Skip to content

fix(mothership): let Chat share credentials and request access as the delegating member - #8840

Merged
waleedlatif1 merged 3 commits into
stagingfrom
fix/chat-credential-sharing-access-requests
Oct 9, 2026
Merged

waleedlatif1 merged 3 commits into
stagingfrom
fix/chat-credential-sharing-access-requests

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • credentials members list|upsert|remove and workspaces access-requests discover|create|mine|cancel answered every Chat call with 403 This operation is unavailable through Mothership, because their use cases admitted no delegated caller
  • Credential members: the three operations take the HUMAN_AND_COPILOT_PRINCIPALS policy the other credential operations already use, and the list use case declares the credential delegation policy (sim:credentials). Chat acts as the delegating user, pinned to its workspace. All existing checks still apply:
    • credential admin role for upsert and remove
    • the target must belong to the credential's workspace
    • workspace admins cannot be demoted or removed
    • integrations.manage capability
    • Chat is confined to OAuth credentials, as for every other Copilot credential operation
    • audit and analytics events
  • Access requests: AccessRequestPrincipal now admits Copilot delegation, and the member operations' workspace policy admits it. Review and settings operations stay direct-only
  • The four workspace v2 routes bind workspace copies of the shared use cases that declare the sim:settings audience. The organization routes keep the shared use cases, so Chat is still refused there at admission. The scope check also refuses a delegated caller on organization scope with PRINCIPAL_KIND_NOT_PERMITTED
  • The funnel resolves the acting user once (the caller, or the member Chat acts for) and passes it to the use cases in place of principal.userId. Requests are therefore recorded, listed and cancelled as that member only
  • Workspace API key and direct-caller admission are unchanged
  • copilot-refused-routes.json regenerated from the route inventory (the source for the CLI's mothershipUnavailable flag): the organization access-request routes stay listed as refused

Type of Change

  • Bug fix

Testing

  • New lib/credentials/__integration__/copilot-credential-members.integration.ts (real Postgres, Chat's in-process CLI transport, real routes and use cases):

    • a workspace admin shares, lists and unshares an OAuth credential, and the audit records the delegated Copilot actor
    • a non-admin member is refused with CREDENTIAL_ADMIN_ACCESS_REQUIRED
    • sharing with a user outside the workspace is refused as a validation error
    • a chat pinned to another workspace gets 404

    Before the fix 4/4 failed; after, 4/4 pass

  • New ee/access-requests/lib/application/copilot-requests.integration.ts:

    • a member discovers, requests, lists and cancels a withheld feature, and the audit records the delegated Copilot actor
    • cancelling another member's request answers 404 and leaves it pending
    • a chat pinned to another workspace cannot create a request
    • the organization route still answers 403 for Chat

    Before the fix 3 of 4 failed (the direct-only guard passes both ways); after, 4/4 pass

  • authorization.test.ts: Chat on an organization-scoped member request is refused with PRINCIPAL_KIND_NOT_PERMITTED before any lookup. The test fails with that guard removed

  • authorized-use-case.test.ts: the actor-preservation table now includes the delegated Copilot caller

  • app/api/v2/access-requests.test.ts mock now covers the workspace use cases

  • Existing ee/access-requests, lib/credentials, app/api/v2/credentials, app/api/v2/workspaces, app/api/v2/organizations, app/api/access-requests, app/api/organizations and lib/api/server/routes suites pass (session, personal-key, OAuth and workspace-key cases unchanged)

  • bun run lint, bun run type-check, bun run check:audits (58), docs-manifest:check, block-registry check, root bun run test

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 6:48am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 16 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical impact] The PR appears safe to merge; no new actionable issues were found.

Summary

Chat can now share OAuth credentials and discover, create, list, and cancel workspace access requests as the delegating member.

  • Credential changes retain the existing admin, capability, type, and workspace checks.
  • Organization access-request routes, review, and settings remain direct-only.
  • New integration tests check stored grants, requests, and delegated audit actors.
  • The previously reported mock-based delegated test row was removed, as waleedlatif1 explained. The thread is unnumbered, so it has no previousFindings entry.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  Chat[Chat acting for a member] --> Admission[Route declares a delegation audience]
  Admission --> Workspace[Check workspace, expiry, and member access]
  Workspace --> Credentials[Credential members: OAuth type and admin checks]
  Workspace --> Requests[Access requests: use the member as requester]
  Credentials --> Audit[Record delegated actor]
  Requests --> Audit
  Chat --> Organization[Organization access-request routes]
  Organization --> Refused[Refuse delegated calls]
Loading

Reviews (4) · Last reviewed commit: "chore(mothership): refresh the refused-r..." · Reviewed by Greptile

Comment thread apps/sim/ee/access-requests/lib/application/authorized-use-case.test.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 16 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the fix/chat-credential-sharing-access-requests branch from 723be6c to 31c02ce Compare October 9, 2026 06:10
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 16 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the fix/chat-credential-sharing-access-requests branch from 31c02ce to 8d1ea34 Compare October 9, 2026 06:47
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 16 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 0809d27 into staging Oct 9, 2026
86 of 88 checks passed

This branch was previously deployed

1 inactive deployment
Preview — 8d1ea34f Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant