Repository navigation
Conversation
Tests for the account holder, the audience check, the account-mode switch, the shared-use inbox and the app screens. They fail until the code lands. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… Personal or Shared mode Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…anded-over work Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ccount row carry its own heading Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… account-holding app a mode Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… from a signed run Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t it holds Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…request Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ounts Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y its published display name Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ccount's stored id Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…l on them Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t through each Bot Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nistrators the requests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…g for owners Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ming who acted Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s for its shared apps Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…audit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ployment's Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ount Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…red one on re-add Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…urn them to the admin page Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…uded Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… to readers Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… closed without a gate Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nd account holders Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…, never a duplicate A second mcp_servers row at the same composio:// address could mark a Shared app Personal and let calls through it skip the audience gate, or let a non-admin connect a personal account to it. Every account decision, the gate, the audit's reachedAs and the mode write now resolve the app's answering row, and the gate refuses if the mode changes before the call goes out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A Bot granted through a duplicate or non-canonical row of an app now gets the approval the audience gate actually reads, appears once in what it holds, and is found when the app's mode changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…wering row Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… is ended Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…a duplicate row Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…fault Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e vendor Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…hared beside the empty state Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…orget its rule on removal Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…o the running app Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… 37th positional argument Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e lint and format run Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two conflicts, both resolved by keeping each side: - `CHANGELOG.md`: 0.1.1 and 0.1.2 were cut while this branch was open, so the Unreleased section this branch writes now sits above them rather than in their place. The migration note's rollback target moves from 0.1.0 to 0.1.2, which is the release somebody would actually roll back to. - `server/src/app.ts`: an import-order collision only. Main's `createCoworkerRoutingService` import and this branch's shared-account imports landed in the same place; both are kept. Main's AG-UI 1.0 upgrade changes `@ag-ui/core` out from under this branch, so the merged tree needs `bun install` before it typechecks.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
An app's account can belong to the team
An administrator can make a Composio app Shared: one account, connected once, that every Bot granted the app acts as. Until now every brokered app was personal — each person connected their own mailbox or tracker, and a Bot acting for the team had no account of its own to use.
What this adds
brokered_connectionstable that records an account's holder — a person or the deployment — rather than assuming a person.Before upgrading
0052_shared_brokered_accountscopies every Composio connection intobrokered_connectionsand leavescomposio_connectionsin place, unwritten. Rolling back to 0.1.2 works, but accounts connected after the upgrade are invisible to it.mainis merged in as ofbb29c63. It carried the AG-UI 1.0 upgrade, so a checkout of this branch needsbun installbefore it typechecks.Verification
bun run formatbun run lintbun run typecheckThe suite was run in batches rather than as a single
bun test. A whole-suite run exhausts PostgreSQL's 100-connection limit locally (sorry, too many clients already), because the suite now has 91 test files that each open a 2-connection pool, up from 62 onmain. Every file passes; worth watching whether CI hits the same ceiling.Still open
bun run test:live-composio) has not been run. The test is written and gated behinddescribe.skipIf(!live), so it is inert without a key.🤖 Generated with Claude Code