fix(orchestration): let the canvastty_agents helper authenticate - #81
Closed
BIackFIame wants to merge 1 commit into
Closed
BIackFIame wants to merge 1 commit into
BIackFIame wants to merge 1 commit into
Conversation
OrchestrationGateway issues every orchestrator capability for one connection id and refuses an authenticate message with any other. The helper did not receive that id and made up its own (`helper-<uuid>`), so the gateway refused every real helper: an orchestrator card listed canvastty_agents but each tool call answered "CanvasTTY orchestration bridge is unavailable". OrchestrationBridge now passes the capability's connection id as CANVASTTY_ORCHESTRATION_CONNECTION_ID, the helper requires it like the address and token, and every provider's MCP config forwards it (Codex env_vars; OpenCode and Hermes read all ORCHESTRATION_ENV names). tests/orchestration-helper-identity.test.mjs starts the real helper with the environment the bridge gives a card and calls list_agents through the real gateway; it fails before this change and passes after it.
This was referenced Sep 27, 2026
Owner
|
Consolidated into #88 at the maintainer's request. Its branch already includes this implementation (the #81 authentication fix is incorporated through #87). Please continue all follow-up fixes and discussion in #88. Detailed changes-requested review: #88 (review) . Closing this superseded PR preserves its branch, commits and authorship; no code is being merged into main. |
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Make
canvastty_agentswork for real agents. On main every call from the real helper is refused, so an orchestrator card lists the tools but each call answers "CanvasTTY orchestration bridge is unavailable".Cause and fix
OrchestrationGatewayissues each orchestrator capability for one connection id and refuses anauthenticatewith any other. The helper never received that id and inventedhelper-<uuid>.OrchestrationBridgepasses the capability's id asCANVASTTY_ORCHESTRATION_CONNECTION_ID.env_varsforwards it. OpenCode and Hermes already forward everyORCHESTRATION_ENVname.Security posture
No new capability. The gateway check stays exactly as strict; the helper now presents the id the capability was bound to instead of a random one.
Tests
tests/orchestration-helper-identity.test.mjsstarts the real helper with the environment the bridge gives a card and callslist_agentsthrough the real gateway. On main it fails (initialize failed: CanvasTTY orchestration bridge is unavailable); with this change it passes.orchestration-launch-roleandorchestration-launch-extraassert the new variable.canvastty_agentstools only with this change.Dependency
Standalone on main, and independent of #80. The plugin-tools PR (#87) carries this same change byte for byte, because plugin tools reach agents through this helper. Whichever PR lands first, the other one drops the change cleanly on rebase.
Used by every plugin agent tool, for example canvastty-plugin-environments (
__collect) and canvastty-plugin-accounts (__pick_account).