Skip to content

fix(orchestration): let the canvastty_agents helper authenticate - #81

Closed
BIackFIame wants to merge 1 commit into
howdeploy:mainfrom
BIackFIame:core/0-fix-agents-helper
Closed

BIackFIame wants to merge 1 commit into
howdeploy:mainfrom
BIackFIame:core/0-fix-agents-helper

Conversation

@BIackFIame

@BIackFIame BIackFIame commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Make canvastty_agents work for real agents. On main every call from the real helper is refused, so an orchestrator card lists the tools but each call answers "CanvasTTY orchestration bridge is unavailable".

Cause and fix

OrchestrationGateway issues each orchestrator capability for one connection id and refuses an authenticate with any other. The helper never received that id and invented helper-<uuid>.

  • OrchestrationBridge passes the capability's id as CANVASTTY_ORCHESTRATION_CONNECTION_ID.
  • The helper requires it, like the address and token.
  • Codex's env_vars forwards it. OpenCode and Hermes already forward every ORCHESTRATION_ENV name.

Security posture

No new capability. The gateway check stays exactly as strict; the helper now presents the id the capability was bound to instead of a random one.

Tests

  • New tests/orchestration-helper-identity.test.mjs starts the real helper with the environment the bridge gives a card and calls list_agents through the real gateway. On main it fails (initialize failed: CanvasTTY orchestration bridge is unavailable); with this change it passes.
  • orchestration-launch-role and orchestration-launch-extra assert the new variable.
  • Gates with a fake HOME: typecheck, full suite 874/874, electron-vite build, audit:secrets, test:even 47/47.
  • Live: in a hidden-window run (a fake Claude driving the real helper), an orchestrator listed and called canvastty_agents tools only with this change.

Dependency

Standalone on main, and independent of #80. The plugin-tools PR (#87) carries this same change byte for byte, because plugin tools reach agents through this helper. Whichever PR lands first, the other one drops the change cleanly on rebase.

Used by every plugin agent tool, for example canvastty-plugin-environments (__collect) and canvastty-plugin-accounts (__pick_account).

OrchestrationGateway issues every orchestrator capability for one
connection id and refuses an authenticate message with any other. The
helper did not receive that id and made up its own
(`helper-<uuid>`), so the gateway refused every real helper: an
orchestrator card listed canvastty_agents but each tool call answered
"CanvasTTY orchestration bridge is unavailable".

OrchestrationBridge now passes the capability's connection id as
CANVASTTY_ORCHESTRATION_CONNECTION_ID, the helper requires it like the
address and token, and every provider's MCP config forwards it (Codex
env_vars; OpenCode and Hermes read all ORCHESTRATION_ENV names).

tests/orchestration-helper-identity.test.mjs starts the real helper with
the environment the bridge gives a card and calls list_agents through
the real gateway; it fails before this change and passes after it.
@howdeploy

Copy link
Copy Markdown
Owner

Consolidated into #88 at the maintainer's request. Its branch already includes this implementation (the #81 authentication fix is incorporated through #87). Please continue all follow-up fixes and discussion in #88. Detailed changes-requested review: #88 (review) . Closing this superseded PR preserves its branch, commits and authorship; no code is being merged into main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants