Skip to content

fix(e2e): authenticate action waits with an observer token - #510

Open
willwashburn wants to merge 1 commit into
mainfrom
fix/e2e-observer-ws-378
Open

willwashburn wants to merge 1 commit into
mainfrom
fix/e2e-observer-ws-378

Conversation

@willwashburn

@willwashburn willwashburn commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Action waits in scripts/e2e.ts and scripts/e2e-actions.ts subscribe to /v1/ws with an observer token scoped to stream:read and activity:read. Agent tokens stay on the HTTP action calls.

action.invoked and action.completed arrive on that workspace observer stream. An agent token on /v1/ws is 401; an observer token with stream:read is 101. scripts/e2e-actions.ts keeps the handler's direct node connected so invoke can dispatch. That socket is not the event wait.

Fixes #378


Note

Low Risk
Test and E2E script changes only; no production engine or API behavior is modified.

Overview
E2E action flows no longer wait on action.invoked / action.completed using agent tokens on /v1/ws (which the server rejects). Both scripts/e2e.ts and scripts/e2e-actions.ts now mint a workspace observer token and subscribe via shared helpers in scripts/action-wait-ws.ts (stream:read + activity:read so action.* frames pass the observer filter).

e2e-actions.ts additionally keeps the handler on a direct node WebSocket (/v1/node/ws) so invoke can dispatch; that connection is separate from the observer wait. Engine tests in actionWaitWsScript.test.ts lock the path, token prefix, scopes, and observerAllowsEvent behavior.

Reviewed by Cursor Bugbot for commit a014a6b. Bugbot is set up for automated code reviews on this repo. Configure here.

View guided diff


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Action waits subscribe to /v1/ws with an observer token scoped to
stream:read and activity:read. Agent tokens stay on the HTTP action
calls. The actions script keeps the handler's direct node connected
so invoke can dispatch.
@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 47 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ecb6ba93-e4cd-4f94-9999-f6baf7bd973e

📥 Commits

Reviewing files that changed from the base of the PR and between 3894b8b and a014a6b.


📒 Files selected for processing (4)
  • packages/engine/src/__tests__/actionWaitWsScript.test.ts
  • scripts/action-wait-ws.ts
  • scripts/e2e-actions.ts
  • scripts/e2e.ts

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T10:05:32.484662Z a014a6b PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

E2E action scripts authenticate workspace WebSocket with rejected agent tokens

1 participant