Sync/master post pap1497 followups 2026 04 15 (#3779)

## Thinking Path

> - Paperclip orchestrates AI agents for zero-human companies
> - The board depends on issue, inbox, cost, and company-skill surfaces
to stay accurate and fast while agents are actively working
> - The PAP-1497 follow-up branch exposed a few rough edges in those
surfaces: stale active-run state on completed issues, missing creator
filters, oversized issue payload scans, and placeholder issue-route
parsing
> - Those gaps make the control plane harder to trust because operators
can see misleading run state, miss the right subset of work, or pay
extra query/render cost on large issue records
> - This pull request tightens those follow-ups across server and UI
code, and adds regression coverage for the affected paths
> - The benefit is a more reliable issue workflow, safer high-volume
cost aggregation, and clearer board/operator navigation

## What Changed

- Added the `v2026.415.0` release changelog entry.
- Fixed stale issue-run presentation after completion and reused the
shared issue-path parser so literal route placeholders no longer become
issue links.
- Added creator filters to the Issues page and Inbox, including
persisted filter-state normalization and regression coverage.
- Bounded issue detail/list project-mention scans and trimmed large
issue-list payload fields to keep issue reads lighter.
- Hardened company-skill list projection and cost/finance aggregation so
large markdown blobs and large summed values do not leak into list
responses or overflow 32-bit casts.
- Added targeted server/UI regression tests for company skills,
costs/finance, issue mention scanning, creator filters, inbox
normalization, and issue reference parsing.

## Verification

- `pnpm exec vitest run
server/src/__tests__/company-skills-service.test.ts
server/src/__tests__/costs-service.test.ts
server/src/__tests__/issues-goal-context-routes.test.ts
server/src/__tests__/issues-service.test.ts ui/src/lib/inbox.test.ts
ui/src/lib/issue-filters.test.ts ui/src/lib/issue-reference.test.ts`
- `gh pr checks 3779`
Current pass set on the PR head: `policy`, `verify`, `e2e`,
`security/snyk (cryppadotta)`, `Greptile Review`

## Risks

- Creator filter options are derived from the currently loaded
issue/agent data, so very sparse result sets may not surface every
historical creator until they appear in the active dataset.
- Cost/finance aggregate casts now use `double precision`; that removes
the current overflow risk, but future schema changes should keep
large-value aggregation behavior under review.
- Issue detail mention scanning now skips comment-body scans on the
detail route, so any consumer that relied on comment-only project
mentions there would need to fetch them separately.

## Model Used

- OpenAI Codex, GPT-5-based coding agent with terminal tool use and
local code execution in the Paperclip workspace. Exact internal model
ID/context-window exposure is not surfaced in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
Dotta 2026-04-15 21:13:56 -05:00 committed by GitHub
parent d4c3899ca4
commit 5f45712846
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
26 changed files with 998 additions and 108 deletions

View file

@ -1,6 +1,15 @@
import express from "express";
import request from "supertest";
import { beforeEach, describe, expect, it, vi } from "vitest";
import { afterAll, afterEach, beforeAll } from "vitest";
import { randomUUID } from "node:crypto";
import { createDb, companies, agents, costEvents, financeEvents, projects } from "@paperclipai/db";
import { costService } from "../services/costs.ts";
import { financeService } from "../services/finance.ts";
import {
getEmbeddedPostgresTestSupport,
startEmbeddedPostgresTestDatabase,
} from "./helpers/embedded-postgres.js";
function makeDb(overrides: Record<string, unknown> = {}) {
const selectChain = {
@ -230,3 +239,154 @@ describe("cost routes", () => {
expect(mockAgentService.update).not.toHaveBeenCalled();
});
});
const embeddedPostgresSupport = await getEmbeddedPostgresTestSupport();
const describeEmbeddedPostgres = embeddedPostgresSupport.supported ? describe : describe.skip;
describeEmbeddedPostgres("cost and finance aggregate overflow handling", () => {
let db!: ReturnType<typeof createDb>;
let costs!: ReturnType<typeof costService>;
let finance!: ReturnType<typeof financeService>;
let tempDb: Awaited<ReturnType<typeof startEmbeddedPostgresTestDatabase>> | null = null;
beforeAll(async () => {
tempDb = await startEmbeddedPostgresTestDatabase("paperclip-costs-service-");
db = createDb(tempDb.connectionString);
costs = costService(db);
finance = financeService(db);
}, 20_000);
afterEach(async () => {
await db.delete(financeEvents);
await db.delete(costEvents);
await db.delete(projects);
await db.delete(agents);
await db.delete(companies);
});
afterAll(async () => {
await tempDb?.cleanup();
});
it("aggregates cost event sums above int32 without raising Postgres integer overflow", async () => {
const companyId = randomUUID();
const agentId = randomUUID();
const projectId = randomUUID();
await db.insert(companies).values({
id: companyId,
name: "Paperclip",
issuePrefix: `T${companyId.replace(/-/g, "").slice(0, 6).toUpperCase()}`,
requireBoardApprovalForNewAgents: false,
});
await db.insert(agents).values({
id: agentId,
companyId,
name: "Cost Agent",
role: "engineer",
status: "active",
adapterType: "codex_local",
adapterConfig: {},
runtimeConfig: {},
permissions: {},
});
await db.insert(projects).values({
id: projectId,
companyId,
name: "Overflow Project",
status: "active",
});
await db.insert(costEvents).values([
{
companyId,
agentId,
projectId,
provider: "openai",
biller: "openai",
billingType: "metered_api",
model: "gpt-5",
inputTokens: 2_000_000_000,
cachedInputTokens: 0,
outputTokens: 200_000_000,
costCents: 2_000_000_000,
occurredAt: new Date("2026-04-10T00:00:00.000Z"),
},
{
companyId,
agentId,
projectId,
provider: "openai",
biller: "openai",
billingType: "metered_api",
model: "gpt-5",
inputTokens: 2_000_000_000,
cachedInputTokens: 10,
outputTokens: 200_000_000,
costCents: 2_000_000_000,
occurredAt: new Date("2026-04-11T00:00:00.000Z"),
},
]);
const range = {
from: new Date("2026-04-01T00:00:00.000Z"),
to: new Date("2026-04-15T23:59:59.999Z"),
};
const [byAgentRow] = await costs.byAgent(companyId, range);
const [byProjectRow] = await costs.byProject(companyId, range);
const [byAgentModelRow] = await costs.byAgentModel(companyId, range);
expect(byAgentRow?.costCents).toBe(4_000_000_000);
expect(byAgentRow?.inputTokens).toBe(4_000_000_000);
expect(byProjectRow?.costCents).toBe(4_000_000_000);
expect(byAgentModelRow?.costCents).toBe(4_000_000_000);
});
it("aggregates finance event sums above int32 without raising Postgres integer overflow", async () => {
const companyId = randomUUID();
await db.insert(companies).values({
id: companyId,
name: "Paperclip",
issuePrefix: `T${companyId.replace(/-/g, "").slice(0, 6).toUpperCase()}`,
requireBoardApprovalForNewAgents: false,
});
await db.insert(financeEvents).values([
{
companyId,
biller: "openai",
eventKind: "invoice",
amountCents: 2_000_000_000,
currency: "USD",
direction: "debit",
estimated: false,
occurredAt: new Date("2026-04-10T00:00:00.000Z"),
},
{
companyId,
biller: "openai",
eventKind: "invoice",
amountCents: 2_000_000_000,
currency: "USD",
direction: "debit",
estimated: true,
occurredAt: new Date("2026-04-11T00:00:00.000Z"),
},
]);
const range = {
from: new Date("2026-04-01T00:00:00.000Z"),
to: new Date("2026-04-15T23:59:59.999Z"),
};
const summary = await finance.summary(companyId, range);
const [byKindRow] = await finance.byKind(companyId, range);
expect(summary.debitCents).toBe(4_000_000_000);
expect(summary.estimatedDebitCents).toBe(2_000_000_000);
expect(byKindRow?.debitCents).toBe(4_000_000_000);
expect(byKindRow?.netCents).toBe(4_000_000_000);
});
});