7f893ac4ec
## Thinking Path > - Paperclip orchestrates AI agents for zero-human companies > - Reliable execution depends on heartbeat routing, issue lifecycle semantics, telemetry, and a fast enough local verification loop to keep regressions visible > - The remaining commits on this branch were mostly server/runtime correctness fixes plus test and documentation follow-ups in that area > - Those changes are logically separate from the UI-focused issue-detail and workspace/navigation branches even when they touch overlapping issue APIs > - This pull request groups the execution reliability, heartbeat, telemetry, and tooling changes into one standalone branch > - The benefit is a focused review of the control-plane correctness work, including the follow-up fix that restored the implicit comment-reopen helpers after branch splitting ## What Changed - Hardened issue/heartbeat execution behavior, including self-review stage skipping, deferred mention wakes during active execution, stranded execution recovery, active-run scoping, assignee resolution, and blocked-to-todo wake resumption - Reduced noisy polling/logging overhead by trimming issue run payloads, compacting persisted run logs, silencing high-volume request logs, and capping heartbeat-run queries in dashboard/inbox surfaces - Expanded telemetry and status semantics with adapter/model fields on task completion plus clearer status guidance in docs/onboarding material - Updated test infrastructure and verification defaults with faster route-test module isolation, cheaper default `pnpm test`, e2e isolation from local state, and repo verification follow-ups - Included docs/release housekeeping from the branch and added a small follow-up commit restoring the implicit comment-reopen helpers that were dropped during branch reconstruction ## Verification - `pnpm vitest run server/src/__tests__/issue-comment-reopen-routes.test.ts server/src/__tests__/issue-telemetry-routes.test.ts` - `pnpm vitest run server/src/__tests__/http-log-policy.test.ts server/src/__tests__/heartbeat-run-log.test.ts server/src/__tests__/health.test.ts` - `server/src/__tests__/activity-service.test.ts`, `server/src/__tests__/heartbeat-comment-wake-batching.test.ts`, and `server/src/__tests__/heartbeat-process-recovery.test.ts` were attempted on this host but the embedded Postgres harness reported init-script/data-dir problems and skipped or failed to start, so they are noted as environment-limited ## Risks - Medium: this branch changes core issue/heartbeat routing and reopen/wakeup behavior, so regressions would affect agent execution flow rather than isolated UI polish - Because it also updates verification infrastructure, reviewers should pay attention to whether the new tests are asserting the right failure modes and not just reshaping harness behavior ## Model Used - OpenAI Codex coding agent (GPT-5-class runtime in Codex CLI; exact deployed model ID is not exposed in this environment), reasoning enabled, tool use and local code execution enabled ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [ ] If this change affects the UI, I have included before/after screenshots - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
80 lines
2.7 KiB
TypeScript
80 lines
2.7 KiB
TypeScript
import { describe, expect, it, vi } from "vitest";
|
|
import express from "express";
|
|
import request from "supertest";
|
|
import { privateHostnameGuard } from "../middleware/private-hostname-guard.js";
|
|
|
|
const unknownHostname = "blocked-host.invalid";
|
|
|
|
function createApp(opts: { enabled: boolean; allowedHostnames?: string[]; bindHost?: string }) {
|
|
const app = express();
|
|
app.use(
|
|
privateHostnameGuard({
|
|
enabled: opts.enabled,
|
|
allowedHostnames: opts.allowedHostnames ?? [],
|
|
bindHost: opts.bindHost ?? "0.0.0.0",
|
|
}),
|
|
);
|
|
app.get("/api/health", (_req, res) => {
|
|
res.status(200).json({ status: "ok" });
|
|
});
|
|
app.get("/dashboard", (_req, res) => {
|
|
res.status(200).send("ok");
|
|
});
|
|
return app;
|
|
}
|
|
|
|
describe("privateHostnameGuard", () => {
|
|
it("allows requests when disabled", async () => {
|
|
const app = createApp({ enabled: false });
|
|
const res = await request(app).get("/api/health").set("Host", "dotta-macbook-pro:3100");
|
|
expect(res.status).toBe(200);
|
|
});
|
|
|
|
it("allows loopback hostnames", async () => {
|
|
const app = createApp({ enabled: true });
|
|
const res = await request(app).get("/api/health").set("Host", "localhost:3100");
|
|
expect(res.status).toBe(200);
|
|
});
|
|
|
|
it("allows explicitly configured hostnames", async () => {
|
|
const app = createApp({ enabled: true, allowedHostnames: ["dotta-macbook-pro"] });
|
|
const res = await request(app).get("/api/health").set("Host", "dotta-macbook-pro:3100");
|
|
expect(res.status).toBe(200);
|
|
});
|
|
|
|
it("blocks unknown hostnames with remediation command", async () => {
|
|
const app = createApp({ enabled: true, allowedHostnames: ["some-other-host"] });
|
|
const res = await request(app).get("/api/health").set("Host", `${unknownHostname}:3100`);
|
|
expect(res.status).toBe(403);
|
|
expect(res.body?.error).toContain(`please run pnpm paperclipai allowed-hostname ${unknownHostname}`);
|
|
});
|
|
|
|
it("blocks unknown hostnames on page routes with plain-text remediation command", async () => {
|
|
const middleware = privateHostnameGuard({
|
|
enabled: true,
|
|
allowedHostnames: ["some-other-host"],
|
|
bindHost: "0.0.0.0",
|
|
});
|
|
const req = {
|
|
path: "/dashboard",
|
|
header: (name: string) => (name.toLowerCase() === "host" ? `${unknownHostname}:3100` : undefined),
|
|
accepts: () => "html",
|
|
} as any;
|
|
const res = {
|
|
status: vi.fn().mockReturnThis(),
|
|
type: vi.fn().mockReturnThis(),
|
|
send: vi.fn(),
|
|
json: vi.fn(),
|
|
} as any;
|
|
const next = vi.fn();
|
|
|
|
middleware(req, res, next);
|
|
|
|
expect(next).not.toHaveBeenCalled();
|
|
expect(res.status).toHaveBeenCalledWith(403);
|
|
expect(res.send).toHaveBeenCalledWith(
|
|
expect.stringContaining(`please run pnpm paperclipai allowed-hostname ${unknownHostname}`),
|
|
);
|
|
}, 20_000);
|
|
});
|