2026-04-06 07:17:48 -05:00
|
|
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
|
|
|
import { PaperclipApiClient } from "./client.js";
|
|
|
|
|
import { createToolDefinitions } from "./tools.js";
|
|
|
|
|
|
|
|
|
|
function makeClient() {
|
|
|
|
|
return new PaperclipApiClient({
|
|
|
|
|
apiUrl: "http://localhost:3100/api",
|
|
|
|
|
apiKey: "token-123",
|
|
|
|
|
companyId: "11111111-1111-1111-1111-111111111111",
|
|
|
|
|
agentId: "22222222-2222-2222-2222-222222222222",
|
|
|
|
|
runId: "33333333-3333-3333-3333-333333333333",
|
|
|
|
|
});
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function getTool(name: string) {
|
|
|
|
|
const tool = createToolDefinitions(makeClient()).find((candidate) => candidate.name === name);
|
|
|
|
|
if (!tool) throw new Error(`Missing tool ${name}`);
|
|
|
|
|
return tool;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function mockJsonResponse(body: unknown, status = 200) {
|
|
|
|
|
return new Response(JSON.stringify(body), {
|
|
|
|
|
status,
|
|
|
|
|
headers: { "Content-Type": "application/json" },
|
|
|
|
|
});
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
describe("paperclip MCP tools", () => {
|
|
|
|
|
beforeEach(() => {
|
|
|
|
|
vi.restoreAllMocks();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("adds auth headers and run id to mutating requests", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ ok: true }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipUpdateIssue");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
status: "done",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(fetchMock).toHaveBeenCalledTimes(1);
|
|
|
|
|
const [url, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(String(url)).toBe("http://localhost:3100/api/issues/PAP-1135");
|
|
|
|
|
expect(init.method).toBe("PATCH");
|
|
|
|
|
expect((init.headers as Record<string, string>)["Authorization"]).toBe("Bearer token-123");
|
|
|
|
|
expect((init.headers as Record<string, string>)["X-Paperclip-Run-Id"]).toBe(
|
|
|
|
|
"33333333-3333-3333-3333-333333333333",
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("uses default company id for company-scoped list tools", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse([{ id: "issue-1" }]),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipListIssues");
|
|
|
|
|
const response = await tool.execute({});
|
|
|
|
|
|
|
|
|
|
expect(fetchMock).toHaveBeenCalledTimes(1);
|
|
|
|
|
const [url] = fetchMock.mock.calls[0] as [string];
|
|
|
|
|
expect(String(url)).toBe(
|
|
|
|
|
"http://localhost:3100/api/companies/11111111-1111-1111-1111-111111111111/issues",
|
|
|
|
|
);
|
|
|
|
|
expect(response.content[0]?.text).toContain("issue-1");
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("uses default agent id for checkout requests", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ id: "PAP-1135", status: "in_progress" }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipCheckoutIssue");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const [, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(JSON.parse(String(init.body))).toEqual({
|
|
|
|
|
agentId: "22222222-2222-2222-2222-222222222222",
|
|
|
|
|
expectedStatuses: ["todo", "backlog", "blocked"],
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
Guard assigned backlog liveness (#5428)
## Thinking Path
> - Paperclip orchestrates AI agents for zero-human companies
> - The issue graph and liveness recovery system decide whether assigned
work is executable or parked
> - Assigned issues created without an explicit status could silently
land in backlog, making parents look blocked with no productive wake
path
> - The server, shared validators, recovery analysis, and UI all need to
agree on that execution semantic
> - This pull request makes assigned issue creation default to `todo`,
flags assigned backlog blockers, and surfaces the state in the board
> - The benefit is that parked assigned work becomes intentional and
visible instead of creating silent liveness stalls
## What Changed
- Adds contract tests for assigned issue creation defaults.
- Defaults assigned issue creation to `todo` when status is omitted
while preserving explicit `backlog` parking.
- Exposes `resolveCreateIssueStatusDefault` through shared validators.
- Teaches liveness/blocker attention paths to distinguish assigned
backlog blockers.
- Adds UI notices, row/header badges, and issue detail safeguards for
assigned backlog blockers.
- Adds Storybook fixtures and execution-semantics documentation for the
assigned-backlog behavior.
## Verification
- `pnpm run preflight:workspace-links && pnpm exec vitest run
packages/shared/src/validators/issue.test.ts
server/src/__tests__/issue-assigned-backlog-contract-routes.test.ts
server/src/__tests__/issue-blocker-attention.test.ts
server/src/__tests__/issue-liveness.test.ts
server/src/__tests__/heartbeat-issue-liveness-escalation.test.ts
ui/src/components/IssueAssignedBacklogNotice.test.tsx
ui/src/components/IssueRow.test.tsx` — 50 passed, 23 skipped.
- Skipped tests were embedded Postgres suites on this host with the repo
skip message: `Postgres init script exited with code null. Please check
the logs for extra info. The data directory might already exist.`
- Pairwise merge check against the issue-controls PR branch completed
without conflicts via `git merge --no-commit --no-ff` in a temporary
worktree.
- Screenshots for assigned-backlog UI states:
[light](docs/pr-screenshots/pr-5428/assigned-backlog-light.png),
[dark](docs/pr-screenshots/pr-5428/assigned-backlog-dark.png).
- Follow-up checks: `pnpm --filter /ui typecheck`; `pnpm --filter
/mcp-server build`; `pnpm --filter /mcp-server test`; `pnpm exec vitest
run packages/shared/src/validators/issue.test.ts`; focused UI component
tests.
- Remote PR checks on head `6300b3c`: policy, verify, serialized server
shards 1/4-4/4, Canary Dry Run, e2e, Greptile Review, and Snyk all
passed.
## Risks
- Medium: changes status defaulting for assigned issue creation when the
caller omits status. Explicit `backlog` remains supported, and
server/shared tests cover both paths.
- Medium: liveness classification changes can affect blocker attention
labels; focused service and UI tests cover the new assigned-backlog
state.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex coding agent, GPT-5 model family (`gpt-5`), tool-enabled
Paperclip heartbeat environment. Context window and internal reasoning
mode are not exposed by the runtime.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-05-07 12:25:26 -05:00
|
|
|
it("allows create issue requests to omit status so the API applies assignee defaults", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ id: "issue-1", status: "todo" }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipCreateIssue");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
title: "Assigned follow-up",
|
|
|
|
|
assigneeAgentId: "22222222-2222-2222-2222-222222222222",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const [url, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(String(url)).toBe(
|
|
|
|
|
"http://localhost:3100/api/companies/11111111-1111-1111-1111-111111111111/issues",
|
|
|
|
|
);
|
|
|
|
|
expect(init.method).toBe("POST");
|
|
|
|
|
expect(JSON.parse(String(init.body))).toEqual({
|
|
|
|
|
title: "Assigned follow-up",
|
|
|
|
|
workMode: "standard",
|
|
|
|
|
priority: "medium",
|
|
|
|
|
assigneeAgentId: "22222222-2222-2222-2222-222222222222",
|
|
|
|
|
requestDepth: 0,
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
2026-04-06 07:17:48 -05:00
|
|
|
it("defaults issue document format to markdown", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ key: "plan", latestRevisionNumber: 2 }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipUpsertIssueDocument");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
key: "plan",
|
|
|
|
|
body: "# Updated",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const [, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(JSON.parse(String(init.body))).toEqual({
|
|
|
|
|
format: "markdown",
|
|
|
|
|
body: "# Updated",
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
[codex] Harden heartbeat scheduling and runtime controls (#4223)
## Thinking Path
> - Paperclip orchestrates AI agents through issue checkout, heartbeat
runs, routines, and auditable control-plane state
> - The runtime path has to recover from lost local processes, transient
adapter failures, blocked dependencies, and routine coalescing without
stranding work
> - The existing branch carried several reliability fixes across
heartbeat scheduling, issue runtime controls, routine dispatch, and
operator-facing run state
> - These changes belong together because they share backend contracts,
migrations, and runtime status semantics
> - This pull request groups the control-plane/runtime slice so it can
merge independently from board UI polish and adapter sandbox work
> - The benefit is safer heartbeat recovery, clearer runtime controls,
and more predictable recurring execution behavior
## What Changed
- Adds bounded heartbeat retry scheduling, scheduled retry state, and
Codex transient failure recovery handling.
- Tightens heartbeat process recovery, blocker wake behavior, issue
comment wake handling, routine dispatch coalescing, and
activity/dashboard bounds.
- Adds runtime-control MCP tools and Paperclip skill docs for issue
workspace runtime management.
- Adds migrations `0061_lively_thor_girl.sql` and
`0062_routine_run_dispatch_fingerprint.sql`.
- Surfaces retry state in run ledger/agent UI and keeps related shared
types synchronized.
## Verification
- `pnpm exec vitest run
server/src/__tests__/heartbeat-retry-scheduling.test.ts
server/src/__tests__/heartbeat-process-recovery.test.ts
server/src/__tests__/routines-service.test.ts`
- `pnpm exec vitest run src/tools.test.ts` from `packages/mcp-server`
## Risks
- Medium risk: this touches heartbeat recovery and routine dispatch,
which are central execution paths.
- Migration order matters if split branches land out of order: merge
this PR before branches that assume the new runtime/routine fields.
- Runtime retry behavior should be watched in CI and in local operator
smoke tests because it changes how transient failures are resumed.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex, GPT-5-based coding agent runtime, shell/git tool use
enabled. Exact hosted model build and context window are not exposed in
this Paperclip heartbeat environment.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-04-21 12:24:11 -05:00
|
|
|
it("controls issue workspace services through the current execution workspace", async () => {
|
|
|
|
|
const fetchMock = vi.fn()
|
|
|
|
|
.mockResolvedValueOnce(mockJsonResponse({
|
|
|
|
|
currentExecutionWorkspace: {
|
|
|
|
|
id: "44444444-4444-4444-8444-444444444444",
|
|
|
|
|
runtimeServices: [],
|
|
|
|
|
},
|
|
|
|
|
}))
|
|
|
|
|
.mockResolvedValueOnce(mockJsonResponse({
|
|
|
|
|
operation: { id: "operation-1" },
|
|
|
|
|
workspace: {
|
|
|
|
|
id: "44444444-4444-4444-8444-444444444444",
|
|
|
|
|
runtimeServices: [
|
|
|
|
|
{
|
|
|
|
|
id: "55555555-5555-4555-8555-555555555555",
|
|
|
|
|
serviceName: "web",
|
|
|
|
|
status: "running",
|
|
|
|
|
url: "http://127.0.0.1:5173",
|
|
|
|
|
},
|
|
|
|
|
],
|
|
|
|
|
},
|
|
|
|
|
}));
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipControlIssueWorkspaceServices");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
action: "restart",
|
|
|
|
|
workspaceCommandId: "web",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(fetchMock).toHaveBeenCalledTimes(2);
|
|
|
|
|
const [lookupUrl, lookupInit] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(String(lookupUrl)).toBe("http://localhost:3100/api/issues/PAP-1135/heartbeat-context");
|
|
|
|
|
expect(lookupInit.method).toBe("GET");
|
|
|
|
|
|
|
|
|
|
const [controlUrl, controlInit] = fetchMock.mock.calls[1] as [string, RequestInit];
|
|
|
|
|
expect(String(controlUrl)).toBe(
|
|
|
|
|
"http://localhost:3100/api/execution-workspaces/44444444-4444-4444-8444-444444444444/runtime-services/restart",
|
|
|
|
|
);
|
|
|
|
|
expect(controlInit.method).toBe("POST");
|
|
|
|
|
expect(JSON.parse(String(controlInit.body))).toEqual({
|
|
|
|
|
workspaceCommandId: "web",
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("waits for an issue workspace runtime service URL", async () => {
|
|
|
|
|
const fetchMock = vi.fn()
|
|
|
|
|
.mockResolvedValueOnce(mockJsonResponse({
|
|
|
|
|
currentExecutionWorkspace: {
|
|
|
|
|
id: "44444444-4444-4444-8444-444444444444",
|
|
|
|
|
runtimeServices: [
|
|
|
|
|
{
|
|
|
|
|
id: "55555555-5555-4555-8555-555555555555",
|
|
|
|
|
serviceName: "web",
|
|
|
|
|
status: "running",
|
|
|
|
|
healthStatus: "healthy",
|
|
|
|
|
url: "http://127.0.0.1:5173",
|
|
|
|
|
},
|
|
|
|
|
],
|
|
|
|
|
},
|
|
|
|
|
}));
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipWaitForIssueWorkspaceService");
|
|
|
|
|
const response = await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
serviceName: "web",
|
|
|
|
|
timeoutSeconds: 1,
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(fetchMock).toHaveBeenCalledTimes(1);
|
|
|
|
|
expect(response.content[0]?.text).toContain("http://127.0.0.1:5173");
|
|
|
|
|
});
|
|
|
|
|
|
[codex] Add structured issue-thread interactions (#4244)
## Thinking Path
> - Paperclip orchestrates AI agents for zero-human companies.
> - Operators supervise that work through issues, comments, approvals,
and the board UI.
> - Some agent proposals need structured board/user decisions, not
hidden markdown conventions or heavyweight governed approvals.
> - Issue-thread interactions already provide a natural thread-native
surface for proposed tasks and questions.
> - This pull request extends that surface with request confirmations,
richer interaction cards, and agent/plugin/MCP helpers.
> - The benefit is that plan approvals and yes/no decisions become
explicit, auditable, and resumable without losing the single-issue
workflow.
## What Changed
- Added persisted issue-thread interactions for suggested tasks,
structured questions, and request confirmations.
- Added board UI cards for interaction review, selection, question
answers, and accept/reject confirmation flows.
- Added MCP and plugin SDK helpers for creating interaction cards from
agents/plugins.
- Updated agent wake instructions, onboarding assets, Paperclip skill
docs, and public docs to prefer structured confirmations for
issue-scoped decisions.
- Rebased the branch onto `public-gh/master` and renumbered branch
migrations to `0063` and `0064`; the idempotency migration uses `ADD
COLUMN IF NOT EXISTS` for old branch users.
## Verification
- `git diff --check public-gh/master..HEAD`
- `pnpm exec vitest run packages/adapter-utils/src/server-utils.test.ts
packages/mcp-server/src/tools.test.ts
packages/shared/src/issue-thread-interactions.test.ts
ui/src/lib/issue-thread-interactions.test.ts
ui/src/lib/issue-chat-messages.test.ts
ui/src/components/IssueThreadInteractionCard.test.tsx
ui/src/components/IssueChatThread.test.tsx
server/src/__tests__/issue-thread-interaction-routes.test.ts
server/src/__tests__/issue-thread-interactions-service.test.ts
server/src/services/issue-thread-interactions.test.ts` -> 9 files / 79
tests passed
- `pnpm -r typecheck` -> passed, including `packages/db` migration
numbering check
## Risks
- Medium: this adds a new issue-thread interaction model across
db/shared/server/ui/plugin surfaces.
- Migration risk is reduced by placing this branch after current master
migrations (`0063`, `0064`) and making the idempotency column add
idempotent for users who applied the old branch numbering.
- UI interaction behavior is covered by component tests, but this PR
does not include browser screenshots.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex, GPT-5-class coding agent runtime. Exact model ID and
context window are not exposed in this Paperclip run; tool use and local
shell/code execution were enabled.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-04-21 20:15:11 -05:00
|
|
|
it("creates suggest_tasks interactions with the expected issue-scoped payload", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ id: "interaction-1", kind: "suggest_tasks" }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipSuggestTasks");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
idempotencyKey: "run-1:suggest",
|
|
|
|
|
payload: {
|
|
|
|
|
version: 1,
|
|
|
|
|
tasks: [{ clientKey: "task-1", title: "One" }],
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const [url, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(String(url)).toBe("http://localhost:3100/api/issues/PAP-1135/interactions");
|
|
|
|
|
expect(init.method).toBe("POST");
|
|
|
|
|
expect(JSON.parse(String(init.body))).toEqual({
|
|
|
|
|
kind: "suggest_tasks",
|
|
|
|
|
continuationPolicy: "wake_assignee",
|
|
|
|
|
idempotencyKey: "run-1:suggest",
|
|
|
|
|
payload: {
|
|
|
|
|
version: 1,
|
|
|
|
|
tasks: [{ clientKey: "task-1", title: "One" }],
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
it("creates request_confirmation interactions with plan target payloads", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ id: "interaction-1", kind: "request_confirmation" }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipRequestConfirmation");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
issueId: "PAP-1135",
|
|
|
|
|
idempotencyKey: "confirmation:PAP-1135:plan:33333333-3333-4333-8333-333333333333",
|
|
|
|
|
title: "Plan approval",
|
|
|
|
|
payload: {
|
|
|
|
|
version: 1,
|
|
|
|
|
prompt: "Accept this plan?",
|
|
|
|
|
acceptLabel: "Accept plan",
|
|
|
|
|
allowDeclineReason: true,
|
|
|
|
|
rejectLabel: "Request changes",
|
|
|
|
|
rejectRequiresReason: true,
|
|
|
|
|
supersedeOnUserComment: true,
|
|
|
|
|
target: {
|
|
|
|
|
type: "issue_document",
|
|
|
|
|
key: "plan",
|
|
|
|
|
revisionId: "33333333-3333-4333-8333-333333333333",
|
|
|
|
|
revisionNumber: 3,
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const [url, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(String(url)).toBe("http://localhost:3100/api/issues/PAP-1135/interactions");
|
|
|
|
|
expect(init.method).toBe("POST");
|
|
|
|
|
expect(JSON.parse(String(init.body))).toEqual({
|
|
|
|
|
kind: "request_confirmation",
|
|
|
|
|
continuationPolicy: "none",
|
|
|
|
|
idempotencyKey: "confirmation:PAP-1135:plan:33333333-3333-4333-8333-333333333333",
|
|
|
|
|
title: "Plan approval",
|
|
|
|
|
payload: {
|
|
|
|
|
version: 1,
|
|
|
|
|
prompt: "Accept this plan?",
|
|
|
|
|
acceptLabel: "Accept plan",
|
|
|
|
|
allowDeclineReason: true,
|
|
|
|
|
rejectLabel: "Request changes",
|
|
|
|
|
rejectRequiresReason: true,
|
|
|
|
|
supersedeOnUserComment: true,
|
|
|
|
|
target: {
|
|
|
|
|
type: "issue_document",
|
|
|
|
|
key: "plan",
|
|
|
|
|
revisionId: "33333333-3333-4333-8333-333333333333",
|
|
|
|
|
revisionNumber: 3,
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
2026-04-06 21:56:13 -05:00
|
|
|
it("creates approvals with the expected company-scoped payload", async () => {
|
|
|
|
|
const fetchMock = vi.fn().mockResolvedValue(
|
|
|
|
|
mockJsonResponse({ id: "approval-1" }),
|
|
|
|
|
);
|
|
|
|
|
vi.stubGlobal("fetch", fetchMock);
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipCreateApproval");
|
|
|
|
|
await tool.execute({
|
|
|
|
|
type: "hire_agent",
|
|
|
|
|
payload: { branch: "pap-1167" },
|
|
|
|
|
issueIds: ["44444444-4444-4444-4444-444444444444"],
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(fetchMock).toHaveBeenCalledTimes(1);
|
|
|
|
|
const [url, init] = fetchMock.mock.calls[0] as [string, RequestInit];
|
|
|
|
|
expect(String(url)).toBe(
|
|
|
|
|
"http://localhost:3100/api/companies/11111111-1111-1111-1111-111111111111/approvals",
|
|
|
|
|
);
|
|
|
|
|
expect(init.method).toBe("POST");
|
|
|
|
|
expect(JSON.parse(String(init.body))).toEqual({
|
|
|
|
|
type: "hire_agent",
|
|
|
|
|
payload: { branch: "pap-1167" },
|
|
|
|
|
issueIds: ["44444444-4444-4444-4444-444444444444"],
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
2026-04-06 07:17:48 -05:00
|
|
|
it("rejects invalid generic request paths", async () => {
|
|
|
|
|
vi.stubGlobal("fetch", vi.fn());
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipApiRequest");
|
|
|
|
|
const response = await tool.execute({
|
|
|
|
|
method: "GET",
|
|
|
|
|
path: "issues",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(response.content[0]?.text).toContain("path must start with /");
|
|
|
|
|
});
|
2026-04-06 21:56:13 -05:00
|
|
|
|
|
|
|
|
it("rejects generic request paths that escape /api", async () => {
|
|
|
|
|
vi.stubGlobal("fetch", vi.fn());
|
|
|
|
|
|
|
|
|
|
const tool = getTool("paperclipApiRequest");
|
|
|
|
|
const response = await tool.execute({
|
|
|
|
|
method: "GET",
|
|
|
|
|
path: "/../../secret",
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
expect(response.content[0]?.text).toContain("must not contain '..'");
|
|
|
|
|
});
|
2026-04-06 07:17:48 -05:00
|
|
|
});
|