|
title: "First connector, five minutes",
|
|
personas: ["Casey", "Scout"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"Apps connect journey reaches a connected app without admin Tools navigation.",
|
|
"A read tool runs through the gateway as Scout.",
|
|
"Activity/audit evidence attributes the call to the selected Scout agent.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-2",
|
|
title: "Ask-first write, approved",
|
|
personas: ["Casey", "Scout"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"A side-effecting tool parks as an action request.",
|
|
"Approval executes the parked call exactly once.",
|
|
"Review and activity surfaces preserve the request-to-execution chain.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-3",
|
|
title: "Ask-first, denied/expired",
|
|
personas: ["Ana", "Scout"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"A denied action request returns a governed denial state.",
|
|
"The denied call does not reach the fixture server.",
|
|
"Review history and audit evidence expose the denial.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-4",
|
|
title: "Deny policy wins",
|
|
personas: ["Ana", "Scout"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"A block policy takes precedence over existing allow/ask-first access.",
|
|
"Disabling the block policy takes effect without reconnecting.",
|
|
"Both the denial and later success are audited.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-5",
|
|
title: "Bring your own MCP server",
|
|
personas: ["Devon"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"A pasted MCP URL discovers fixture tools.",
|
|
"Only reviewed/enabled tools become callable.",
|
|
"Unreviewed tools remain unavailable until the connection is finished.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-6",
|
|
title: "OAuth connector",
|
|
personas: ["Casey"],
|
|
status: "dependency_gated",
|
|
gate: "Phase 4a/4b Paperclip-owned OAuth app registrations.",
|
|
assertions: [
|
|
"OAuth state round trip completes without token leakage.",
|
|
"Reconnect-after-revoke restores health.",
|
|
"Scoped catalog calls succeed after callback.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-7",
|
|
title: "External client via gateway",
|
|
personas: ["Devon"],
|
|
status: "dependency_gated",
|
|
gate: "Gateway UI and session revocation dependencies PAP-11200/PAP-11190.",
|
|
assertions: [
|
|
"A real external MCP client sees only policy-allowed tools.",
|
|
"Gateway calls are audited with client/session attribution.",
|
|
"Session revocation cuts the client off immediately.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-8",
|
|
title: "Credential failure and recovery",
|
|
personas: ["Casey"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"Broken credentials surface on the app card and Needs attention.",
|
|
"Reconnect restores connection health.",
|
|
"Calls succeed after recovery.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-9",
|
|
title: "Test-tab bug regressions",
|
|
personas: ["Ana"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"A side-effecting ask-first test action can be approved and re-run.",
|
|
"The Review link does not lose the pending card.",
|
|
"Catalog descriptions remain stable for fixture transports.",
|
|
],
|
|
},
|
|
{
|
|
id: "US-10",
|
|
title: "Admin depth is optional",
|
|
personas: ["Casey", "Ana"],
|
|
status: "runnable",
|
|
assertions: [
|
|
"Casey completes the happy path from Apps.",
|
|
"Ana can trace the same connection in admin depth.",
|
|
"Apps and Tools naming remain coherent.",
|
|
],
|
|
},
|
|
];
|
|
|
|
export function storyById(id: McpUserStory["id"]): McpUserStory {
|
|
const story = mcpUserStories.find((candidate) => candidate.id === id);
|
|
if (!story) throw new Error(`Unknown MCP user story: ${id}`);
|
|
return story;
|
|
}
|