Repository navigation
merge(stage): upstream 73e097b8c with MCP OAuth for outside agents - #287
Merged
Merged
Conversation
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
…dotgg#14825) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
…ibfuse2 launch failure) (pingdotgg#7765) Co-authored-by: Julius Marminge <julius0216@outlook.com>
…ingdotgg#16319) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
pingdotgg#16320) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…stead of gh (pingdotgg#16321) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…wer reads per PR action (pingdotgg#16322) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ow it (pingdotgg#16551) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tgg#16571) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…gdotgg#16563) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16562) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…cy policy (pingdotgg#16564) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e a patch arrives (pingdotgg#16033) Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…6335) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16336) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g#16337) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…es (pingdotgg#16375) Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r requests (pingdotgg#15515) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ls the send (pingdotgg#16398) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…otgg#16296) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dotgg#16330) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ingdotgg#16369) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ar state (pingdotgg#16729) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…height (pingdotgg#17086) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Brings in upstream's MCP OAuth sign-in (pingdotgg#16336, pingdotgg#16718), per-tool access declarations (pingdotgg#16335), Copy MCP URL (pingdotgg#16337, pingdotgg#16909), MCP apps (pingdotgg#16236) and the rest of upstream through 73e097b (139 commits). Fork layers kept on top of upstream: - Settings-issued MCP bearer credentials resolve to upstream's client caller (clientAccess.expbkt3.ts), so Bifrost/Toolyard keep working. - Fork control, web UI bridge and session-webhook tools register through upstream McpToolAccess declarations. - OAuth clients bind to the approving team user (actorUserId). - Per-profile GitHub tokens ported onto upstream's GitHubApi (gitHubProfileCredential.expbkt3.ts); GitHubCli.ts removed with upstream. - New upstream RPCs (mcpApps.*, terminal.observe) get the fork thread gate. - Upstream migrations 59-60 registered as 1048-1049. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- ChatView: drop a leftover fragment of upstream's startThreadTurn line. - client-runtime: the org user directory atom provides HttpClient itself, like upstream's session atom. - contracts: external-sync:write reports as orchestration:operate to old clients. - Tests: fork services in upstream's new tests (McpOAuth, bounded snapshot transport), fork migration ids (1043, 1048-1049), web UI RPC counts (235/31), fork client_version in bootstrap expectations, member pairing permissions, HandlersLayer in the PR session-watch test, full startTurn input. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Security: MCP OAuth approvals now follow the environment identity mode. In "required" mode an approval must name a team user (Clerk-bound code or session); an unbound client is an external operator only when its approver held access:write (signed `mop` claim), otherwise a plain external user. Shared predicate in mcpApprovalPolicy.expbkt3.ts. Web: /pair#token links redeem through upstream's pairing surface in Clerk team mode; the Clerk path reloads after sign-in like upstream; /pair with a token no longer throws when the managed primary is offline. Mobile: follow upstream's iosBottomClearance rename, make the fork threadCostHeader prop optional, mock fork modules that pull the app runtime in upstream's tests. Server test: optional thread on fork scopes. Formatting per vp fmt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- web: reopening a closed plan review panel uses the fork's openPlanReview. - mobile: upstream's git-actions test expects the fork's per-thread VCS refresh. - format two source-control files. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- RpcInstrumentation covers the fork RPCs through forkRpcGroups.expbkt3.ts. - Complete fork service mocks in upstream's bounded snapshot test and the session-webhook MCP test. - Lint: fork reads of session client metadata join upstream's allowlist. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
….16 sqlite Upstream's requested-scope check binds `requestedScopes === undefined`. node:sqlite on Node 24.16 (the stage server and stage workflow) refuses boolean parameters, so every pairing redemption failed there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Stage shipped migration 1048 (ThreadCommentLastSent), so upstream 59-60 move to 1049-1050. Web UI RPC counts include #286's resend RPC (236). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
bk-agent-01
marked this pull request as ready for review
October 8, 2026 09:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The fork lacked upstream's new MCP work: OAuth sign-in for outside agents (Claude Code, Codex, ChatGPT, claude.ai), access declarations for each MCP tool, Copy MCP URL, and MCP apps. The fork had its own Settings-issued MCP credentials and access checks. Keeping two systems makes each upstream merge harder.
What this PR does
It merges upstream
73e097b8c(139 commits) intostage. Where upstream now does the same thing, the PR uses upstream's code. Fork changes stay as small marked layers on top.McpToolAccessdeclarations (pingdotgg#16335)t3_*control tools, web UI bridge, session webhooks) use the upstream declarations. Fork-only checks stay in the handlers.clientAccess.expbkt3.tsmaps the credentials onto it, so Bifrost and Toolyard keep their access.GitHubApireplacesGitHubCligitHubProfileCredential.expbkt3.tskeeps one token for each profile, with its own cache key and rate-limit scope.mcpApps.*,terminal.observeThe fork-marker check passes: 487 modified upstream files, 826 fork-owned files, and an empty baseline.
Behavior changes to review
terminal.observegets a thread access gate. Its neighbour,terminalAttach, has no gate.Verification
The host does not allow local builds or tests. CI on this PR verifies the merge. After the merge, stage deploys at https://stagebkt3.dev.beknown.live.
🤖 Generated with Claude Code