2026-02-23 14:40:32 -06:00
|
|
|
import type { Request, RequestHandler } from "express";
|
2026-02-25 08:39:20 -06:00
|
|
|
import type { IncomingHttpHeaders } from "node:http";
|
2026-02-23 14:40:32 -06:00
|
|
|
import { betterAuth } from "better-auth";
|
|
|
|
|
import { drizzleAdapter } from "better-auth/adapters/drizzle";
|
|
|
|
|
import { toNodeHandler } from "better-auth/node";
|
2026-03-03 08:45:26 -06:00
|
|
|
import type { Db } from "@paperclipai/db";
|
2026-02-23 14:40:32 -06:00
|
|
|
import {
|
|
|
|
|
authAccounts,
|
|
|
|
|
authSessions,
|
|
|
|
|
authUsers,
|
|
|
|
|
authVerifications,
|
2026-03-03 08:45:26 -06:00
|
|
|
} from "@paperclipai/db";
|
2026-02-23 14:40:32 -06:00
|
|
|
import type { Config } from "../config.js";
|
[codex] Add backup endpoint and dev runtime hardening (#4087)
## Thinking Path
> - Paperclip is a local-first control plane for AI-agent companies.
> - Operators need predictable local dev behavior, recoverable instance
data, and scripts that do not churn the running app.
> - Several accumulated changes improve backup streaming, dev-server
health, static UI caching/logging, diagnostic-file ignores, and instance
isolation.
> - These are operational improvements that can land independently from
product UI work.
> - This pull request groups the dev-infra and backup changes from the
split branch into one standalone branch.
> - The benefit is safer local operation, easier manual backups, less
noisy dev output, and less cross-instance auth leakage.
## What Changed
- Added a manual instance database backup endpoint and route tests.
- Streamed backup/restore handling to avoid materializing large payloads
at once.
- Reduced dev static UI log/cache churn and ignored Node diagnostic
report captures.
- Added guarded dev auto-restart health polling coverage.
- Preserved worktree config during provisioning and scoped auth cookies
by instance.
- Added a Discord daily digest helper script and environment
documentation.
- Hardened adapter-route and startup feedback export tests around the
changed infrastructure.
## Verification
- `pnpm install --frozen-lockfile`
- `pnpm exec vitest run packages/db/src/backup-lib.test.ts
server/src/__tests__/instance-database-backups-routes.test.ts
server/src/__tests__/server-startup-feedback-export.test.ts
server/src/__tests__/adapter-routes.test.ts
server/src/__tests__/dev-runner-paths.test.ts
server/src/__tests__/health-dev-server-token.test.ts
server/src/__tests__/http-log-policy.test.ts
server/src/__tests__/vite-html-renderer.test.ts
server/src/__tests__/workspace-runtime.test.ts
server/src/__tests__/better-auth.test.ts`
- Split integration check: merged after the runtime/governance branch
and before UI branches with no merge conflicts.
- Confirmed this branch does not include `pnpm-lock.yaml`.
## Risks
- Medium risk: touches server startup, backup streaming, auth cookie
naming, dev health checks, and worktree provisioning.
- Backup endpoint behavior depends on existing board/admin access
controls and database backup helpers.
- No database migrations are included.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex, GPT-5.4 tool-enabled coding model, agentic
code-editing/runtime with local shell and GitHub CLI access; exact
context window and reasoning mode are not exposed by the Paperclip
harness.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-04-20 06:08:55 -05:00
|
|
|
import { resolvePaperclipInstanceId } from "../home-paths.js";
|
2026-02-23 14:40:32 -06:00
|
|
|
|
|
|
|
|
export type BetterAuthSessionUser = {
|
|
|
|
|
id: string;
|
|
|
|
|
email?: string | null;
|
|
|
|
|
name?: string | null;
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
export type BetterAuthSessionResult = {
|
|
|
|
|
session: { id: string; userId: string } | null;
|
|
|
|
|
user: BetterAuthSessionUser | null;
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
type BetterAuthInstance = ReturnType<typeof betterAuth>;
|
|
|
|
|
|
[codex] Add backup endpoint and dev runtime hardening (#4087)
## Thinking Path
> - Paperclip is a local-first control plane for AI-agent companies.
> - Operators need predictable local dev behavior, recoverable instance
data, and scripts that do not churn the running app.
> - Several accumulated changes improve backup streaming, dev-server
health, static UI caching/logging, diagnostic-file ignores, and instance
isolation.
> - These are operational improvements that can land independently from
product UI work.
> - This pull request groups the dev-infra and backup changes from the
split branch into one standalone branch.
> - The benefit is safer local operation, easier manual backups, less
noisy dev output, and less cross-instance auth leakage.
## What Changed
- Added a manual instance database backup endpoint and route tests.
- Streamed backup/restore handling to avoid materializing large payloads
at once.
- Reduced dev static UI log/cache churn and ignored Node diagnostic
report captures.
- Added guarded dev auto-restart health polling coverage.
- Preserved worktree config during provisioning and scoped auth cookies
by instance.
- Added a Discord daily digest helper script and environment
documentation.
- Hardened adapter-route and startup feedback export tests around the
changed infrastructure.
## Verification
- `pnpm install --frozen-lockfile`
- `pnpm exec vitest run packages/db/src/backup-lib.test.ts
server/src/__tests__/instance-database-backups-routes.test.ts
server/src/__tests__/server-startup-feedback-export.test.ts
server/src/__tests__/adapter-routes.test.ts
server/src/__tests__/dev-runner-paths.test.ts
server/src/__tests__/health-dev-server-token.test.ts
server/src/__tests__/http-log-policy.test.ts
server/src/__tests__/vite-html-renderer.test.ts
server/src/__tests__/workspace-runtime.test.ts
server/src/__tests__/better-auth.test.ts`
- Split integration check: merged after the runtime/governance branch
and before UI branches with no merge conflicts.
- Confirmed this branch does not include `pnpm-lock.yaml`.
## Risks
- Medium risk: touches server startup, backup streaming, auth cookie
naming, dev health checks, and worktree provisioning.
- Backup endpoint behavior depends on existing board/admin access
controls and database backup helpers.
- No database migrations are included.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex, GPT-5.4 tool-enabled coding model, agentic
code-editing/runtime with local shell and GitHub CLI access; exact
context window and reasoning mode are not exposed by the Paperclip
harness.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-04-20 06:08:55 -05:00
|
|
|
const AUTH_COOKIE_PREFIX_FALLBACK = "default";
|
|
|
|
|
const AUTH_COOKIE_PREFIX_INVALID_SEGMENTS_RE = /[^a-zA-Z0-9_-]+/g;
|
|
|
|
|
|
|
|
|
|
export function deriveAuthCookiePrefix(instanceId = resolvePaperclipInstanceId()): string {
|
|
|
|
|
const scopedInstanceId = instanceId
|
|
|
|
|
.trim()
|
|
|
|
|
.replace(AUTH_COOKIE_PREFIX_INVALID_SEGMENTS_RE, "-")
|
|
|
|
|
.replace(/^-+|-+$/g, "") || AUTH_COOKIE_PREFIX_FALLBACK;
|
|
|
|
|
return `paperclip-${scopedInstanceId}`;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
export function buildBetterAuthAdvancedOptions(input: { disableSecureCookies: boolean }) {
|
|
|
|
|
return {
|
|
|
|
|
cookiePrefix: deriveAuthCookiePrefix(),
|
|
|
|
|
...(input.disableSecureCookies ? { useSecureCookies: false } : {}),
|
|
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
|
2026-02-25 08:39:20 -06:00
|
|
|
function headersFromNodeHeaders(rawHeaders: IncomingHttpHeaders): Headers {
|
2026-02-23 14:40:32 -06:00
|
|
|
const headers = new Headers();
|
2026-02-25 08:39:20 -06:00
|
|
|
for (const [key, raw] of Object.entries(rawHeaders)) {
|
2026-02-23 14:40:32 -06:00
|
|
|
if (!raw) continue;
|
|
|
|
|
if (Array.isArray(raw)) {
|
|
|
|
|
for (const value of raw) headers.append(key, value);
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
headers.set(key, raw);
|
|
|
|
|
}
|
|
|
|
|
return headers;
|
|
|
|
|
}
|
|
|
|
|
|
2026-02-25 08:39:20 -06:00
|
|
|
function headersFromExpressRequest(req: Request): Headers {
|
|
|
|
|
return headersFromNodeHeaders(req.headers);
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-05 17:55:34 -03:00
|
|
|
export function deriveAuthTrustedOrigins(config: Config): string[] {
|
|
|
|
|
const baseUrl = config.authBaseUrlMode === "explicit" ? config.authPublicBaseUrl : undefined;
|
|
|
|
|
const trustedOrigins = new Set<string>();
|
|
|
|
|
|
|
|
|
|
if (baseUrl) {
|
|
|
|
|
try {
|
|
|
|
|
trustedOrigins.add(new URL(baseUrl).origin);
|
|
|
|
|
} catch {
|
|
|
|
|
// Better Auth will surface invalid base URL separately.
|
|
|
|
|
}
|
|
|
|
|
}
|
2026-03-06 15:38:33 -03:00
|
|
|
if (config.deploymentMode === "authenticated") {
|
2026-03-05 17:55:34 -03:00
|
|
|
for (const hostname of config.allowedHostnames) {
|
|
|
|
|
const trimmed = hostname.trim().toLowerCase();
|
|
|
|
|
if (!trimmed) continue;
|
|
|
|
|
trustedOrigins.add(`https://${trimmed}`);
|
|
|
|
|
trustedOrigins.add(`http://${trimmed}`);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return Array.from(trustedOrigins);
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-06 15:38:33 -03:00
|
|
|
export function createBetterAuthInstance(db: Db, config: Config, trustedOrigins?: string[]): BetterAuthInstance {
|
2026-02-23 14:40:32 -06:00
|
|
|
const baseUrl = config.authBaseUrlMode === "explicit" ? config.authPublicBaseUrl : undefined;
|
2026-04-08 17:51:21 +03:00
|
|
|
const secret = process.env.BETTER_AUTH_SECRET ?? process.env.PAPERCLIP_AGENT_JWT_SECRET;
|
|
|
|
|
if (!secret) {
|
|
|
|
|
throw new Error(
|
|
|
|
|
"BETTER_AUTH_SECRET (or PAPERCLIP_AGENT_JWT_SECRET) must be set. " +
|
|
|
|
|
"For local development, set BETTER_AUTH_SECRET=paperclip-dev-secret in your .env file.",
|
|
|
|
|
);
|
|
|
|
|
}
|
2026-03-06 15:38:33 -03:00
|
|
|
const effectiveTrustedOrigins = trustedOrigins ?? deriveAuthTrustedOrigins(config);
|
2026-02-23 14:40:32 -06:00
|
|
|
|
2026-03-08 22:00:51 -05:00
|
|
|
const publicUrl = process.env.PAPERCLIP_PUBLIC_URL ?? baseUrl;
|
|
|
|
|
const isHttpOnly = publicUrl ? publicUrl.startsWith("http://") : false;
|
|
|
|
|
|
2026-02-23 14:40:32 -06:00
|
|
|
const authConfig = {
|
|
|
|
|
baseURL: baseUrl,
|
|
|
|
|
secret,
|
2026-03-06 15:38:33 -03:00
|
|
|
trustedOrigins: effectiveTrustedOrigins,
|
2026-02-23 14:40:32 -06:00
|
|
|
database: drizzleAdapter(db, {
|
|
|
|
|
provider: "pg",
|
|
|
|
|
schema: {
|
|
|
|
|
user: authUsers,
|
|
|
|
|
session: authSessions,
|
|
|
|
|
account: authAccounts,
|
|
|
|
|
verification: authVerifications,
|
|
|
|
|
},
|
|
|
|
|
}),
|
|
|
|
|
emailAndPassword: {
|
|
|
|
|
enabled: true,
|
|
|
|
|
requireEmailVerification: false,
|
2026-03-08 10:18:27 +08:00
|
|
|
disableSignUp: config.authDisableSignUp,
|
2026-02-23 14:40:32 -06:00
|
|
|
},
|
[codex] Add backup endpoint and dev runtime hardening (#4087)
## Thinking Path
> - Paperclip is a local-first control plane for AI-agent companies.
> - Operators need predictable local dev behavior, recoverable instance
data, and scripts that do not churn the running app.
> - Several accumulated changes improve backup streaming, dev-server
health, static UI caching/logging, diagnostic-file ignores, and instance
isolation.
> - These are operational improvements that can land independently from
product UI work.
> - This pull request groups the dev-infra and backup changes from the
split branch into one standalone branch.
> - The benefit is safer local operation, easier manual backups, less
noisy dev output, and less cross-instance auth leakage.
## What Changed
- Added a manual instance database backup endpoint and route tests.
- Streamed backup/restore handling to avoid materializing large payloads
at once.
- Reduced dev static UI log/cache churn and ignored Node diagnostic
report captures.
- Added guarded dev auto-restart health polling coverage.
- Preserved worktree config during provisioning and scoped auth cookies
by instance.
- Added a Discord daily digest helper script and environment
documentation.
- Hardened adapter-route and startup feedback export tests around the
changed infrastructure.
## Verification
- `pnpm install --frozen-lockfile`
- `pnpm exec vitest run packages/db/src/backup-lib.test.ts
server/src/__tests__/instance-database-backups-routes.test.ts
server/src/__tests__/server-startup-feedback-export.test.ts
server/src/__tests__/adapter-routes.test.ts
server/src/__tests__/dev-runner-paths.test.ts
server/src/__tests__/health-dev-server-token.test.ts
server/src/__tests__/http-log-policy.test.ts
server/src/__tests__/vite-html-renderer.test.ts
server/src/__tests__/workspace-runtime.test.ts
server/src/__tests__/better-auth.test.ts`
- Split integration check: merged after the runtime/governance branch
and before UI branches with no merge conflicts.
- Confirmed this branch does not include `pnpm-lock.yaml`.
## Risks
- Medium risk: touches server startup, backup streaming, auth cookie
naming, dev health checks, and worktree provisioning.
- Backup endpoint behavior depends on existing board/admin access
controls and database backup helpers.
- No database migrations are included.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex, GPT-5.4 tool-enabled coding model, agentic
code-editing/runtime with local shell and GitHub CLI access; exact
context window and reasoning mode are not exposed by the Paperclip
harness.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-04-20 06:08:55 -05:00
|
|
|
advanced: buildBetterAuthAdvancedOptions({ disableSecureCookies: isHttpOnly }),
|
2026-02-23 14:40:32 -06:00
|
|
|
};
|
|
|
|
|
|
|
|
|
|
if (!baseUrl) {
|
|
|
|
|
delete (authConfig as { baseURL?: string }).baseURL;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return betterAuth(authConfig);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
export function createBetterAuthHandler(auth: BetterAuthInstance): RequestHandler {
|
|
|
|
|
const handler = toNodeHandler(auth);
|
|
|
|
|
return (req, res, next) => {
|
|
|
|
|
void Promise.resolve(handler(req, res)).catch(next);
|
|
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
|
2026-02-25 08:39:20 -06:00
|
|
|
export async function resolveBetterAuthSessionFromHeaders(
|
2026-02-23 14:40:32 -06:00
|
|
|
auth: BetterAuthInstance,
|
2026-02-25 08:39:20 -06:00
|
|
|
headers: Headers,
|
2026-02-23 14:40:32 -06:00
|
|
|
): Promise<BetterAuthSessionResult | null> {
|
|
|
|
|
const api = (auth as unknown as { api?: { getSession?: (input: unknown) => Promise<unknown> } }).api;
|
|
|
|
|
if (!api?.getSession) return null;
|
|
|
|
|
|
|
|
|
|
const sessionValue = await api.getSession({
|
2026-02-25 08:39:20 -06:00
|
|
|
headers,
|
2026-02-23 14:40:32 -06:00
|
|
|
});
|
|
|
|
|
if (!sessionValue || typeof sessionValue !== "object") return null;
|
|
|
|
|
|
|
|
|
|
const value = sessionValue as {
|
|
|
|
|
session?: { id?: string; userId?: string } | null;
|
|
|
|
|
user?: { id?: string; email?: string | null; name?: string | null } | null;
|
|
|
|
|
};
|
|
|
|
|
const session = value.session?.id && value.session.userId
|
|
|
|
|
? { id: value.session.id, userId: value.session.userId }
|
|
|
|
|
: null;
|
|
|
|
|
const user = value.user?.id
|
|
|
|
|
? {
|
|
|
|
|
id: value.user.id,
|
|
|
|
|
email: value.user.email ?? null,
|
|
|
|
|
name: value.user.name ?? null,
|
|
|
|
|
}
|
|
|
|
|
: null;
|
|
|
|
|
|
|
|
|
|
if (!session || !user) return null;
|
|
|
|
|
return { session, user };
|
|
|
|
|
}
|
2026-02-25 08:39:20 -06:00
|
|
|
|
|
|
|
|
export async function resolveBetterAuthSession(
|
|
|
|
|
auth: BetterAuthInstance,
|
|
|
|
|
req: Request,
|
|
|
|
|
): Promise<BetterAuthSessionResult | null> {
|
|
|
|
|
return resolveBetterAuthSessionFromHeaders(auth, headersFromExpressRequest(req));
|
|
|
|
|
}
|