Brad Groux
a58496839d
fix: workflow correctness — human gate blocking, retry bounds, HTTP errors, shared contracts, depends_on enforcement ( #805 )
...
Fixes #778 , #780 , #785 , #786 , #787
## #778 — Human gate blocking/resume correctness
- Introduce HumanGateBlockError in WorkflowStepExecutor; gate steps with
on_false.escalate_to=human now throw this typed exception instead of a
plain Error.
- executeRun() catches HumanGateBlockError before handleStepFailure() so the
run transitions to blocked (not failed); persists _gateBlock context.
- Add approveGateStep() and rejectGateStep() service methods; fix route
endpoints to persist state and validate run.status===blocked.
## #780 — Bounded retry_step cycles
- Add max_reroutes field to FailurePolicy and retryRouteCount to WorkflowRun
in both shared and server type contracts.
- handleStepFailure increments and checks retryRouteCount on every retry_step
reroute; defaults to MAX_REROUTES_DEFAULT=10; exhaustion fires on_exhausted
policy or fails deterministically.
- retryRouteCount persists to disk/SQLite; survives process restart.
## #785 — WorkflowRunService domain errors → HTTP mapping
- Remove private NotFoundError and ValidationError from workflow-run-service.ts.
- Import and throw the shared AppError-based NotFoundError/ValidationError from
middleware/error-handler.ts so central error middleware maps them to 404/400.
## #786 — Shared workflow contracts
- Add provider? and command? fields to WorkflowAgent in
shared/src/types/workflow.ts to match the server-side definition and expose
them to web, CLI, and MCP consumers.
## #787 — depends_on enforcement during status transitions
- BlockingService refactored to merge both legacy blockedBy and canonical
dependencies.depends_on (deduplication via Set) in getBlockingStatus(),
canMoveToInProgress(), getDependentTasks(), and
wouldCreateCircularDependency().
- Tasks route transition guard now triggers when either blockedBy or
dependencies.depends_on is non-empty.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-10 12:16:51 -05:00
Brad Groux
999acb6317
Add canonical AGENTS guidance and validated Hermes/OpenClaw providers ( #803 )
...
* feat: add AGENTS.md, hermes-cli provider, and validated OpenClaw gateway dispatch
Issue #790 : Add canonical AGENTS.md as the source-of-truth repository
instruction file for Codex, OpenClaw, Hermes, Claude, and other compatible
coding harnesses. Correct stale pnpm (9+ → ≥ 11.0.0) and Node (22+ → ≥ 22.22.1)
version requirements. Convert CLAUDE.md to a Claude-specific supplement.
Issue #791 : Add first-class hermes-cli provider for Hermes Agent v2026.7.7.2.
- Add hermes-cli to AgentProvider type in shared/src/types/config.types.ts
- Add buildSafeHermesEnv utility with Hermes-specific env allowlist
- Add hermes-cli auth probe to AgentHealthService (hermes --version + API key check)
- Add hermes-cli provider adapter that spawns hermes -z <prompt> in task worktree
without a shell, captures stdout/stderr/exit code, records session identity
- Add SIGTERM with bounded SIGKILL fallback for graceful stop
- Document limitations: resume not supported in this release
Issue #794 : Fix OpenClaw gateway dispatch for task and workflow runs.
- Add OpenClawGatewayPreflightResult type and preflight() method to
HttpOpenClawWorkflowAdapter that verifies sessions_spawn policy before dispatch
- Add HttpOpenClawTaskAdapter that uses sessions_spawn to dispatch tasks via the
gateway HTTP API (replacing the broken request-file approach)
- Store childSessionKey in PendingAgent for durable session tracking
- Policy denial surfaces an actionable configHint pointing to gateway tool policy
- Add openclawSessionKey and hermesSessionId to PendingAgent interface
Add contract and regression tests:
- hermes-provider.test.ts: env utility, key sensitivity, health service
- openclaw-provider.test.ts: preflight scenarios (blocked, timeout, 403, ok: false, success)
and spawnTask scenarios (policy denial, missing key, success, timeout, forbidden status)
Update docs/AGENT-PROVIDERS.md with Hermes and OpenClaw setup sections.
Update CHANGELOG.md Unreleased section.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: address GPT review findings for harness providers
- preserve Hermes base allowlist when sandbox passthrough keys are present
- add hermes-cli sandbox capability mapping and built-in preset auth keys
- treat OpenClaw transport failures as unreachable in gateway preflight
- parse text-wrapped MCP tool results in OpenClaw task dispatch
- extend contract tests for the reviewed regressions
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: align OpenClaw dispatch with current gateway contract
Persist acknowledged child session keys atomically without overwriting newer attempt state.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-07-10 11:27:33 -05:00
Brad Groux
5bd4377f32
Add external tracker schema introspection
...
Adds configurable external tracker schema introspection, mapping profiles, validation, dry-run create, and approved mock create support.
2026-06-26 14:28:59 -05:00
Brad Groux
7950fec5f4
Add reflection memory promotion queue
...
Adds a reviewed reflection candidate queue, API, Settings UI, duplicate merge flow, task lesson promotion, redaction, docs, and tests.
2026-06-26 14:00:51 -05:00
Brad Groux
b9a648afe7
Add ceremony enforcement gates ( #750 )
2026-06-26 13:35:45 -05:00
Brad Groux
13fc8ac083
Add human reply communication adapters ( #749 )
2026-06-26 13:08:22 -05:00
Brad Groux
1b29b2eb24
Add Squad Chat collaboration state ( #748 )
2026-06-26 12:42:14 -05:00
Brad Groux
9abd06dd0e
Add policy-gated queue intake monitors
...
Add GitHub-backed queue monitor service, APIs, CLI commands, Settings queue dashboard, scheduler integration, operations digest activity, tests, and documentation.
2026-06-26 11:40:11 -05:00
Brad Groux
5b363303c4
Add unified recurring work scheduler
...
Add scheduler APIs, CLI commands, settings UI, retry/event state, telemetry hooks, and documentation over scheduled deliverables and workflow schedules.
2026-06-26 11:06:45 -05:00
Brad Groux
fbff5b5c40
Add workspace capability discovery and intake
...
Add config-backed workspace capability discovery, trusted intake APIs, CLI commands, settings UI, and delegated work status links.
2026-06-26 10:45:47 -05:00
Brad Groux
c6eed92631
Add team roster routing manifests
...
Add config-backed team roster manifests, route preview APIs, and roster-first agent routing.
2026-06-26 10:12:49 -05:00
Brad Groux
ca2dd7ef23
Add shared live run sessions ( #731 )
2026-06-18 16:49:55 -05:00
Brad Groux
43c21b71a4
Add decision review sessions
...
Adds task-linked multi-participant decision review sessions with ordered critique rounds, final packet attachment, export support, API/UI integration, docs, and regression coverage.
2026-06-18 16:16:05 -05:00
Brad Groux
4a0c66d331
Add reusable agent profile packages ( #729 )
...
* Add reusable agent profile packages
* Add profile CLI permission coverage
2026-06-18 15:53:47 -05:00
Brad Groux
8686803350
Implement agent run budget enforcement
...
Adds enforceable agent and workflow run budgets with governance traces, UI controls, completion evidence, docs, and regression coverage.
2026-06-18 15:22:45 -05:00
Brad Groux
398d6024af
Add sandbox policy presets ( #727 )
2026-06-18 14:44:27 -05:00
Brad Groux
aa062d79b2
feat(tasks): soft-delete tasks into archive
...
* feat(tasks): soft-delete tasks into archive
* Harden soft-delete restore behavior
* Avoid async task directory setup race
---------
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-06-09 06:01:57 -05:00
Brad Groux
f82741fde4
Add local LLM agent providers ( #695 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-06 15:26:12 -05:00
Brad Groux
446def7e8d
Add configurable board columns
...
Adds configurable board columns and dynamic task statuses across the board, server validation, summaries, CLI, MCP, and docs.
Closes #640 .
2026-06-05 11:44:10 -05:00
Brad Groux
d796c3df27
Add session template recommendations ( #638 )
2026-06-05 10:53:40 -05:00
Brad Groux
c3716c1a85
Add agent host routing health ( #636 )
2026-06-05 10:06:17 -05:00
Brad Groux
0b33699684
Add editable time breakdown exports ( #635 )
2026-06-05 09:43:04 -05:00
Brad Groux
f6f0bd31ca
Add source-backed evidence timeline ( #634 )
2026-06-05 09:24:54 -05:00
Brad Groux
ad151ab5cc
Apply desktop remote destination policy ( #629 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-05 02:45:56 -05:00
Brad Groux
00ba51f252
Restrict work product source link schemes ( #628 )
2026-06-05 00:14:46 -07:00
Brad Groux
b93adbcb9f
Redact settings webhook URLs ( #623 )
...
* Redact settings webhook URLs
* Use full settings fixtures in route coverage
2026-06-04 22:35:50 -07:00
Brad Groux
0a0e751a38
Enforce local agent control capability ( #619 )
2026-06-04 21:28:58 -07:00
Brad Groux
973be6bcf3
Require execute permission for Codex review ( #618 )
2026-06-04 21:15:56 -07:00
Brad Groux
854b6429ed
Add agent health classifier ( #592 )
2026-06-04 17:27:54 -07:00
Brad Groux
438301dd1e
Add watcher continuation policy gates ( #591 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-04 16:01:16 -07:00
Brad Groux
2cd7fe2ad2
Add prompt template import command
2026-06-04 01:01:14 -07:00
Brad Groux
68fb90a939
Add saved board views
2026-06-03 23:50:37 -07:00
Brad Groux
ea352fcac9
Add orchestrator pipelines and product modes
...
Add first-class orchestrator pipeline metadata, OpenClaw audit recipe support, persisted product modes, and the related UI, docs, and regression coverage.
2026-06-03 07:34:51 -07:00
Brad Groux
7fac1b8977
Add skill risk gates
2026-06-03 07:02:44 -07:00
Brad Groux
a9217784b3
Add skill security scanner ( #538 )
2026-06-03 06:33:05 -07:00
Brad Groux
4274171a8a
Add skill capability profiles
2026-06-03 06:09:29 -07:00
Brad Groux
abfac7c446
Add governance decision traces
2026-06-03 05:45:59 -07:00
Brad Groux
62f258052c
Add v5 maintenance center ( #535 )
2026-06-03 05:02:57 -07:00
Brad Groux
fd96f73408
Harden v5 security review surfaces ( #531 )
2026-06-03 03:55:22 -07:00
Brad Groux
58f39ea2b5
Implement secure device pairing sessions
...
Add signed pairing-code exchange, hashed device session secrets, identity device session management, desktop pairing onboarding, docs, and regression coverage.
2026-06-03 02:02:22 -07:00
Brad Groux
17799f3f72
Add workflow recipe authoring and dry-run linting
...
Adds workflow recipe authoring, visual/YAML dry-run linting, and output/schedule metadata for v5 workflows.
2026-06-03 01:12:57 -07:00
Brad Groux
de5183ed0e
Capture agent stream and retry trace events ( #523 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-03 00:12:15 -07:00
Brad Groux
7b64a5388b
Add work product maintenance preview ( #522 )
2026-06-02 23:59:05 -07:00
Brad Groux
8d854a1786
Add task readiness start gate ( #517 )
2026-06-02 22:54:42 -07:00
Brad Groux
f4146b9b1f
Add agent timeline links and entry points
...
Enrich agent run timeline navigation and linked evidence from dashboard, workflow, notification, approval, and work-product surfaces.
2026-06-02 22:22:26 -07:00
Brad Groux
af7e68c541
Add agent run timeline replay view
2026-06-02 14:22:27 -07:00
Brad Groux
28aee90b82
feat: add actor attribution and optimistic concurrency
...
## Summary
- adds task/comment/workflow revision metadata, ETag headers, and stale-write 409 conflict responses
- records actors on task, comment, activity, audit, and workflow API mutations
- sends cached revisions from web task/comment mutations and reloads the current task on conflicts
- documents the conflict contract and adds route/API regression coverage
## Verification
- `VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/tasks-coverage.test.ts server/src/__tests__/routes/optimistic-concurrency.test.ts`
- `node_modules/.bin/prettier --check server/src/__tests__/routes/tasks-coverage.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `git diff --check`
- PR checks: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 10:54:53 -05:00
Brad Groux
cb70bc42f9
fix: tighten agent approval RBAC guards
...
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
## Summary
- splits agent register, permission, and routing route guards so read-like POSTs stay available without treating all agent self-service POSTs as read-only safe
- requires task:write for agent approval requests, telemetry:write for agent registration writes, and admin:manage for approval review/routing configuration/permission elevation
- mirrors the route guard changes in the shared CLI/MCP permission preflight map
- expands REST, CLI, and MCP authorization tests for read-only mutation denial and scoped agent approval requests
Closes #336 .
## Verification
- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts
- node scripts/check-permission-coverage.mjs
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/server typecheck
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/routes/v1/permissions.ts server/src/routes/v1/index.ts shared/src/utils/api-permissions.ts server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts docs/security.md
- git diff --check
## Notes
- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
- pnpm --filter @veritas-kanban/mcp typecheck is not available because the package has no typecheck script; pnpm --filter @veritas-kanban/mcp build covers TypeScript compilation.
2026-05-31 05:53:32 -05:00
Brad Groux
3f5c9a03af
feat: enforce CLI and MCP token permissions
...
## Summary
- adds a shared client-side API permission mapper and guarded API client for CLI and MCP calls
- exposes a non-secret /api/auth/context endpoint for scoped token preflight
- routes CLI and MCP task lookup helpers through the guarded client
- preflights direct summary text fetches that bypass the JSON API helper
- adds focused CLI and MCP token authorization coverage and documents the behavior
Refs #336 .
## Verification
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm --filter @veritas-kanban/server typecheck
- focused CLI and MCP api-permissions tests
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:35:10 -05:00
Brad Groux
b502872b49
feat: add durable work product foundation
...
Summary:
- adds typed durable work product render contracts
- adds SQLite work_products, work_product_versions, and work_product_search storage
- adds create, list, refine, archive, restore, preview, and export APIs
- wires work products into task-scoped APIs and keyword search
- adds redacted preview/export behavior and SQLite regression coverage
- documents the work product API and SQLite schema
Verification:
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- ./node_modules/.bin/prettier --check README.md docs/SQLITE-SCHEMA.md docs/features/work-products.md shared/src/types/work-product.types.ts shared/src/types/index.ts server/src/schemas/work-product-schemas.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/work-product-repository.ts server/src/services/work-product-service.ts server/src/routes/work-products.ts server/src/routes/v1/index.ts server/src/routes/search.ts server/src/services/search-service.ts server/src/__tests__/storage/sqlite-work-products.test.ts
- pnpm --filter @veritas-kanban/server test -- sqlite-work-products
- pnpm typecheck
- pnpm lint:budget
- pnpm --filter @veritas-kanban/server test
- pnpm build
- pnpm audit --prod --audit-level=high
- git diff --check
Part of #403 .
Part of #332 .
2026-05-31 01:31:00 -05:00