ece8a51e22
## Thinking Path > - Paperclip orchestrates AI agents for zero-human companies. > - This branch accumulated multiple already-tested control-plane, adapter runtime, invite, workspace, plugin, and UI quality fixes on the primary Paperclip checkout. > - `origin/master` advanced while those commits were still local, so the branch needed to be preserved and reconciled before review. > - Splitting the branch commit-by-commit against the new base produced overlapping conflicts with recently merged upstream PRs. > - This pull request keeps the remaining branch as one standalone PR because the final diff is 38 files after removing screenshot artifacts, under Greptile's 100-file cap, and can be merged independently after review. > - The benefit is that none of the local work is lost, the branch is now based on current `origin/master`, and reviewers can evaluate the reconciled changes in one place. ## What Changed - Merged the local accumulated branch with current `origin/master` and resolved the invite-flow overlaps from the newer upstream companies query helper. - Preserved the local fixes for invite existing-member behavior, invite link copy fallback, reusable workspace selection, worktree auth, static SPA fallback, markdown wrapping, plugin slot registration, cloud upstream UX/server polish, project sorting, and related tests. - Removed screenshot artifacts from the PR per review request. - Kept the PR under the requested file limit: 38 files changed, with no `pnpm-lock.yaml` or `.github/workflows/*` changes. ## Verification - `NODE_ENV=test pnpm exec vitest run ui/src/pages/CompanyInvites.test.tsx ui/src/pages/InviteLanding.test.tsx ui/src/pages/Projects.test.tsx ui/src/plugins/slots.test.ts ui/src/components/MarkdownBody.test.tsx server/src/__tests__/invite-accept-existing-member.test.ts server/src/__tests__/static-index-html.test.ts server/src/__tests__/execution-workspaces-service.test.ts server/src/__tests__/better-auth.test.ts server/src/__tests__/worktree-config.test.ts` - `NODE_ENV=test pnpm --filter @paperclipai/ui typecheck` - `NODE_ENV=test pnpm --filter @paperclipai/server typecheck` - Confirmed `git diff --name-only origin/master...HEAD | wc -l` is `38`. - Confirmed no PR diff entries match `pnpm-lock.yaml`, `.github/workflows/*`, or `screenshots/*`. ## Risks - Medium review risk because this is a bundled rescue PR rather than several narrow feature PRs. - Invite flow and company cache behavior overlapped with newer upstream changes; the merge resolution intentionally keeps the shared `companiesListQueryOptions` helper while preserving local existing-member invite behavior. - Visual review evidence is no longer attached in-repo because screenshots were removed from this PR per review request. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, GPT-5-based coding agent, with repository tool access, terminal execution, and git/GitHub CLI operations. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] UI screenshots were intentionally removed from this PR per review request - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> Co-authored-by: CodexCoder <codexcoder@paperclip.local>
160 lines
5.9 KiB
TypeScript
160 lines
5.9 KiB
TypeScript
import { afterEach, describe, expect, it } from "vitest";
|
|
import type { BetterAuthOptions } from "better-auth";
|
|
import { getCookies } from "better-auth/cookies";
|
|
import {
|
|
buildBetterAuthAdvancedOptions,
|
|
deriveAuthCookiePrefix,
|
|
deriveAuthTrustedOrigins,
|
|
shouldDisableSecureAuthCookies,
|
|
} from "../auth/better-auth.js";
|
|
|
|
const ORIGINAL_INSTANCE_ID = process.env.PAPERCLIP_INSTANCE_ID;
|
|
const ORIGINAL_PUBLIC_URL = process.env.PAPERCLIP_PUBLIC_URL;
|
|
|
|
afterEach(() => {
|
|
if (ORIGINAL_INSTANCE_ID === undefined) delete process.env.PAPERCLIP_INSTANCE_ID;
|
|
else process.env.PAPERCLIP_INSTANCE_ID = ORIGINAL_INSTANCE_ID;
|
|
if (ORIGINAL_PUBLIC_URL === undefined) delete process.env.PAPERCLIP_PUBLIC_URL;
|
|
else process.env.PAPERCLIP_PUBLIC_URL = ORIGINAL_PUBLIC_URL;
|
|
});
|
|
|
|
describe("Better Auth cookie scoping", () => {
|
|
it("derives an instance-scoped cookie prefix", () => {
|
|
expect(deriveAuthCookiePrefix("default")).toBe("paperclip-default");
|
|
expect(deriveAuthCookiePrefix("PAP-1601-worktree")).toBe("paperclip-PAP-1601-worktree");
|
|
});
|
|
|
|
it("uses PAPERCLIP_INSTANCE_ID for the Better Auth cookie prefix", () => {
|
|
process.env.PAPERCLIP_INSTANCE_ID = "sat-worktree";
|
|
|
|
const advanced = buildBetterAuthAdvancedOptions({ disableSecureCookies: false });
|
|
|
|
expect(advanced).toEqual({
|
|
cookiePrefix: "paperclip-sat-worktree",
|
|
});
|
|
expect(getCookies({ advanced } as BetterAuthOptions).sessionToken.name).toMatch(
|
|
/paperclip-sat-worktree\.session_token$/,
|
|
);
|
|
});
|
|
|
|
it("keeps local http auth cookies non-secure while preserving the scoped prefix", () => {
|
|
process.env.PAPERCLIP_INSTANCE_ID = "pap-worktree";
|
|
|
|
expect(buildBetterAuthAdvancedOptions({ disableSecureCookies: true })).toEqual({
|
|
cookiePrefix: "paperclip-pap-worktree",
|
|
useSecureCookies: false,
|
|
});
|
|
expect(getCookies({
|
|
advanced: buildBetterAuthAdvancedOptions({ disableSecureCookies: true }),
|
|
} as BetterAuthOptions).sessionToken.name).toBe("paperclip-pap-worktree.session_token");
|
|
});
|
|
|
|
it("disables secure cookies for authenticated private auto-origin dev servers", () => {
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
deploymentExposure: "private",
|
|
authBaseUrlMode: "auto",
|
|
authPublicBaseUrl: undefined,
|
|
publicUrl: undefined,
|
|
})).toBe(true);
|
|
});
|
|
|
|
it("keeps secure cookies for authenticated public auto-origin servers", () => {
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
deploymentExposure: "public",
|
|
authBaseUrlMode: "auto",
|
|
authPublicBaseUrl: undefined,
|
|
publicUrl: undefined,
|
|
})).toBe(false);
|
|
});
|
|
|
|
it("uses an explicit public URL when deciding whether secure cookies are required", () => {
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
deploymentExposure: "private",
|
|
authBaseUrlMode: "auto",
|
|
authPublicBaseUrl: undefined,
|
|
publicUrl: "https://paperclip.example.test",
|
|
})).toBe(false);
|
|
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
deploymentExposure: "public",
|
|
authBaseUrlMode: "explicit",
|
|
authPublicBaseUrl: "http://paperclip.local.test:3100",
|
|
publicUrl: undefined,
|
|
})).toBe(true);
|
|
});
|
|
|
|
it("disables secure cookies when no canonical public auth URL is configured", () => {
|
|
delete process.env.PAPERCLIP_PUBLIC_URL;
|
|
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
authBaseUrlMode: "auto",
|
|
authPublicBaseUrl: undefined,
|
|
} as Parameters<typeof shouldDisableSecureAuthCookies>[0])).toBe(true);
|
|
});
|
|
|
|
it("derives secure cookie behavior from the configured public auth URL", () => {
|
|
delete process.env.PAPERCLIP_PUBLIC_URL;
|
|
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
authBaseUrlMode: "explicit",
|
|
authPublicBaseUrl: "http://paperclip-dev:46259",
|
|
} as Parameters<typeof shouldDisableSecureAuthCookies>[0])).toBe(true);
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
authBaseUrlMode: "explicit",
|
|
authPublicBaseUrl: "https://paperclip.example.test",
|
|
} as Parameters<typeof shouldDisableSecureAuthCookies>[0])).toBe(false);
|
|
});
|
|
|
|
it("uses the caller-resolved public URL for cookie security", () => {
|
|
process.env.PAPERCLIP_PUBLIC_URL = "https://ignored.example.test";
|
|
|
|
expect(shouldDisableSecureAuthCookies({
|
|
deploymentMode: "authenticated",
|
|
authBaseUrlMode: "explicit",
|
|
authPublicBaseUrl: "https://paperclip.example.test",
|
|
publicUrl: "http://paperclip-dev:46259",
|
|
} as Parameters<typeof shouldDisableSecureAuthCookies>[0])).toBe(true);
|
|
});
|
|
|
|
it("adds hostname port variants for authenticated mode on non-default ports", () => {
|
|
const trustedOrigins = deriveAuthTrustedOrigins({
|
|
deploymentMode: "authenticated",
|
|
authBaseUrlMode: "auto",
|
|
authPublicBaseUrl: undefined,
|
|
allowedHostnames: ["Board.Example.Test"],
|
|
port: 3101,
|
|
} as Parameters<typeof deriveAuthTrustedOrigins>[0]);
|
|
|
|
expect(trustedOrigins).toEqual(expect.arrayContaining([
|
|
"https://board.example.test",
|
|
"http://board.example.test",
|
|
"https://board.example.test:3101",
|
|
"http://board.example.test:3101",
|
|
]));
|
|
});
|
|
|
|
it("prefers an explicit resolved listen port over the configured port", () => {
|
|
const trustedOrigins = deriveAuthTrustedOrigins({
|
|
deploymentMode: "authenticated",
|
|
authBaseUrlMode: "auto",
|
|
authPublicBaseUrl: undefined,
|
|
allowedHostnames: ["board.example.test"],
|
|
port: 3100,
|
|
} as Parameters<typeof deriveAuthTrustedOrigins>[0], { listenPort: 3101 });
|
|
|
|
expect(trustedOrigins).toEqual(expect.arrayContaining([
|
|
"https://board.example.test:3101",
|
|
"http://board.example.test:3101",
|
|
]));
|
|
expect(trustedOrigins).not.toContain("https://board.example.test:3100");
|
|
expect(trustedOrigins).not.toContain("http://board.example.test:3100");
|
|
});
|
|
});
|