mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 04:33:12 +00:00
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788) Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com> (cherry picked from commit 32e81f2979a7baf11fe387df59f7d13a31889c74) * Fix PR creation guard shell bypasses (#1786) Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> (cherry picked from commit 75fb8b487852003916c4984504a13ee7226b2ceb) * fix: add exc_info to swallowed exception in push re-review webhook (#1764) (cherry picked from commit ab85b372b4f37b7feb849054553daed10852a42c) * chore: clarify shared response image guidance (#1782) Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit 2e8ff4b72f1148bb36c0c1181063a3abd78b15d0) * fix: match embedded review description background (#1791) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit 4ea2441ada1229bc414b02950d821786be2f7301) * fix: show current shared thread in sidebar (#1799) * fix: show current shared thread in sidebar Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> * fix: preserve resolved active sidebar threads Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> --------- Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com> (cherry picked from commit a77c4e475643b4a55bb2f0c93c0aa2669014fbac) * chore: switch deferred items to landed in upstream-sync triage documentation and jsonl entries (fork PR #226). Signed-off-by: Adam Moussa <adam@seahavenind.com> * harden PR guards + sidebar after security review - Mirror upstream #1786's nested-shell / executable-normalization hardening into the fork-only pr_verdict_guard.py (verdict-gating is a real fork control), keeping it in parity with pr_creation_guard.py. - Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's -c argument can be concatenated into the same argv token, which the space-separated -c detection missed. Diverges pr_creation_guard.py from upstream #1786 by design; to be upstreamed. - Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner viewing a shared thread reads last-known state without persisting a metadata write (mirrors the is_owner gate on the single-thread read path). - Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type). Guards remain intentionally fail-open per the honest-agent threat model; docstrings narrowed to name the residual exotic-shell / stdin-fed vectors. --------- Signed-off-by: Adam Moussa <adam@seahavenind.com> Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com> Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> Co-authored-by: Suraj Bayas <surajyou24@gmail.com> Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev> Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> Co-authored-by: Johannes du Plessis <johannes@langchain.dev> Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
151 lines
5.4 KiB
TypeScript
151 lines
5.4 KiB
TypeScript
import { test, expect, type Locator, type Page } from "@playwright/test";
|
|
|
|
// Exercises the sidebar's "Copy sandbox ID" action against the REAL dashboard
|
|
// UI and a REAL (local-provider) sandbox: the Slack flow runs the agent, which
|
|
// creates a sandbox and stamps its id into the thread metadata, and the UI
|
|
// copies that same id. Only the LLM/GitHub/Slack boundaries are faked.
|
|
const SAME_USER = { login: "alice", email: "alice@example.com" };
|
|
const OTHER_USER = { login: "bob", email: "bob@example.com" };
|
|
|
|
async function loginAs(page: Page, user: { login: string; email: string }) {
|
|
const res = await page.request.post("/control/login", { data: user });
|
|
expect(res.ok()).toBeTruthy();
|
|
}
|
|
|
|
// Drive the Slack flow so the real agent creates a thread + sandbox, then follow
|
|
// the bot's "Open in Web" link. Returns the created thread id.
|
|
async function createThreadWithSandbox(page: Page): Promise<string> {
|
|
await page.goto("/mock/slack");
|
|
await page.locator("#reset").click();
|
|
await expect(page.locator("#thread")).toContainText("No messages yet");
|
|
await page
|
|
.locator("#text")
|
|
.fill("<@U0BOT> please add a greet() helper and open a PR");
|
|
await page.locator("#send").click();
|
|
await expect(
|
|
page.locator(".msg.bot").filter({ hasText: "Add greet() helper" }),
|
|
).toBeVisible();
|
|
|
|
const webLink = page.locator('.msg.bot a[href*="/agents/"]').first();
|
|
await expect(webLink).toBeVisible();
|
|
await webLink.click();
|
|
await expect(page).toHaveURL(/\/agents\//);
|
|
|
|
const id = new URL(page.url()).pathname.split("/").filter(Boolean).pop();
|
|
expect(id).toBeTruthy();
|
|
return id as string;
|
|
}
|
|
|
|
const copyItem = (page: Page) =>
|
|
page.getByRole("menuitem", { name: "Copy sandbox ID" });
|
|
|
|
// The kebab sits beside the row Link (not inside the anchor), so reach it via
|
|
// their shared wrapper — the Link's parent.
|
|
const kebabFor = (row: Locator) =>
|
|
row.locator("..").getByRole("button", { name: "Thread actions" });
|
|
|
|
test.describe("thread sandbox id (real dashboard UI)", () => {
|
|
test("desktop: kebab menu copies the real sandbox id", async ({
|
|
page,
|
|
baseURL,
|
|
}) => {
|
|
await page
|
|
.context()
|
|
.grantPermissions(["clipboard-read", "clipboard-write"], {
|
|
origin: baseURL,
|
|
});
|
|
await loginAs(page, SAME_USER);
|
|
const threadId = await createThreadWithSandbox(page);
|
|
|
|
const row = page.locator(`a[href$="/agents/${threadId}"]`).first();
|
|
await expect(row).toBeVisible();
|
|
// The kebab is revealed on hover on pointer devices.
|
|
await row.hover();
|
|
await kebabFor(row).click();
|
|
|
|
await expect(copyItem(page)).toBeEnabled();
|
|
await copyItem(page).click();
|
|
|
|
const clip = await page.evaluate(() => navigator.clipboard.readText());
|
|
expect(clip.length).toBeGreaterThan(0);
|
|
});
|
|
|
|
test("iPad: kebab copies the sandbox id without navigating", async ({
|
|
browser,
|
|
baseURL,
|
|
}) => {
|
|
// iPad-class device: Chromium in mobile mode reports (hover: none), which
|
|
// gates the touch-only kebab. 834px is wider than the 767px mobile
|
|
// breakpoint, so the sidebar renders inline.
|
|
const context = await browser.newContext({
|
|
baseURL,
|
|
viewport: { width: 834, height: 1112 },
|
|
isMobile: true,
|
|
hasTouch: true,
|
|
});
|
|
await context.grantPermissions(["clipboard-read", "clipboard-write"], {
|
|
origin: baseURL,
|
|
});
|
|
const page = await context.newPage();
|
|
await loginAs(page, SAME_USER);
|
|
|
|
// Two threads: we sit on B's page and act on A's sidebar row, so a stray
|
|
// Link navigation would be observable as a URL change to A.
|
|
const threadA = await createThreadWithSandbox(page);
|
|
const threadB = await createThreadWithSandbox(page);
|
|
await expect(page).toHaveURL(new RegExp(`/agents/${threadB}$`));
|
|
|
|
const rowA = page.locator(`a[href$="/agents/${threadA}"]`).first();
|
|
await expect(rowA).toBeVisible();
|
|
|
|
const kebab = kebabFor(rowA);
|
|
await expect(kebab).toBeVisible();
|
|
await kebab.tap();
|
|
|
|
await expect(copyItem(page)).toBeEnabled();
|
|
await copyItem(page).tap();
|
|
|
|
const clip = await page.evaluate(() => navigator.clipboard.readText());
|
|
expect(clip.length).toBeGreaterThan(0);
|
|
|
|
// Tapping the kebab must open the menu, not follow A's Link — we stay on B.
|
|
await expect(page).toHaveURL(new RegExp(`/agents/${threadB}$`));
|
|
|
|
await context.close();
|
|
});
|
|
|
|
test("shared active thread appears in the sidebar with sandbox action", async ({
|
|
page,
|
|
browser,
|
|
baseURL,
|
|
}, testInfo) => {
|
|
await loginAs(page, SAME_USER);
|
|
const threadId = await createThreadWithSandbox(page);
|
|
|
|
const bobContext = await browser.newContext({ baseURL });
|
|
await bobContext.grantPermissions(["clipboard-read", "clipboard-write"], {
|
|
origin: baseURL,
|
|
});
|
|
const bobPage = await bobContext.newPage();
|
|
await loginAs(bobPage, OTHER_USER);
|
|
await bobPage.goto(`/agents/${threadId}`);
|
|
await expect(bobPage).toHaveURL(new RegExp(`/agents/${threadId}$`));
|
|
|
|
const row = bobPage.locator(`a[href$="/agents/${threadId}"]`).first();
|
|
await expect(row).toBeVisible();
|
|
await row.hover();
|
|
await kebabFor(row).click();
|
|
await expect(copyItem(bobPage)).toBeEnabled();
|
|
|
|
const screenshotPath = testInfo.outputPath(
|
|
"shared-thread-sidebar-sandbox-menu.png",
|
|
);
|
|
await bobPage.screenshot({ path: screenshotPath, fullPage: true });
|
|
await testInfo.attach("shared-thread-sidebar-sandbox-menu", {
|
|
path: screenshotPath,
|
|
contentType: "image/png",
|
|
});
|
|
|
|
await bobContext.close();
|
|
});
|
|
});
|