Conversation
Forward denied document scopes through RealtimeProvider so content loaded before reconnection is cleared after access is revoked. Wait for keyboard sensor readiness and scope Analytics and Inbox locators to accessible content. Cover connection races and persisted drag state.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
|
Thanks for your first pull request to Orbit. Two things that will save you a review round: A maintainer will review this shortly. Ask anything on the thread. |
| await signIn(page); | ||
| const mainAgentName = `HTTP Researcher ${randomUUID().slice(0, 8)}`; | ||
| const mainToken = await authorizeAgent(page, metadata, mainAgentName); | ||
| let writerToken = mainToken; |
|
This can be something amazing; you are basically adding an agent directly to Orbit. Is there a design doc? |
What this changes
This is a Draft PR for early review of the Agent identity, data model, permission boundaries, and Issue runtime implementation. It is not ready to merge and does not claim to complete #215. Known Web integration gaps and remaining work are listed below.
Adds workspace Agent identities that can be assigned issues through MCP and appear as the actor for Issue mutations. The authorizing Human remains the permission principal, so Agent access is the intersection of the grant scopes, the Human's current permissions, and resource policy.
create_issuesupports idempotency keys, and public events omit grant identifiers.Why
MCP actions currently appear to come from the authorizing person, and Agents cannot own an assignment queue. This work establishes the runtime and permission boundaries needed to make Agent work visible and assignable without granting additional access. This draft requests upstream feedback before completing the remaining UI integration.
Refs #215
Feedback requested
Known gaps and remaining work before ready for review
creator,assignee,owner,assigneeAgentId, andownerIdin the client Issue schema and update detail, list, and board consumers. Agent assignments currently render as Unassigned, and the Human Issue Owner has no display or transfer controls.ownerUserId: nullfor policy-controlled Owner clearing when there is no Agent Assignee. The current validator and transfer path do not support that input.How you know it works
Validated on
203a066dcba7c7ffc4adcb5a28e81749f3392e79, including upstreamd133153ef077637324f0eb34b79fbc82f45b1212.bun run verifybun run test:e2ebun run test:e2e:agent-releasedb:release, repeated release, anddb:check-driftbun run build,bun run docs:build, documentation navigation testgit diff --checkThe regression coverage includes current-permission checks, identity lifecycle races, exact credential binding, Actor constraints and backfills, issue attribution, Agent queue access, idempotency, Outbox delivery and redaction, and real HTTP OAuth/MCP behavior with the Writer enabled and disabled.
The browser coverage also includes document access revoked during a reconnect, keyboard drag readiness and persistence, and Agent settings and Inbox behavior. The full verification includes real S3 round trips with signature validation enabled. The earlier persistent Worker image and recovery drill was not repeated for this merge candidate; it remains historical evidence, not a new result.
These passing results describe the current test suite, not complete coverage of #215. The existing MCP browser test checks the generic Agent Creator label and Activity badge, but does not assert Agent Assignee rendering, Human Owner controls, or Web Agent selection. Those gaps remain despite the green suite.
Screenshots
Before this change, MCP settings listed Human-authorized client connections without an Agent management surface, and MCP issue actions appeared to come from the Human.
After this change, settings show Agent identities, owners, lifecycle and connection state, locks, permissions, quota, and recent activity. Issue activity distinguishes the Agent actor from its Human principal.
Light and dark screenshots of Agent settings and issue attribution have been captured in the local review bundle. Uploading the four PNGs to this PR is pending. They use synthetic E2E data, not production records.
The screenshots cover existing Settings and Activity behavior only. They are not evidence that the Agent Assignee and Human Owner UI is complete.
Checklist
bun run verifyis green, all four checksany, no non-null assertions@orbit/sharedpackages/shared/src/policy, including the remaining lifecycle action checksbun run db:releaseandbun run db:check-driftpassed against the target database before this ships. The isolated acceptance target passed; the deployment target remains a release-time check.Anything reviewers should know
0030_green_shaman.sqlappends to the official migration chain. Existing upstream migrations are unchanged. The abandoned local development migration lineage is not a supported upgrade path.meandlist_my_issueskeep their Human meanings;agentandlist_agent_issuesrefer to the current Agent. Agent attribution covers issue mutations; comments, attachments, and documents retain Human attribution.