mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-08 11:13:44 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents need a governed way to request app connections during issue work. > - The catalog now describes the available providers and setup methods. > - A request must become a durable, company-scoped intent before an operator acts on it. > - This pull request adds that intent runtime across server, agent, CLI, and shared contracts. > - The benefit is a safe bridge from agent need to operator-approved setup. ## Linked Issues or Issue Description Refs #11965 This is stack 7 of 11. It depends on stack 6 and replaces another reviewable part of #11965. ## What Changed - Add connection intent types, validation, service logic, and routes. - Add agent runtime tools and CLI support for connection requests. - Add issue-thread interaction support for connection intents. - Add runtime, route, adapter, and contract tests. - Hold the final resolved-continuation row lock through asynchronous adapter preparation until an actual process spawn, so parking or reassignment cannot cross that boundary. - Report Hermes Gateway's first remote run request through the shared dispatch hook so the resolved-intent lock is released at the true dispatch boundary. - Revalidate the addressed user's live non-viewer membership and connection-management authority for every intent mutation, including OAuth completion. ## Verification - `pnpm --filter @paperclipai/server typecheck` - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/tool-access-service.test.ts` - Result: 176 tests passed. - `pnpm build` - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/heartbeat-stale-queue-invalidation.test.ts` (32 passed; includes non-process dispatch lock-release coverage) - `pnpm exec vitest run --project @paperclipai/server server/src/__tests__/connection-intents-service.test.ts -t "addressed-user mutation"` (1 passed) - `pnpm exec vitest run --project @paperclipai/server server/src/__tests__/tool-access-service.test.ts -t "binds OAuth callback completion to the initiating board session"` (1 passed) - `pnpm --filter @paperclipai/hermes-paperclip-adapter test -- src/gateway/server/execute.test.ts` (23 passed; includes dispatch-hook ordering and exactly-once coverage) - `pnpm --filter @paperclipai/hermes-paperclip-adapter typecheck` ## Risks - A malformed intent could create an unusable operator request. - Validators and company checks reject invalid or cross-company requests. - The final continuation gate holds the issue row lock through adapter preparation until process or remote dispatch; later operator changes use the normal active-run interruption path. - The change does not add a database migration. > I checked `ROADMAP.md`. This stack continues the existing app connection work from #11965 and does not duplicate another planned item. ## Model Used OpenAI Codex, GPT-5. The runtime model ID and context window were not exposed. The model used reasoning, tool use, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have linked the public source pull request with `Refs #` - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
96 lines
3.2 KiB
TypeScript
96 lines
3.2 KiB
TypeScript
import { createHmac, timingSafeEqual } from "node:crypto";
|
|
import { resolvePaperclipInstanceId } from "./home-paths.js";
|
|
|
|
export interface RuntimeToolsTokenClaims {
|
|
sub: string;
|
|
company_id: string;
|
|
run_id: string;
|
|
responsible_user_id: string;
|
|
scope: "connection_intents";
|
|
iat: number;
|
|
exp: number;
|
|
instance_id: string;
|
|
}
|
|
|
|
const TOKEN_TTL_SECONDS = 60 * 60;
|
|
|
|
function secret() {
|
|
return process.env.PAPERCLIP_AGENT_JWT_SECRET?.trim()
|
|
|| process.env.BETTER_AUTH_SECRET?.trim()
|
|
|| null;
|
|
}
|
|
|
|
function encode(value: unknown) {
|
|
return Buffer.from(JSON.stringify(value), "utf8").toString("base64url");
|
|
}
|
|
|
|
function sign(value: string, companyId: string, instanceId: string) {
|
|
const master = secret();
|
|
if (!master) return null;
|
|
const key = createHmac("sha256", master)
|
|
.update(`runtime-tools:${instanceId}:${companyId}`)
|
|
.digest();
|
|
return createHmac("sha256", key).update(value).digest("base64url");
|
|
}
|
|
|
|
function safeEqual(left: string, right: string) {
|
|
const a = Buffer.from(left);
|
|
const b = Buffer.from(right);
|
|
return a.length === b.length && timingSafeEqual(a, b);
|
|
}
|
|
|
|
export function createRuntimeToolsToken(input: {
|
|
agentId: string;
|
|
companyId: string;
|
|
runId: string;
|
|
responsibleUserId: string;
|
|
}) {
|
|
if (!secret()) return null;
|
|
const now = Math.floor(Date.now() / 1000);
|
|
const instanceId = resolvePaperclipInstanceId();
|
|
const claims: RuntimeToolsTokenClaims = {
|
|
sub: input.agentId,
|
|
company_id: input.companyId,
|
|
run_id: input.runId,
|
|
responsible_user_id: input.responsibleUserId,
|
|
scope: "connection_intents",
|
|
iat: now,
|
|
exp: now + TOKEN_TTL_SECONDS,
|
|
instance_id: instanceId,
|
|
};
|
|
const signingInput = `${encode({ alg: "HS256", typ: "JWT" })}.${encode(claims)}`;
|
|
const signature = sign(signingInput, input.companyId, instanceId);
|
|
return signature
|
|
? { token: `${signingInput}.${signature}`, expiresAt: new Date(claims.exp * 1000).toISOString() }
|
|
: null;
|
|
}
|
|
|
|
export function verifyRuntimeToolsToken(token: string): RuntimeToolsTokenClaims | null {
|
|
const parts = token.split(".");
|
|
if (parts.length !== 3) return null;
|
|
let header: Record<string, unknown>;
|
|
let claims: Record<string, unknown>;
|
|
try {
|
|
header = JSON.parse(Buffer.from(parts[0]!, "base64url").toString("utf8"));
|
|
claims = JSON.parse(Buffer.from(parts[1]!, "base64url").toString("utf8"));
|
|
} catch {
|
|
return null;
|
|
}
|
|
if (header.alg !== "HS256") return null;
|
|
const companyId = typeof claims.company_id === "string" ? claims.company_id : null;
|
|
const instanceId = typeof claims.instance_id === "string" ? claims.instance_id : null;
|
|
if (!companyId || !instanceId || instanceId !== resolvePaperclipInstanceId()) return null;
|
|
const expected = sign(`${parts[0]}.${parts[1]}`, companyId, instanceId);
|
|
if (!expected || !safeEqual(parts[2]!, expected)) return null;
|
|
if (
|
|
typeof claims.sub !== "string"
|
|
|| typeof claims.run_id !== "string"
|
|
|| typeof claims.responsible_user_id !== "string"
|
|
|| claims.scope !== "connection_intents"
|
|
|| typeof claims.iat !== "number"
|
|
|| typeof claims.exp !== "number"
|
|
|| claims.exp <= Math.floor(Date.now() / 1000)
|
|
) return null;
|
|
return claims as unknown as RuntimeToolsTokenClaims;
|
|
}
|