open-swe/ui/src/features/agents/lib/api.ts
Adam Moussa d48cb12e08
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
feat(open-swe): port upstream clean batch (#1788, #1786, #1764, #1782, #1791, #1799) + guard hardening (#226)
* Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 32e81f2979a7baf11fe387df59f7d13a31889c74)

* Fix PR creation guard shell bypasses (#1786)

Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
(cherry picked from commit 75fb8b487852003916c4984504a13ee7226b2ceb)

* fix: add exc_info to swallowed exception in push re-review webhook (#1764)

(cherry picked from commit ab85b372b4f37b7feb849054553daed10852a42c)

* chore: clarify shared response image guidance (#1782)

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 2e8ff4b72f1148bb36c0c1181063a3abd78b15d0)

* fix: match embedded review description background (#1791)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 4ea2441ada1229bc414b02950d821786be2f7301)

* fix: show current shared thread in sidebar (#1799)

* fix: show current shared thread in sidebar

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: preserve resolved active sidebar threads

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

---------

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
(cherry picked from commit a77c4e475643b4a55bb2f0c93c0aa2669014fbac)

* chore: switch deferred items to landed in upstream-sync triage documentation and jsonl entries (fork PR #226).

Signed-off-by: Adam Moussa <adam@seahavenind.com>

* harden PR guards + sidebar after security review

- Mirror upstream #1786's nested-shell / executable-normalization hardening
  into the fork-only pr_verdict_guard.py (verdict-gating is a real fork
  control), keeping it in parity with pr_creation_guard.py.
- Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's
  -c argument can be concatenated into the same argv token, which the
  space-separated -c detection missed. Diverges pr_creation_guard.py from
  upstream #1786 by design; to be upstreamed.
- Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner
  viewing a shared thread reads last-known state without persisting a metadata
  write (mirrors the is_owner gate on the single-thread read path).
- Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type).

Guards remain intentionally fail-open per the honest-agent threat model;
docstrings narrowed to name the residual exotic-shell / stdin-fed vectors.

---------

Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
Co-authored-by: Suraj Bayas <surajyou24@gmail.com>
Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
2026-07-24 18:49:53 -04:00

374 lines
10 KiB
TypeScript

import type { AgentSchedule, AgentThread, ImageChunk, Message } from "./types"
export type { AgentSchedule, AgentThread, Message }
export class AgentsApiError extends Error {
constructor(
public readonly status: number,
message: string
) {
super(message)
this.name = "AgentsApiError"
}
}
export interface ThreadMessageRequest {
content: string
images?: Array<ImageChunk>
model_id?: string | null
effort?: string | null
plan_mode?: boolean
}
export interface ScheduleCreateRequest {
prompt: string
schedule: string
name?: string | null
repo?: string | null
model_id?: string | null
effort?: string | null
slack_report_channel?: string | null
}
export interface ScheduleUpdateRequest {
prompt?: string | null
schedule?: string | null
name?: string | null
repo?: string | null
model_id?: string | null
effort?: string | null
enabled?: boolean | null
slack_report_channel?: string | null
}
export interface ThreadPrDiffFile {
path: string
previousPath: string | null
status: "added" | "removed" | "modified" | "renamed" | string
additions: number
deletions: number
originalContent: string | null
modifiedContent: string | null
unrenderable: boolean
}
export interface ThreadPrDiff {
prNumber: number
baseSha: string
headSha: string
truncated: boolean
files: Array<ThreadPrDiffFile>
}
export interface ThreadRecoveryPatch {
blob: Blob
filename: string
}
export type WorkflowApprovalStatus = "pending" | "approved" | "rejected"
export interface WorkflowDiffStats {
files: number
additions: number
deletions: number
}
export interface WorkflowPushApproval {
fingerprint: string
status: WorkflowApprovalStatus
repo: string
branch: string
baseSha: string
headSha: string
files: Array<string>
diffStats: WorkflowDiffStats
diffPreview: string
diffPreviewTruncated: boolean
approvalUrl: string | null
requestedAt: string | null
decidedAt: string | null
decidedBy: string | null
}
export interface WorkflowPushApprovalsResponse {
threadId: string
isOwner: boolean
approvals: Array<WorkflowPushApproval>
}
export interface WorkflowApprovalDecision {
status: string
fingerprint: string
}
// Legacy alias kept for backward-compatible prop typing.
export type WorkflowApproval = WorkflowPushApproval
export interface WorkflowApprovalsPayload {
approvals: Array<WorkflowPushApproval>
}
export interface ThreadsPageParams {
limit?: number
offset?: number
all?: boolean
resolved?: boolean
viewed?: boolean
source?: string
status?: string
q?: string
}
export interface ThreadsPage {
items: Array<AgentThread>
total?: number
limit: number
offset: number
hasMore?: boolean
}
export interface SidebarThreadsGroup {
items: Array<AgentThread>
limit: number
hasMore: boolean
}
export interface SidebarThreads {
active: SidebarThreadsGroup
resolved: SidebarThreadsGroup
}
const API_BASE = (import.meta.env.VITE_DASHBOARD_API_BASE_URL ?? "").replace(
/\/$/,
""
)
export const agentsLangGraphApiUrl = `${API_BASE}/dashboard/api`
async function agentsRequest<T>(
path: string,
init: RequestInit = {}
): Promise<T> {
const res = await fetch(`${API_BASE}/dashboard/api${path}`, {
...init,
credentials: "include",
headers: {
"Content-Type": "application/json",
...(init.headers ?? {}),
},
})
if (!res.ok) {
let message = res.statusText
try {
const body = await res.json()
if (body?.detail) {
message =
typeof body.detail === "string"
? body.detail
: JSON.stringify(body.detail)
}
} catch {
/* ignore */
}
throw new AgentsApiError(res.status, message)
}
if (res.status === 204) return undefined as T
return (await res.json()) as T
}
function filenameFromContentDisposition(value: string | null): string | null {
const match = /filename="([^"]+)"/.exec(value ?? "")
return match?.[1] ?? null
}
async function agentsBlobRequest(path: string): Promise<ThreadRecoveryPatch> {
const res = await fetch(`${API_BASE}/dashboard/api${path}`, {
credentials: "include",
headers: { Accept: "text/x-diff" },
})
if (!res.ok) {
let message = res.statusText
try {
const body = await res.json()
if (body?.detail) {
message =
typeof body.detail === "string"
? body.detail
: JSON.stringify(body.detail)
}
} catch {
/* ignore */
}
throw new AgentsApiError(res.status, message)
}
return {
blob: await res.blob(),
filename:
filenameFromContentDisposition(res.headers.get("content-disposition")) ??
"open-swe-recovery.patch",
}
}
function buildThreadsPageQuery(params: ThreadsPageParams): string {
const search = new URLSearchParams()
if (params.limit != null) search.set("limit", String(params.limit))
if (params.offset != null) search.set("offset", String(params.offset))
if (params.all != null) search.set("all", String(params.all))
if (params.resolved != null) search.set("resolved", String(params.resolved))
if (params.viewed != null) search.set("viewed", String(params.viewed))
if (params.source) search.set("source", params.source)
if (params.status) search.set("status", params.status)
if (params.q) search.set("q", params.q)
const query = search.toString()
return query ? `?${query}` : ""
}
function buildSidebarThreadsQuery(params: {
activeLimit?: number
resolvedLimit?: number
activeThreadId?: string
}): string {
const search = new URLSearchParams()
if (params.activeLimit != null) {
search.set("active_limit", String(params.activeLimit))
}
if (params.resolvedLimit != null) {
search.set("resolved_limit", String(params.resolvedLimit))
}
if (params.activeThreadId) {
search.set("active_thread_id", params.activeThreadId)
}
const query = search.toString()
return query ? `?${query}` : ""
}
export const agentsApi = {
langGraphApiUrl: agentsLangGraphApiUrl,
listSidebarThreads: (params: {
activeLimit?: number
resolvedLimit?: number
activeThreadId?: string
}) =>
agentsRequest<SidebarThreads>(
`/threads/sidebar${buildSidebarThreadsQuery(params)}`
),
listThreadsPage: (params: ThreadsPageParams = {}) =>
agentsRequest<ThreadsPage>(`/threads/page${buildThreadsPageQuery(params)}`),
resolveThread: (threadId: string, resolved: boolean) =>
agentsRequest<AgentThread>(
`/threads/${encodeURIComponent(threadId)}/resolve`,
{
method: "POST",
body: JSON.stringify({ resolved }),
}
),
listSchedules: () => agentsRequest<Array<AgentSchedule>>("/schedules"),
createSchedule: (body: ScheduleCreateRequest) =>
agentsRequest<AgentSchedule>("/schedules", {
method: "POST",
body: JSON.stringify(body),
}),
updateSchedule: (scheduleId: string, body: ScheduleUpdateRequest) =>
agentsRequest<AgentSchedule>(
`/schedules/${encodeURIComponent(scheduleId)}`,
{
method: "PATCH",
body: JSON.stringify(body),
}
),
deleteSchedule: (scheduleId: string) =>
agentsRequest<void>(`/schedules/${encodeURIComponent(scheduleId)}`, {
method: "DELETE",
}),
getThread: (threadId: string, options?: { markViewed?: boolean }) =>
agentsRequest<AgentThread>(
`/threads/${encodeURIComponent(threadId)}${
options?.markViewed === false ? "?mark_viewed=false" : ""
}`
),
queueMessage: (threadId: string, body: ThreadMessageRequest) =>
agentsRequest<AgentThread>(
`/threads/${encodeURIComponent(threadId)}/messages`,
{
method: "POST",
body: JSON.stringify(body),
}
),
cancelThread: (threadId: string) =>
agentsRequest<AgentThread>(
`/threads/${encodeURIComponent(threadId)}/cancel`,
{
method: "POST",
}
),
adminCancelThread: (threadId: string) =>
agentsRequest<AgentThread>(
`/admin/threads/${encodeURIComponent(threadId)}/cancel`,
{
method: "POST",
}
),
deleteThread: (threadId: string) =>
agentsRequest<void>(`/threads/${encodeURIComponent(threadId)}`, {
method: "DELETE",
}),
getThreadPrDiff: (threadId: string) =>
agentsRequest<ThreadPrDiff>(
`/threads/${encodeURIComponent(threadId)}/pr-diff`
),
downloadThreadRecoveryPatch: (threadId: string) =>
agentsBlobRequest(
`/threads/${encodeURIComponent(threadId)}/recovery.patch`
),
streamUrl: (threadId: string) =>
`${API_BASE}/dashboard/api/threads/${encodeURIComponent(threadId)}/stream`,
listWorkflowApprovals: (threadId: string) =>
agentsRequest<WorkflowPushApprovalsResponse>(
`/workflow-approval/${encodeURIComponent(threadId)}`
),
approveWorkflowPush: (threadId: string, fingerprint: string) =>
agentsRequest<WorkflowApprovalDecision>(
`/workflow-approval/${encodeURIComponent(threadId)}/${encodeURIComponent(
fingerprint
)}/approve`,
{ method: "POST" }
),
rejectWorkflowPush: (threadId: string, fingerprint: string) =>
agentsRequest<WorkflowApprovalDecision>(
`/workflow-approval/${encodeURIComponent(threadId)}/${encodeURIComponent(
fingerprint
)}/reject`,
{ method: "POST" }
),
}
export type ThreadGroup = "today" | "last7" | "last30" | "older"
export function groupThreads(
threads: Array<AgentThread>
): Record<ThreadGroup, Array<AgentThread>> {
const todayStart = new Date()
todayStart.setHours(0, 0, 0, 0)
const sevenDaysAgo = Date.now() - 7 * 24 * 60 * 60 * 1000
const thirtyDaysAgo = Date.now() - 30 * 24 * 60 * 60 * 1000
const groups: Record<ThreadGroup, Array<AgentThread>> = {
today: [],
last7: [],
last30: [],
older: [],
}
for (const thread of [...threads].sort((a, b) => b.updatedAt - a.updatedAt)) {
if (thread.updatedAt >= todayStart.getTime()) {
groups.today.push(thread)
} else if (thread.updatedAt >= sevenDaysAgo) {
groups.last7.push(thread)
} else if (thread.updatedAt >= thirtyDaysAgo) {
groups.last30.push(thread)
} else {
groups.older.push(thread)
}
}
return groups
}