Repository navigation
fix(e2e): authenticate action waits with an observer token - #510
willwashburn wants to merge 1 commit into
Conversation
Action waits subscribe to /v1/ws with an observer token scoped to stream:read and activity:read. Agent tokens stay on the HTTP action calls. The actions script keeps the handler's direct node connected so invoke can dispatch.
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 47 minutes. View limit details
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Action waits in
scripts/e2e.tsandscripts/e2e-actions.tssubscribe to/v1/wswith an observer token scoped tostream:readandactivity:read. Agent tokens stay on the HTTP action calls.action.invokedandaction.completedarrive on that workspace observer stream. An agent token on/v1/wsis 401; an observer token withstream:readis 101.scripts/e2e-actions.tskeeps the handler's direct node connected so invoke can dispatch. That socket is not the event wait.Fixes #378
Note
Low Risk
Test and E2E script changes only; no production engine or API behavior is modified.
Overview
E2E action flows no longer wait on
action.invoked/action.completedusing agent tokens on/v1/ws(which the server rejects). Bothscripts/e2e.tsandscripts/e2e-actions.tsnow mint a workspace observer token and subscribe via shared helpers inscripts/action-wait-ws.ts(stream:read+activity:readsoaction.*frames pass the observer filter).e2e-actions.tsadditionally keeps the handler on a direct node WebSocket (/v1/node/ws) so invoke can dispatch; that connection is separate from the observer wait. Engine tests inactionWaitWsScript.test.tslock the path, token prefix, scopes, andobserverAllowsEventbehavior.Reviewed by Cursor Bugbot for commit a014a6b. Bugbot is set up for automated code reviews on this repo. Configure here.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.