mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Apps action tests let operators use an agent's permissions. > - The agent picker must scroll inside the test dialog. > - Its body portal sits outside the dialog's scroll boundary and blocks wheel input. > - Admin permission bypasses also skip agent lifecycle checks. > - This PR fixes scrolling and rejects agents that cannot receive assignments. ## Linked Issues or Issue Description **What happened?** The Act as picker does not scroll with the mouse wheel inside an action test dialog. Admins can also see terminated agents. **Expected behavior** The list scrolls normally. Terminated and pending-approval agents are absent. Direct requests cannot test an action as one of those agents. **Steps to reproduce** 1. Create enough agents to overflow the list. Terminate one agent. 2. Open a connected app's Permissions tab. Click Test on an action. 3. Open Act as and use the mouse wheel over the list. 4. Check whether the terminated agent appears as an admin. **Paperclip version or commit** Reproduced on master atf2c5e54dc. Rebased ontod351e08de. **Deployment mode** Local dev, built from source. This is a shared Apps bug and does not require Railway credentials. Related search result: #9918 added search to a separate secrets picker. It does not cover this action test dialog. No duplicate action-test picker PR was found. ## What Changed - Keep the action tester's agent popover inside its dialog's scroll boundary. - Check company membership and the shared agent lifecycle policy before assignment permission bypasses. - Reject terminated and pending-approval agents in lists, previews, and test calls. - Reuse company-scoped rows during listing to avoid extra per-agent queries. - Add route tests for both admin modes and a browser wheel-scroll regression. ## Verification - 335 focused tool-access and TestPanel tests passed after rebase. After the review cleanup, both admin regressions and writable-agent selection passed again (3 tests). - The browser regression failed before the fix because wheel input left scrollTop at zero. It passed after the fix, including search and selection. It executes no provider tools. - Full typecheck, build, and token gates passed during implementation. Token gates passed again after rebase. - The full test run reported a failure in the GitHub installation recovery chat test. That test passed in isolation. The full run was stopped after the failure, so later groups were not completed. Manual check: open an action's Test dialog, open Act as, scroll, search, and select an agent. Terminated agents must be absent. ## Risks The portal change affects only the picker inside the action test dialog. The browser test covers scrolling and selection. Paused agents remain eligible under existing assignment rules. There is no migration or provider policy change. ## Model Used OpenAI Codex, based on GPT-6, with code execution and browser testing. The exact serving model ID and context window were not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>