mirror of
https://github.com/alkimake/paperclip.git
synced 2026-06-17 03:10:38 +09:00
[codex] Add routine env secrets support (#6212)
## Thinking Path > - Paperclip orchestrates AI agents for zero-human companies. > - Scheduled routines are the control-plane path for recurring agent work. > - Routines already had dispatch/history, but their runtime environment did not carry routine-owned secret bindings through execution. > - Operators need routine-specific secrets that can override project/agent env without exposing secret values in history, logs, or access events. > - This pull request adds the routine env runtime contract, wires it into execution, and makes the routine UI/history surfaces show safe secret metadata. > - The benefit is that routine executions can use scoped secret refs predictably while preserving company boundaries and auditability. ## What Changed - Added routine env persistence/runtime support, including `routines.env`, `routine_runs.routine_revision_id`, revision snapshots, and idempotent migration `0086_routine_env_runtime_contract`. - Resolved routine env during heartbeat adapter config assembly with precedence `agent < project < routine` and secret access events recorded against the routine consumer. - Added secret binding synchronization for routine create/update/restore flows and guarded cross-company, missing, disabled, and deleted secret cases. - Added a Secrets tab to routine detail, env/secret history diff rendering, and Storybook coverage for the new UI states. - Added server/UI regression tests, including an embedded-Postgres QA path for routine secret execution and restore behavior. - Updated implementation/database docs for routine env and secret-binding behavior. ## Verification - `pnpm install --frozen-lockfile` after rebasing onto `public-gh/master` to refresh workspace links for the newly-added upstream Grok adapter package. - `pnpm exec vitest run server/src/__tests__/heartbeat-project-env.test.ts server/src/__tests__/routines-service.test.ts server/src/__tests__/secrets-service.test.ts server/src/__tests__/qa-routine-secrets-e2e.test.ts ui/src/components/RoutineHistoryTab.test.tsx` passed: 5 files, 92 tests. - `pnpm -r typecheck` passed across the workspace. - `pnpm build` passed. Vite emitted the existing large-chunk/dynamic-import warnings. - UI screenshots were captured locally during QA in `artifacts/pap-9521/` and `artifacts/pap-9522/`; generated screenshots are not committed to avoid adding binary artifacts to the repo. ## Risks - Migration risk is limited by `IF NOT EXISTS` guards for the new columns, FK, and index, and the migration is ordered as `0086` immediately after upstream `0085`. - Runtime behavior changes env precedence for routine executions by adding routine env as the highest-precedence layer; tests cover agent/project/routine precedence. - Secret handling is security-sensitive; tests cover value-free manifests/events/errors, disabled/missing/deleted secrets, and cross-company rejection. - UI history now renders routine env/secret diffs; tests and Storybook stories cover the main rendering paths. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex coding agent based on GPT-5, with shell/tool use and medium reasoning effort. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] If this change affects the UI, I have included before/after screenshots - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
parent
3e6610fb93
commit
705c1b8d81
20 changed files with 1736 additions and 50 deletions
|
|
@ -366,6 +366,8 @@ function createRoutineDispatchFingerprint(input: {
|
|||
payload: Record<string, unknown> | null;
|
||||
projectId: string | null;
|
||||
assigneeAgentId: string | null;
|
||||
routineRevisionId: string | null;
|
||||
routineEnvFingerprint: string | null;
|
||||
executionWorkspaceId?: string | null;
|
||||
executionWorkspacePreference?: string | null;
|
||||
executionWorkspaceSettings?: Record<string, unknown> | null;
|
||||
|
|
@ -376,6 +378,11 @@ function createRoutineDispatchFingerprint(input: {
|
|||
return crypto.createHash("sha256").update(canonical).digest("hex");
|
||||
}
|
||||
|
||||
function createRoutineEnvFingerprint(env: unknown) {
|
||||
const canonical = JSON.stringify(normalizeRoutineDispatchFingerprintValue(env ?? null));
|
||||
return crypto.createHash("sha256").update(canonical).digest("hex");
|
||||
}
|
||||
|
||||
function readManagedRoutineIssueTemplate(defaultsJson: Record<string, unknown> | null | undefined) {
|
||||
const value = defaultsJson?.issueTemplate;
|
||||
if (!isPlainRecord(value)) return null;
|
||||
|
|
@ -406,6 +413,7 @@ function routineRevisionSnapshotRoutine(routine: RoutineRow): RoutineRevisionSna
|
|||
concurrencyPolicy: routine.concurrencyPolicy as RoutineRevisionSnapshotV1["routine"]["concurrencyPolicy"],
|
||||
catchUpPolicy: routine.catchUpPolicy as RoutineRevisionSnapshotV1["routine"]["catchUpPolicy"],
|
||||
variables: routine.variables ?? [],
|
||||
env: routine.env ?? null,
|
||||
};
|
||||
}
|
||||
|
||||
|
|
@ -686,6 +694,7 @@ export function routineService(
|
|||
idempotencyKey: routineRuns.idempotencyKey,
|
||||
triggerPayload: routineRuns.triggerPayload,
|
||||
dispatchFingerprint: routineRuns.dispatchFingerprint,
|
||||
routineRevisionId: routineRuns.routineRevisionId,
|
||||
linkedIssueId: routineRuns.linkedIssueId,
|
||||
coalescedIntoRunId: routineRuns.coalescedIntoRunId,
|
||||
failureReason: routineRuns.failureReason,
|
||||
|
|
@ -719,6 +728,7 @@ export function routineService(
|
|||
idempotencyKey: row.idempotencyKey,
|
||||
triggerPayload: row.triggerPayload as Record<string, unknown> | null,
|
||||
dispatchFingerprint: row.dispatchFingerprint,
|
||||
routineRevisionId: row.routineRevisionId,
|
||||
linkedIssueId: row.linkedIssueId,
|
||||
coalescedIntoRunId: row.coalescedIntoRunId,
|
||||
failureReason: row.failureReason,
|
||||
|
|
@ -1138,6 +1148,8 @@ export function routineService(
|
|||
payload: triggerPayload,
|
||||
projectId,
|
||||
assigneeAgentId,
|
||||
routineRevisionId: input.routine.latestRevisionId,
|
||||
routineEnvFingerprint: createRoutineEnvFingerprint(input.routine.env),
|
||||
executionWorkspaceId: input.executionWorkspaceId ?? null,
|
||||
executionWorkspacePreference: input.executionWorkspacePreference ?? null,
|
||||
executionWorkspaceSettings: input.executionWorkspaceSettings ?? null,
|
||||
|
|
@ -1183,6 +1195,7 @@ export function routineService(
|
|||
idempotencyKey: input.idempotencyKey ?? null,
|
||||
triggerPayload,
|
||||
dispatchFingerprint,
|
||||
routineRevisionId: input.routine.latestRevisionId,
|
||||
})
|
||||
.returning();
|
||||
|
||||
|
|
@ -1430,6 +1443,7 @@ export function routineService(
|
|||
idempotencyKey: routineRuns.idempotencyKey,
|
||||
triggerPayload: routineRuns.triggerPayload,
|
||||
dispatchFingerprint: routineRuns.dispatchFingerprint,
|
||||
routineRevisionId: routineRuns.routineRevisionId,
|
||||
linkedIssueId: routineRuns.linkedIssueId,
|
||||
coalescedIntoRunId: routineRuns.coalescedIntoRunId,
|
||||
failureReason: routineRuns.failureReason,
|
||||
|
|
@ -1462,6 +1476,7 @@ export function routineService(
|
|||
idempotencyKey: run.idempotencyKey,
|
||||
triggerPayload: run.triggerPayload as Record<string, unknown> | null,
|
||||
dispatchFingerprint: run.dispatchFingerprint,
|
||||
routineRevisionId: run.routineRevisionId,
|
||||
linkedIssueId: run.linkedIssueId,
|
||||
coalescedIntoRunId: run.coalescedIntoRunId,
|
||||
failureReason: run.failureReason,
|
||||
|
|
@ -1508,13 +1523,19 @@ export function routineService(
|
|||
await assertAssignableAgent(companyId, input.assigneeAgentId ?? null);
|
||||
if (input.goalId) await assertGoal(companyId, input.goalId);
|
||||
if (input.parentIssueId) await assertParentIssue(companyId, input.parentIssueId);
|
||||
const env = input.env === undefined || input.env === null
|
||||
? null
|
||||
: await secretsSvc.normalizeEnvBindingsForPersistence(companyId, input.env, {
|
||||
strictMode: process.env.PAPERCLIP_SECRETS_STRICT_MODE === "true",
|
||||
fieldPath: "env",
|
||||
});
|
||||
const variables = syncRoutineVariablesWithTemplate(
|
||||
[input.title, input.description],
|
||||
sanitizeRoutineVariableInputs(input.variables),
|
||||
);
|
||||
assertRoutineVariableDefinitions(variables);
|
||||
const status = normalizeDraftRoutineStatus(input.status, input.assigneeAgentId);
|
||||
return db.transaction(async (tx) => {
|
||||
const createdRoutine = await db.transaction(async (tx) => {
|
||||
const txDb = tx as unknown as Db;
|
||||
const [created] = await txDb
|
||||
.insert(routines)
|
||||
|
|
@ -1531,6 +1552,7 @@ export function routineService(
|
|||
concurrencyPolicy: input.concurrencyPolicy,
|
||||
catchUpPolicy: input.catchUpPolicy,
|
||||
variables,
|
||||
env,
|
||||
createdByAgentId: actor.agentId ?? null,
|
||||
createdByUserId: actor.userId ?? null,
|
||||
updatedByAgentId: actor.agentId ?? null,
|
||||
|
|
@ -1540,8 +1562,17 @@ export function routineService(
|
|||
const { routine } = await appendRoutineRevision(txDb, created, actor, {
|
||||
changeSummary: "Created routine",
|
||||
});
|
||||
if (env) {
|
||||
await secretsSvc.syncEnvBindingsForTarget(
|
||||
companyId,
|
||||
{ targetType: "routine", targetId: routine.id },
|
||||
env,
|
||||
{ db: tx },
|
||||
);
|
||||
}
|
||||
return routine;
|
||||
});
|
||||
return createdRoutine;
|
||||
},
|
||||
|
||||
update: async (id: string, patch: UpdateRoutine, actor: Actor): Promise<Routine | null> => {
|
||||
|
|
@ -1551,6 +1582,14 @@ export function routineService(
|
|||
const nextAssigneeAgentId = patch.assigneeAgentId === undefined ? existing.assigneeAgentId : patch.assigneeAgentId;
|
||||
const nextTitle = patch.title ?? existing.title;
|
||||
const nextDescription = patch.description === undefined ? existing.description : patch.description;
|
||||
const nextEnv = patch.env === undefined
|
||||
? existing.env
|
||||
: patch.env === null
|
||||
? null
|
||||
: await secretsSvc.normalizeEnvBindingsForPersistence(existing.companyId, patch.env, {
|
||||
strictMode: process.env.PAPERCLIP_SECRETS_STRICT_MODE === "true",
|
||||
fieldPath: "env",
|
||||
});
|
||||
const requestedStatus = patch.status ?? existing.status;
|
||||
if (patch.status === "active") {
|
||||
assertRoutineCanEnable(patch.status, nextAssigneeAgentId);
|
||||
|
|
@ -1582,7 +1621,7 @@ export function routineService(
|
|||
if (enabledScheduleTriggers) {
|
||||
assertScheduleCompatibleVariables(nextVariables);
|
||||
}
|
||||
return db.transaction(async (tx) => {
|
||||
const updatedRoutine = await db.transaction(async (tx) => {
|
||||
const txDb = tx as unknown as Db;
|
||||
await tx.execute(sql`select id from ${routines} where ${routines.id} = ${id} for update`);
|
||||
const locked = await txDb
|
||||
|
|
@ -1611,6 +1650,7 @@ export function routineService(
|
|||
concurrencyPolicy: patch.concurrencyPolicy ?? locked.concurrencyPolicy,
|
||||
catchUpPolicy: patch.catchUpPolicy ?? locked.catchUpPolicy,
|
||||
variables: nextVariables,
|
||||
env: nextEnv,
|
||||
updatedByAgentId: actor.agentId ?? null,
|
||||
updatedByUserId: actor.userId ?? null,
|
||||
};
|
||||
|
|
@ -1633,6 +1673,14 @@ export function routineService(
|
|||
)
|
||||
.then((rows) => rows[0] ?? null);
|
||||
if (latestRevision && snapshotsMatch(nextSnapshot, latestRevision.snapshot as RoutineRevisionSnapshotV1)) {
|
||||
if (patch.env !== undefined) {
|
||||
await secretsSvc.syncEnvBindingsForTarget(
|
||||
locked.companyId,
|
||||
{ targetType: "routine", targetId: locked.id },
|
||||
candidate.env,
|
||||
{ db: tx },
|
||||
);
|
||||
}
|
||||
return locked;
|
||||
}
|
||||
}
|
||||
|
|
@ -1651,6 +1699,7 @@ export function routineService(
|
|||
concurrencyPolicy: candidate.concurrencyPolicy,
|
||||
catchUpPolicy: candidate.catchUpPolicy,
|
||||
variables: candidate.variables,
|
||||
env: candidate.env,
|
||||
updatedByAgentId: actor.agentId ?? null,
|
||||
updatedByUserId: actor.userId ?? null,
|
||||
updatedAt: new Date(),
|
||||
|
|
@ -1661,8 +1710,17 @@ export function routineService(
|
|||
const { routine } = await appendRoutineRevision(txDb, updated, actor, {
|
||||
changeSummary: "Updated routine",
|
||||
});
|
||||
if (patch.env !== undefined) {
|
||||
await secretsSvc.syncEnvBindingsForTarget(
|
||||
routine.companyId,
|
||||
{ targetType: "routine", targetId: routine.id },
|
||||
routine.env,
|
||||
{ db: tx },
|
||||
);
|
||||
}
|
||||
return routine;
|
||||
});
|
||||
return updatedRoutine;
|
||||
},
|
||||
|
||||
createTrigger: async (
|
||||
|
|
@ -1770,7 +1828,7 @@ export function routineService(
|
|||
}
|
||||
}
|
||||
|
||||
return db.transaction(async (tx) => {
|
||||
const result = await db.transaction(async (tx) => {
|
||||
const txDb = tx as unknown as Db;
|
||||
await tx.execute(sql`select id from ${routines} where ${routines.id} = ${existing.routineId} for update`);
|
||||
const [updated] = await txDb
|
||||
|
|
@ -1801,12 +1859,13 @@ export function routineService(
|
|||
});
|
||||
return { trigger: updated as RoutineTrigger, revision: appended.revision };
|
||||
});
|
||||
return result;
|
||||
},
|
||||
|
||||
deleteTrigger: async (id: string, actor: Actor = {}): Promise<{ deleted: boolean; revision: RoutineRevision | null }> => {
|
||||
const existing = await getTriggerById(id);
|
||||
if (!existing) return { deleted: false, revision: null };
|
||||
return db.transaction(async (tx) => {
|
||||
const result = await db.transaction(async (tx) => {
|
||||
const txDb = tx as unknown as Db;
|
||||
await tx.execute(sql`select id from ${routines} where ${routines.id} = ${existing.routineId} for update`);
|
||||
await txDb.delete(routineTriggers).where(eq(routineTriggers.id, id));
|
||||
|
|
@ -1821,6 +1880,7 @@ export function routineService(
|
|||
});
|
||||
return { deleted: true, revision: appended.revision };
|
||||
});
|
||||
return result;
|
||||
},
|
||||
|
||||
rotateTriggerSecret: async (
|
||||
|
|
@ -1912,7 +1972,7 @@ export function routineService(
|
|||
const routineSnapshot = snapshot.routine;
|
||||
await assertRestorableAssignee(existingRoutine.companyId, routineSnapshot.assigneeAgentId, actor);
|
||||
|
||||
return db.transaction(async (tx) => {
|
||||
const result = await db.transaction(async (tx) => {
|
||||
const txDb = tx as unknown as Db;
|
||||
await tx.execute(sql`select id from ${routines} where ${routines.id} = ${existingRoutine.id} for update`);
|
||||
const locked = await txDb
|
||||
|
|
@ -1964,6 +2024,7 @@ export function routineService(
|
|||
concurrencyPolicy: routineSnapshot.concurrencyPolicy,
|
||||
catchUpPolicy: routineSnapshot.catchUpPolicy,
|
||||
variables: routineSnapshot.variables,
|
||||
env: routineSnapshot.env,
|
||||
updatedByAgentId: actor.agentId ?? null,
|
||||
updatedByUserId: actor.userId ?? null,
|
||||
updatedAt: now,
|
||||
|
|
@ -2033,6 +2094,12 @@ export function routineService(
|
|||
changeSummary: `Restored from revision ${targetRevision.revisionNumber}`,
|
||||
restoredFromRevisionId: targetRevision.id,
|
||||
});
|
||||
await secretsSvc.syncEnvBindingsForTarget(
|
||||
locked.companyId,
|
||||
{ targetType: "routine", targetId: locked.id },
|
||||
routineSnapshot.env,
|
||||
{ db: tx },
|
||||
);
|
||||
return {
|
||||
routine: appended.routine,
|
||||
revision: appended.revision,
|
||||
|
|
@ -2041,6 +2108,7 @@ export function routineService(
|
|||
secretMaterials: [...recreatedWebhookSecrets.values()].map((entry) => entry.secretMaterial),
|
||||
};
|
||||
});
|
||||
return result;
|
||||
},
|
||||
|
||||
runRoutine: async (id: string, input: RunRoutine, actor?: Actor) => {
|
||||
|
|
@ -2172,6 +2240,7 @@ export function routineService(
|
|||
idempotencyKey: routineRuns.idempotencyKey,
|
||||
triggerPayload: routineRuns.triggerPayload,
|
||||
dispatchFingerprint: routineRuns.dispatchFingerprint,
|
||||
routineRevisionId: routineRuns.routineRevisionId,
|
||||
linkedIssueId: routineRuns.linkedIssueId,
|
||||
coalescedIntoRunId: routineRuns.coalescedIntoRunId,
|
||||
failureReason: routineRuns.failureReason,
|
||||
|
|
@ -2204,6 +2273,7 @@ export function routineService(
|
|||
idempotencyKey: row.idempotencyKey,
|
||||
triggerPayload: row.triggerPayload as Record<string, unknown> | null,
|
||||
dispatchFingerprint: row.dispatchFingerprint,
|
||||
routineRevisionId: row.routineRevisionId,
|
||||
linkedIssueId: row.linkedIssueId,
|
||||
coalescedIntoRunId: row.coalescedIntoRunId,
|
||||
failureReason: row.failureReason,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue