Repository navigation
fix(mothership): let Chat share credentials and request access as the delegating member - #8840
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
|
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
723be6c to
31c02ce
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
31c02ce to
8d1ea34
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
Summary
credentials members list|upsert|removeandworkspaces access-requests discover|create|mine|cancelanswered every Chat call with403 This operation is unavailable through Mothership, because their use cases admitted no delegated callerHUMAN_AND_COPILOT_PRINCIPALSpolicy the other credential operations already use, and the list use case declares the credential delegation policy (sim:credentials). Chat acts as the delegating user, pinned to its workspace. All existing checks still apply:integrations.managecapabilityAccessRequestPrincipalnow admits Copilot delegation, and the member operations' workspace policy admits it. Review and settings operations stay direct-onlysim:settingsaudience. The organization routes keep the shared use cases, so Chat is still refused there at admission. The scope check also refuses a delegated caller on organization scope withPRINCIPAL_KIND_NOT_PERMITTEDprincipal.userId. Requests are therefore recorded, listed and cancelled as that member onlycopilot-refused-routes.jsonregenerated from the route inventory (the source for the CLI'smothershipUnavailableflag): the organization access-request routes stay listed as refusedType of Change
Testing
New
lib/credentials/__integration__/copilot-credential-members.integration.ts(real Postgres, Chat's in-process CLI transport, real routes and use cases):CREDENTIAL_ADMIN_ACCESS_REQUIREDBefore the fix 4/4 failed; after, 4/4 pass
New
ee/access-requests/lib/application/copilot-requests.integration.ts:Before the fix 3 of 4 failed (the direct-only guard passes both ways); after, 4/4 pass
authorization.test.ts: Chat on an organization-scoped member request is refused withPRINCIPAL_KIND_NOT_PERMITTEDbefore any lookup. The test fails with that guard removedauthorized-use-case.test.ts: the actor-preservation table now includes the delegated Copilot callerapp/api/v2/access-requests.test.tsmock now covers the workspace use casesExisting
ee/access-requests,lib/credentials,app/api/v2/credentials,app/api/v2/workspaces,app/api/v2/organizations,app/api/access-requests,app/api/organizationsandlib/api/server/routessuites pass (session, personal-key, OAuth and workspace-key cases unchanged)bun run lint,bun run type-check,bun run check:audits(58),docs-manifest:check, block-registry check, rootbun run testChecklist
test-auditauthoring gate)