Repository navigation
Fix the console Agents view for saved providers and authenticate node routes first - #136
Merged
Merged
Conversation
The console's Agents page failed for any Agent saved with x_agents_core.model_provider
because the admin projection reused the Session Agent projection, which accepts only
{harness}. Saved Agent reads return an optional harness and an optional safe provider
view (protocol, base_url, optional limits, api_key_configured), and an empty object when
neither is saved.
Split the Core extension check: Session Agent snapshots keep the exact harness-only
shape, and saved Agents reuse the execution-configuration provider validator. Unknown
members, a null provider and any api_key are still rejected.
Before the sandbox deployment was initialized, GET /api/v1/sandbox-node/configuration and POST /api/v1/sandbox-node/enroll answered any credential, invalid ones included, with 503 runtime_node_unavailable: the shared deployment lock rejected an uninitialized deployment before the route checked its credential. Configuration also reported a non-node (E2B) deployment as 409 before authenticating. Node routes now lock the deployment without that check, authenticate the enrollment token or node credential first, and only then report an uninitialized deployment (503), an installation mismatch (401) or the existing mode, maintenance and specification outcomes. Administrator routes keep the initialized-deployment check. Identity and the node connection already authenticated first and are unchanged.
…ored provider URLs A claimed but uninitialized installation now rejects an enrollment token or node credential issued for another installation with 401 before reporting 503, as it does after initialization, so the two deployment states are indistinguishable to such a caller. The contract states that only configuration and enroll answer an accepted credential with 503 before initialization. Core's provider base URL admission now requires a port in 1-65535 and a usable host: an IP address, or a domain with valid IDNA labels of letters, digits, hyphens and underscores and a non-numeric final label. The client's read check no longer parses the host with URL: it keeps the HTTPS, credential, query and fragment checks, so a base URL an earlier Core stored cannot fail a whole Agents list.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes two defects found in the real acceptance run of the Core/Web boundary release (#128), plus the findings from their blind review.
x_agents_core.model_provider. The admin client validated saved Agents with the Session snapshot rule, which accepts only{harness}.{}, harness only, provider only, both. It still rejects unknown members and anyapi_key./api/v1/sandbox-node/configurationand/enrollreturned 503 or 409 for invalid credentials while the deployment was uninitialized or E2B.base_urlvalidation now rejects invalid ports and hosts. The client's read check is no stricter than Core's write rule, so one saved Agent can no longer break the whole Agents list.Review
ca5c6763and verified by regression tests and the gate. There was no second review round, per the small-fix rule.Verification
acceptance-fixes-r4) on5deb9b22: passed. Playwright browser cases were skipped on the server (Chrome unavailable; approved skip).fca93f5dmerges main's Replace the forced first-run with a Getting started checklist #133, a Web-only change whose files don't overlap with this branch. On the merged tree:pnpm typecheckpassed;pnpm test:web: 339/339.Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.