mirror of
https://github.com/alkimake/paperclip.git
synced 2026-06-16 02:40:39 +09:00
Fix feedback review findings
Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
parent
c0d0d03bce
commit
d12e3e3d1a
7 changed files with 200 additions and 86 deletions
|
|
@ -762,9 +762,11 @@ describe("feedbackService.saveIssueVote", () => {
|
|||
|
||||
expect(localTrace?.status).toBe("local_only");
|
||||
expect(localTrace?.exportId).toBeNull();
|
||||
expect(localTrace?.payloadVersion).toBe("paperclip-feedback-v1");
|
||||
expect(localTrace?.payloadSnapshot?.bundle).toBeNull();
|
||||
expect(sharedTrace?.status).toBe("pending");
|
||||
expect(sharedTrace?.exportId).toMatch(/^fbexp_/);
|
||||
expect(sharedTrace?.payloadVersion).toBe("paperclip-feedback-v1");
|
||||
});
|
||||
|
||||
it("captures Claude project session artifacts as full traces", async () => {
|
||||
|
|
|
|||
128
server/src/__tests__/issue-feedback-routes.test.ts
Normal file
128
server/src/__tests__/issue-feedback-routes.test.ts
Normal file
|
|
@ -0,0 +1,128 @@
|
|||
import express from "express";
|
||||
import request from "supertest";
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { errorHandler } from "../middleware/index.js";
|
||||
import { issueRoutes } from "../routes/issues.js";
|
||||
|
||||
const mockFeedbackService = vi.hoisted(() => ({
|
||||
getFeedbackTraceById: vi.fn(),
|
||||
getFeedbackTraceBundle: vi.fn(),
|
||||
listIssueVotesForUser: vi.fn(),
|
||||
listFeedbackTraces: vi.fn(),
|
||||
saveIssueVote: vi.fn(),
|
||||
}));
|
||||
|
||||
vi.mock("../services/index.js", () => ({
|
||||
accessService: () => ({
|
||||
canUser: vi.fn(),
|
||||
hasPermission: vi.fn(),
|
||||
}),
|
||||
agentService: () => ({
|
||||
getById: vi.fn(),
|
||||
}),
|
||||
documentService: () => ({}),
|
||||
executionWorkspaceService: () => ({}),
|
||||
feedbackService: () => mockFeedbackService,
|
||||
goalService: () => ({}),
|
||||
heartbeatService: () => ({
|
||||
wakeup: vi.fn(async () => undefined),
|
||||
reportRunActivity: vi.fn(async () => undefined),
|
||||
getRun: vi.fn(async () => null),
|
||||
getActiveRunForAgent: vi.fn(async () => null),
|
||||
cancelRun: vi.fn(async () => null),
|
||||
}),
|
||||
instanceSettingsService: () => ({
|
||||
get: vi.fn(async () => ({
|
||||
id: "instance-settings-1",
|
||||
general: {
|
||||
censorUsernameInLogs: false,
|
||||
feedbackDataSharingPreference: "prompt",
|
||||
},
|
||||
})),
|
||||
listCompanyIds: vi.fn(async () => ["company-1"]),
|
||||
}),
|
||||
issueApprovalService: () => ({}),
|
||||
issueService: () => ({
|
||||
getById: vi.fn(),
|
||||
update: vi.fn(),
|
||||
addComment: vi.fn(),
|
||||
findMentionedAgents: vi.fn(),
|
||||
}),
|
||||
logActivity: vi.fn(async () => undefined),
|
||||
projectService: () => ({}),
|
||||
routineService: () => ({
|
||||
syncRunStatusForIssue: vi.fn(async () => undefined),
|
||||
}),
|
||||
workProductService: () => ({}),
|
||||
}));
|
||||
|
||||
function createApp(actor: Record<string, unknown>) {
|
||||
const app = express();
|
||||
app.use(express.json());
|
||||
app.use((req, _res, next) => {
|
||||
(req as any).actor = actor;
|
||||
next();
|
||||
});
|
||||
app.use("/api", issueRoutes({} as any, {} as any));
|
||||
app.use(errorHandler);
|
||||
return app;
|
||||
}
|
||||
|
||||
describe("issue feedback trace routes", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
});
|
||||
|
||||
it("rejects non-board callers before fetching a feedback trace", async () => {
|
||||
const app = createApp({
|
||||
type: "agent",
|
||||
agentId: "agent-1",
|
||||
companyId: "company-1",
|
||||
source: "agent_key",
|
||||
runId: "run-1",
|
||||
});
|
||||
|
||||
const res = await request(app).get("/api/feedback-traces/trace-1");
|
||||
|
||||
expect(res.status).toBe(403);
|
||||
expect(mockFeedbackService.getFeedbackTraceById).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("returns 404 when a board user lacks access to the trace company", async () => {
|
||||
mockFeedbackService.getFeedbackTraceById.mockResolvedValue({
|
||||
id: "trace-1",
|
||||
companyId: "company-2",
|
||||
});
|
||||
const app = createApp({
|
||||
type: "board",
|
||||
userId: "user-1",
|
||||
source: "session",
|
||||
isInstanceAdmin: false,
|
||||
companyIds: ["company-1"],
|
||||
});
|
||||
|
||||
const res = await request(app).get("/api/feedback-traces/trace-1");
|
||||
|
||||
expect(res.status).toBe(404);
|
||||
});
|
||||
|
||||
it("returns 404 for bundle fetches when a board user lacks access to the trace company", async () => {
|
||||
mockFeedbackService.getFeedbackTraceBundle.mockResolvedValue({
|
||||
id: "trace-1",
|
||||
companyId: "company-2",
|
||||
issueId: "issue-1",
|
||||
files: [],
|
||||
});
|
||||
const app = createApp({
|
||||
type: "board",
|
||||
userId: "user-1",
|
||||
source: "session",
|
||||
isInstanceAdmin: false,
|
||||
companyIds: ["company-1"],
|
||||
});
|
||||
|
||||
const res = await request(app).get("/api/feedback-traces/trace-1/bundle");
|
||||
|
||||
expect(res.status).toBe(404);
|
||||
});
|
||||
});
|
||||
|
|
@ -116,6 +116,13 @@ export function issueRoutes(db: Db, storage: StorageService) {
|
|||
return false;
|
||||
}
|
||||
|
||||
function actorCanAccessCompany(req: Request, companyId: string) {
|
||||
if (req.actor.type === "none") return false;
|
||||
if (req.actor.type === "agent") return req.actor.companyId === companyId;
|
||||
if (req.actor.source === "local_implicit" || req.actor.isInstanceAdmin) return true;
|
||||
return (req.actor.companyIds ?? []).includes(companyId);
|
||||
}
|
||||
|
||||
function canCreateAgentsLegacy(agent: { permissions: Record<string, unknown> | null | undefined; role: string }) {
|
||||
if (agent.role === "ceo") return true;
|
||||
if (!agent.permissions || typeof agent.permissions !== "object") return false;
|
||||
|
|
@ -1538,31 +1545,30 @@ export function issueRoutes(db: Db, storage: StorageService) {
|
|||
|
||||
router.get("/feedback-traces/:traceId", async (req, res) => {
|
||||
const traceId = req.params.traceId as string;
|
||||
const trace = await feedback.getFeedbackTraceById(traceId, parseBooleanQuery(req.query.includePayload) || req.query.includePayload === undefined);
|
||||
if (!trace) {
|
||||
res.status(404).json({ error: "Feedback trace not found" });
|
||||
return;
|
||||
}
|
||||
assertCompanyAccess(req, trace.companyId);
|
||||
if (req.actor.type !== "board") {
|
||||
res.status(403).json({ error: "Only board users can view feedback traces" });
|
||||
return;
|
||||
}
|
||||
const includePayload = parseBooleanQuery(req.query.includePayload) || req.query.includePayload === undefined;
|
||||
const trace = await feedback.getFeedbackTraceById(traceId, includePayload);
|
||||
if (!trace || !actorCanAccessCompany(req, trace.companyId)) {
|
||||
res.status(404).json({ error: "Feedback trace not found" });
|
||||
return;
|
||||
}
|
||||
res.json(trace);
|
||||
});
|
||||
|
||||
router.get("/feedback-traces/:traceId/bundle", async (req, res) => {
|
||||
const traceId = req.params.traceId as string;
|
||||
const bundle = await feedback.getFeedbackTraceBundle(traceId);
|
||||
if (!bundle) {
|
||||
res.status(404).json({ error: "Feedback trace not found" });
|
||||
return;
|
||||
}
|
||||
assertCompanyAccess(req, bundle.companyId);
|
||||
if (req.actor.type !== "board") {
|
||||
res.status(403).json({ error: "Only board users can view feedback trace bundles" });
|
||||
return;
|
||||
}
|
||||
const bundle = await feedback.getFeedbackTraceBundle(traceId);
|
||||
if (!bundle || !actorCanAccessCompany(req, bundle.companyId)) {
|
||||
res.status(404).json({ error: "Feedback trace not found" });
|
||||
return;
|
||||
}
|
||||
res.json(bundle);
|
||||
});
|
||||
|
||||
|
|
|
|||
|
|
@ -49,6 +49,7 @@ import { getRunLogStore } from "./run-log-store.js";
|
|||
|
||||
const FEEDBACK_SCHEMA_VERSION = "paperclip-feedback-envelope-v2";
|
||||
const FEEDBACK_BUNDLE_VERSION = "paperclip-feedback-bundle-v2";
|
||||
const FEEDBACK_PAYLOAD_VERSION = "paperclip-feedback-v1";
|
||||
const FEEDBACK_DESTINATION = "paperclip_labs_feedback_v1";
|
||||
const FEEDBACK_CONTEXT_WINDOW = 3;
|
||||
const MAX_EXCERPT_CHARS = 200;
|
||||
|
|
@ -1999,7 +2000,7 @@ export function feedbackService(db: Db, options: FeedbackServiceOptions = {}) {
|
|||
consentVersion: sharedWithLabs ? (consentVersion ?? DEFAULT_FEEDBACK_DATA_SHARING_TERMS_VERSION) : null,
|
||||
schemaVersion: FEEDBACK_SCHEMA_VERSION,
|
||||
bundleVersion: FEEDBACK_BUNDLE_VERSION,
|
||||
payloadVersion: FEEDBACK_BUNDLE_VERSION,
|
||||
payloadVersion: FEEDBACK_PAYLOAD_VERSION,
|
||||
payloadDigest: artifacts.payloadDigest,
|
||||
payloadSnapshot: artifacts.payloadSnapshot,
|
||||
targetSummary: artifacts.targetSummary,
|
||||
|
|
@ -2021,7 +2022,7 @@ export function feedbackService(db: Db, options: FeedbackServiceOptions = {}) {
|
|||
consentVersion: sharedWithLabs ? (consentVersion ?? DEFAULT_FEEDBACK_DATA_SHARING_TERMS_VERSION) : null,
|
||||
schemaVersion: FEEDBACK_SCHEMA_VERSION,
|
||||
bundleVersion: FEEDBACK_BUNDLE_VERSION,
|
||||
payloadVersion: FEEDBACK_BUNDLE_VERSION,
|
||||
payloadVersion: FEEDBACK_PAYLOAD_VERSION,
|
||||
payloadDigest: artifacts.payloadDigest,
|
||||
payloadSnapshot: artifacts.payloadSnapshot,
|
||||
targetSummary: artifacts.targetSummary,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue