Peter Steinberger
976d99995a
perf(test): await 1Password descendant cleanup ( #125321 )
2026-08-17 09:48:00 -07:00
Peter Steinberger
568b920b21
feat(lint): enforce import ordering and deduplication ( #124730 )
...
* refactor(imports): dedupe and hoist imports
* feat(lint): enforce import/no-duplicates and import/first
2026-08-16 11:44:52 -07:00
Peter Steinberger
447393dc32
test(core): remove residual duplicate assertions ( #124116 )
2026-08-15 02:06:44 -07:00
Peter Steinberger
5d601233df
refactor(types): remove chained type assertions in extensions ( #124079 )
...
* refactor(types): remove chained assertions in extensions
* fix(codex): preserve canonical binding identity
2026-08-15 01:39:26 -07:00
Peter Steinberger
cad77fb39c
refactor: consolidate remaining coercion helpers ( #122020 )
2026-08-11 10:22:01 -07:00
Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Peter Steinberger
b6b937d6ac
chore(types): give test helpers nameable exported types ( #121783 )
2026-08-10 18:17:50 -07:00
Peter Steinberger
8616c0c374
refactor: finish shared test helper migrations ( #120996 )
...
* test: finish shared helper migrations
* test: fix helper migration CI
* style: fix test import ordering
* test(acpx): restore deferred void types
* test: fix helper migrations after rebase
2026-08-09 06:00:06 -07:00
Peter Steinberger
deb682abfe
refactor(plugins): consolidate extension runtime helpers ( #118509 )
...
* refactor(plugins): consolidate extension runtime helpers
* fix(ci): satisfy extension type and lint checks
* chore(plugin-sdk): regenerate API baseline for #118509
2026-08-03 02:56:43 -07:00
Peter Steinberger
30b7a3acb7
test(onepassword): speed resolver process fixtures ( #118102 )
...
* test(onepassword): speed resolver process fixtures
* test(onepassword): relax staged resolver deadline
* test(onepassword): canonicalize timeout fixture shell
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
2026-08-02 11:31:08 -07:00
Peter Steinberger
4b26a15a1f
refactor: remove dead internal exports ( #117819 )
2026-08-01 22:01:38 -07:00
Peter Steinberger
302f262e6b
refactor: deduplicate extension normalization primitives ( #115650 )
...
* refactor(plugins): reuse SDK normalization primitives
* fix(ci): repair code-mode matrix checks
* fix(ci): satisfy code-mode matrix gates
* fix(ci): use matrix evidence export
* fix(ci): validate matrix evidence artifact
2026-07-29 04:10:06 -04:00
Peter Steinberger
7be5c0a7c9
test(plugins): repair prerelease fixture contracts ( #113877 )
...
* test(plugins): repair prerelease fixtures
* test(onepassword): run resolver fixture from source
* test(moonshot): align catalog input fixtures
2026-07-25 14:54:39 -07:00
Peter Steinberger
481d826ff4
fix(vault): prevent insecure secrets plan writes ( #113707 )
...
* fix(vault): harden secrets plan writes
* fix(secrets): avoid env marker collision
* style(secrets): type plan write rejection
* refactor(onepassword): remove obsolete path resolver
* fix(secrets): preserve Windows plan path trust
* refactor(secrets): compact ACL token policy
* fix(secrets): route permission checks through facade
2026-07-25 08:27:33 -07:00
joshavant
f153858045
fix(onepassword): make SecretRef setup production-safe
2026-07-25 06:03:30 -05:00
joshavant
56bf326371
fix(onepassword): bound SecretRef resolution lifecycle
2026-07-25 06:03:30 -05:00
joshavant
fb8589ebdb
fix(onepassword): harden trusted op execution
2026-07-25 06:03:30 -05:00
sallyom
f045f33a62
feat(onepassword): add managed SecretRef integration
2026-07-25 06:03:30 -05:00
Peter Steinberger
8bf4d388b0
fix(onepassword): disable desktop-app integration on broker op calls ( #109157 )
...
Without OP_LOAD_DESKTOP_APP_SETTINGS=false and OP_BIOMETRIC_UNLOCK_ENABLED=false,
op 2.35 on macOS reads the 1Password desktop app's settings even on the
service-account path and can block on a per-PID App Data Protection dialog,
hanging the broker until timeoutMs on Mac gateway hosts.
2026-07-16 09:15:03 -07:00
Peter Steinberger
e1fda44ecc
fix(onepassword): preserve oversized token diagnostics ( #108964 )
2026-07-16 04:52:36 -07:00
wahaha1223
df72216580
fix(onepassword): reject oversized service account token files ( #108596 )
...
* fix(onepassword): reject oversized service account token files
* fix(onepassword): clarify oversized token errors
Co-authored-by: wahaha1223 <0668001153@xydigit.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 02:48:49 -07:00
Peter Steinberger
30738a3c3b
fix(onepassword): preserve authorization handoff
2026-07-14 23:23:17 -04:00
Peter Steinberger
3d15bf513e
fix(onepassword): preserve pending tool authorization ( #107275 )
...
* fix(onepassword): preserve pending tool authorization
* refactor(onepassword): consume pending authorization in helper
* chore: defer release note generation
2026-07-14 01:12:04 -07:00
mushuiyu886
ef25cefc8e
fix(onepassword): validate audit limit strictly ( #106926 )
...
* fix(onepassword): validate audit limit strictly
* test(onepassword): strengthen audit limit coverage
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-13 21:37:07 -07:00
Leon-SK668
5864fa2dbf
fix(onepassword): preserve Unicode in audit reason truncation ( #106424 )
...
* fix(onepassword): preserve Unicode in audit reason truncation
* test(onepassword): strengthen Unicode audit boundary proof
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-13 17:01:14 -07:00
Peter Steinberger
db02a96c4c
refactor(process): route bounded commands through Execa ( #106495 )
...
* refactor(process): centralize bounded command execution
* refactor(process): migrate core one-shot commands
* refactor(plugins): migrate one-shot commands
* fix(process): await Windows tree termination
* chore(plugin-sdk): refresh process runtime surface
* refactor(process): migrate remaining bounded commands
* refactor(process): normalize command result handling
* refactor(process): split execution responsibilities
* chore(plugin-sdk): refresh API baseline
* chore(process): remove release-owned changelog entry
* fix(process): narrow binary command input checks
* fix(process): cap sandbox command output
* fix(qa-lab): preserve exact node probe env
* chore(ci): refresh dead export baseline
* fix(process): preserve force-kill command deadlines
* fix(process): avoid post-exit timeout reclassification
* test(process): update scp staging wrapper mock
* test(process): update remaining wrapper mocks
* refactor(qa-lab): preserve Execa tar execution
2026-07-13 11:07:35 -07:00
Peter Steinberger
6bb85f177f
feat(onepassword): optional 1Password secrets broker plugin ( #106133 )
...
* feat(onepassword): add optional 1Password secrets broker plugin
Curated slug registry with per-item auto/approve/deny policy, plugin-approval
gating with expiring allow-always grants, SQLite audit history, onepassword
status/audit CLI, and a single-attempt op client (--cache=false, minimal env).
Closes #105924
* docs(plugins): refresh generated inventory count after rebase
* fix(onepassword): scope grants and field reads
* fix(onepassword): bound grant retention
* fix(onepassword): satisfy deadcode ratchet and hook allowlist contract
* fix(onepassword): honor live policy reloads
* refactor(onepassword): trim private exports
* test(onepassword): satisfy plugin boundaries
* test(onepassword): document temp directory boundary
2026-07-13 03:12:47 -07:00