Skip to content

Add cmux.com team-vault APIs for local Subrouter egress - #9099

Merged
lawrencecchen merged 19 commits into
mainfrom
feat-subrouter-local-egress
Jul 29, 2026
Merged

lawrencecchen merged 19 commits into
mainfrom
feat-subrouter-local-egress

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds the authenticated cmux.com control plane for shared Subrouter credentials. Every macOS or Linux client runs a loopback proxy and sends provider traffic from that machine. cmux.com selects the team account and brokers an access-only five-minute lease. Provider refresh tokens remain in the central Worker.

  • Stack device sessions authenticate sr login and team membership.
  • subrouter:use leases credentials; subrouter:manage_accounts uploads, repairs, and deletes them.
  • Upload and repair force one central refresh before success, transferring refresh-chain custody.
  • Native bearer failures cannot fall back to browser cookies. Browser mutations require same-origin CSRF checks.
  • API responses whitelist account metadata and never return provider refresh tokens, ID tokens, tenant keys, raw upstream errors, or provider endpoint overrides.
  • CLI authentication needs Stack Auth plus Postgres, and no longer depends on transcript S3 configuration.
  • Private beta access is restricted by SUBROUTER_ALLOWED_TEAM_IDS.
  • Safe operation/status logging makes control-plane failures diagnosable without logging credentials.

Depends on manaflow-ai/subrouter#99.

Deployment and canary

  • Durable staging control plane: https://cmux-staging.vercel.app
  • PR preview: https://cmux-hsjp16d1a-manaflow.vercel.app
  • Staging deployment: dpl_D3q6spAKA8vnL3Wsr3JkdR4ThceD
  • Production Worker: subrouter.cmux.dev, version 467267f5-fb1c-4d25-bacc-730a566a42ff
  • Worker staging: subrouter-staging.cmux.dev, version de30e48e-aa7d-4bb1-8704-a27dcd9d2e71
  • Real canary: sr login selected the Stack team, sr doctor passed, and sr codex exec returned exactly OK through the local daemon. The central account remained auth_valid: true with no refresh failure.

Verification

  • bun run typecheck
  • bun test tests/vault-route-helpers.test.ts tests/subrouter-accounts-route.test.ts tests/vm-route-auth.test.ts (82 pass)
  • Biome checks on touched files

Summary by CodeRabbit

  • New Features
    • Added credential lease creation and outcome reporting, plus lease events handling.
    • Added account repair support and refreshed team listing/selection with account-management permissions.
    • Added native-session logout for the subrouter.
  • Bug Fixes
    • Improved request validation and bounded payload handling across subrouter endpoints.
    • Prevented invalid native credentials from falling back to browser sessions.
    • Enhanced account listing/health details while avoiding credential exposure.
  • Documentation
    • Updated CLI auth route wiring to work correctly when vault storage configuration is absent.

@coderabbitai

coderabbitai Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The change centralizes subrouter authentication and request context handling, adds account repair, credential lease, logout, and team endpoints, strengthens account and lease validation/parsing, updates dashboard permissions and CLI vault wrappers, and expands related route and authentication tests.

Changes

Subrouter API and authorization

Layer / File(s) Summary
Authentication and request context
web/services/vms/auth.ts, web/services/subrouter/routeHelpers.ts, web/services/subrouter/requestContext.ts
Adds subrouter permission resolution, team allowlisting, native credential handling, and shared request-context construction.
Client contracts and input parsing
web/services/subrouter/client.ts, web/services/subrouter/accountInput.ts, web/services/subrouter/boundedJson.ts
Adds strict account and lease types, bounded JSON processing, provider-specific validation, account adoption/validation calls, lease operations, and response parsing.
Account creation, deletion, and repair
web/app/api/subrouter/accounts/**, web/app/[locale]/dashboard/components/ai-account-forms.tsx
Routes account operations through shared context and validated input, adds account repair, and updates account query forwarding.
Lease, logout, and team routes
web/app/api/subrouter/leases/**, web/app/api/subrouter/logout/route.ts, web/app/api/subrouter/teams/route.ts, web/app/lib/stack.ts
Adds credential lease creation/reporting, native-session logout, non-redirecting sign-out support, and team plus personal-scope listing.
Dashboard permission-aware rendering
web/app/[locale]/dashboard/subrouter/page.tsx
Uses authorized subrouter teams and conditionally renders account-management controls from manageAccounts.
Route and authentication validation
web/tests/subrouter-accounts-route.test.ts, web/tests/vm-route-auth.test.ts
Covers permissions, allowlisting, account sanitization, repair, leases, teams, logout, and native-authentication fallback rejection.

CLI authentication route wrappers

Layer / File(s) Summary
CLI route wrapper configuration
web/services/vault/routeHelpers.ts, web/app/api/vault/cli/auth/*/route.ts
Adds CLI-specific wrappers that do not require object-storage configuration and applies them to CLI authentication routes.
CLI and vault wrapper tests
web/tests/vault-route-helpers.test.ts
Verifies CLI routes remain available without object storage while transcript vault routes remain configuration-gated.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CLI
  participant LeaseRoute
  participant RequestContext
  participant TenantDatabase
  participant SubrouterClient
  CLI->>LeaseRoute: POST lease request
  LeaseRoute->>RequestContext: Resolve authenticated team context
  RequestContext->>TenantDatabase: Find shared tenant
  LeaseRoute->>SubrouterClient: Create credential lease
  SubrouterClient-->>LeaseRoute: Return lease
  LeaseRoute-->>CLI: Return teamId and lease JSON
Loading
🚥 Pre-merge checks | ✅ 24 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 3.13% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (24 passed)
Check name Status Explanation
Title check ✅ Passed It clearly summarizes the main change: new cmux.com team-vault APIs for local Subrouter egress.
Description check ✅ Passed It covers the required summary and verification details well, with only some template sections like demo video and checklist omitted.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PASS: The PR diff only touches TS/TSX files; no Swift files or SwiftUI/actor-isolation changes are introduced.
Cmux Swift Blocking Runtime ✅ Passed No Swift files were changed; the diff only touches TS/Next.js code and tests, so the Swift blocking-runtime rule is not applicable.
Cmux Browser Automation Off-Main ✅ Passed HEAD only changes web subrouter routes/tests; no browser automation Swift files or policy-routing code were touched, so the rule isn’t implicated.
Cmux Expensive Synchronous Load ✅ Passed PR diff only touches TS/JS files; no Swift sources or Xcode project files were changed, so the Swift sync-load rule is not applicable.
Cmux Cache Substitution Correctness ✅ Passed No authoritative fresh read was swapped for a cache in a persistence/snapshot path; the new caches are only for Stack app instances and per-request auth permissions.
Cmux No Hacky Sleeps ✅ Passed No hacky production waits were introduced; the only fixed sleep is test-only pacing, and the new timeouts are bounded deadline abstractions.
Cmux Algorithmic Complexity ✅ Passed No new nested rescans or repeated sorts on scalable collections; new team/lease paths are linear and bounded-concurrency, with explicit page/request caps.
Cmux Swift Concurrency ✅ Passed PASS: Diff against origin/main contains only TS/route/test changes; no Swift files or concurrency patterns were introduced.
Cmux Swift @Concurrent ✅ Passed No .swift files are changed in this diff, so the Swift concurrency annotation rule is not applicable.
Cmux Swift Package Boundaries ✅ Passed No Swift files or package changes are in the diff, so the Swift boundary rule is not applicable.
Cmux Swiftpm Lockfiles ✅ Passed No Package.swift, Package.resolved, Xcode, workflow, or cmux-owned .gitignore changes appear in the PR diff, so the SwiftPM lockfile rule isn’t triggered.
Cmux Swift Logging ✅ Passed PASS: The diff touches only web TS/TSX files; no Swift files or Swift logging statements were added or changed.
Cmux User-Facing Error Privacy ✅ Passed New routes return only generic error bodies (invalid_request, forbidden, service_unavailable, upstream_request_failed); no vendor names, raw upstream text, or secrets are exposed.
Cmux Full Internationalization ✅ Passed Changed dashboard copy comes from next-intl keys already present across locales; API payload strings are machine codes, and no locale catalogs were regressed.
Cmux Swiftui State Layout ✅ Passed Diff only touches TS/JS control-plane files; no SwiftUI/AppKit files or state-layout patterns are present.
Cmux Architecture Rethink ✅ Passed PASS: The PR only touches TypeScript/Next.js files; no Swift code or Swift-architecture patterns are introduced.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR diff contains no Swift files, so the auxiliary-window close-shortcut rule is not applicable.
Cmux Source Artifacts ✅ Passed All changed paths are hand-written TS source/test files; no logs, caches, build output, binaries, or scratch artifact dirs appear in the diff.
Cmux No Test Or Debug Seam In Production Source ✅ Passed No Swift production-source files under Sources/ were changed; the commit only touches TS and test files, so the rule is not applicable.
Cmux No Ambient Global State ✅ Passed PASS: The rule applies only to production Swift code, and the PR diff contains only TS/TSX files—no .swift changes or new ambient global Swift state.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-subrouter-local-egress

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2aa57dcdc5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/app/api/subrouter/logout/route.ts Outdated
Comment thread web/services/subrouter/requestContext.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 9

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/app/api/subrouter/accounts/`[accountId]/repair/route.ts:
- Around line 19-23: Extract the duplicated trim-and-200-character validation
into a shared normalizeAccountId helper, then update the repair route and the
accounts route to use it. Preserve the existing invalid_request 400 response
when normalization returns null, and use the helper’s normalized value for valid
requests.

In `@web/app/api/subrouter/logout/route.ts`:
- Around line 18-23: Wrap the Stack Auth calls in the logout route—specifically
getStackServerApp().getUser and user.signOut—in try/catch handling, and return
the established subrouterErrorResponse for failures. Preserve the unauthorized
response when no user is found and the existing successful logout flow.
- Around line 10-20: Replace the inline authorization and refresh-token parsing
in the logout route with the shared token-parsing logic used by verifyRequest in
auth.ts, extracting or reusing a helper such as parseNativeStackTokens(request).
Preserve the existing unauthorized response for missing or invalid tokens and
pass the parsed accessToken and refreshToken to getStackServerApp().getUser.

In `@web/app/api/subrouter/teams/route.ts`:
- Around line 44-51: In the response-building logic, extract user.selectedTeamId
?? user.billingTeamId into a local constant before the teams.some check, then
reuse that constant for both the membership comparison and selectedTeamId value
while preserving the existing null fallback behavior.

In `@web/services/subrouter/boundedJson.ts`:
- Around line 21-35: Update the reader-processing try/catch in bounded JSON
parsing so the reader lock is always released via a finally block, including
read errors and overflow returns. Preserve the existing cancellation and
response statuses while ensuring cleanup runs on every exit path.

In `@web/services/subrouter/client.ts`:
- Around line 418-424: Update parseAccountHealth to treat null the same as
undefined by returning undefined before the record validation. Preserve the
existing validation and SubrouterClientError behavior for non-null values that
are not valid health records, allowing parseAccountList to continue when an
account’s health is explicitly absent.

In `@web/services/subrouter/routeHelpers.ts`:
- Around line 62-71: Update subrouterTeamAllowed so an unset or empty
SUBROUTER_ALLOWED_TEAM_IDS value denies all teams by default. Preserve matching
for explicitly listed team IDs, and support an explicit wildcard such as "*" to
intentionally allow all teams; do not retain the current implicit allow-all
behavior.

In `@web/services/vms/auth.ts`:
- Around line 196-198: Update the catch block in the permission-checking flow of
auth.ts to capture and log the caught error server-side before returning { use:
false, manageAccounts: false }. Preserve the existing fail-closed return
behavior and avoid exposing error details to clients.
- Around line 140-148: Update the permission configuration around
enforceSubrouterPermissions and subrouterPermissions so enforcement is enabled
by default, with only an explicit opt-out disabling it; ensure disabled or
invalid configuration fails closed rather than granting permissions. In the
enforced branch, run the two hasPermission checks concurrently with Promise.all
while preserving their existing permission results.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 5b16c1cc-5016-4b68-a1be-a202dfbccce4

📥 Commits

Reviewing files that changed from the base of the PR and between d61e668 and 2aa57dc.

📒 Files selected for processing (16)
  • web/app/[locale]/dashboard/components/ai-account-forms.tsx
  • web/app/api/subrouter/accounts/[accountId]/repair/route.ts
  • web/app/api/subrouter/accounts/[accountId]/route.ts
  • web/app/api/subrouter/accounts/route.ts
  • web/app/api/subrouter/leases/[leaseId]/events/route.ts
  • web/app/api/subrouter/leases/route.ts
  • web/app/api/subrouter/logout/route.ts
  • web/app/api/subrouter/teams/route.ts
  • web/services/subrouter/accountInput.ts
  • web/services/subrouter/boundedJson.ts
  • web/services/subrouter/client.ts
  • web/services/subrouter/requestContext.ts
  • web/services/subrouter/routeHelpers.ts
  • web/services/vms/auth.ts
  • web/tests/subrouter-accounts-route.test.ts
  • web/tests/vm-route-auth.test.ts

Comment thread web/app/api/subrouter/accounts/[accountId]/repair/route.ts
Comment thread web/app/api/subrouter/logout/route.ts Outdated
Comment thread web/app/api/subrouter/logout/route.ts Outdated
Comment thread web/app/api/subrouter/teams/route.ts Outdated
Comment thread web/services/subrouter/boundedJson.ts
Comment thread web/services/subrouter/client.ts
Comment thread web/services/subrouter/routeHelpers.ts
Comment thread web/services/vms/auth.ts Outdated
Comment thread web/services/vms/auth.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/app/`[locale]/dashboard/subrouter/page.tsx:
- Around line 84-85: Update the teams filter in the dashboard page to retain
candidates where either use or manageAccounts is true, preserving accounts-only
managers for the permission-gated controls. Add coverage for a candidate with
manageAccounts true and use false.

In `@web/app/api/subrouter/teams/route.ts`:
- Around line 20-36: The teams response currently maps authorized teams and then
performs a second scan with teams.some. Replace this with a single iteration in
the route handler that builds teams while recording whether the preferred
selectedTeamId or billingTeamId was emitted, then return that recorded ID or
null without rescanning the collection.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b9e09133-3189-4b26-85d5-958196f7b2c1

📥 Commits

Reviewing files that changed from the base of the PR and between 752e049 and 27424cf.

📒 Files selected for processing (4)
  • web/app/[locale]/dashboard/subrouter/page.tsx
  • web/app/api/subrouter/logout/route.ts
  • web/app/api/subrouter/teams/route.ts
  • web/app/lib/stack.ts

Comment thread web/app/[locale]/dashboard/subrouter/page.tsx Outdated
Comment thread web/app/api/subrouter/teams/route.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
web/services/vms/auth.ts (1)

144-145: 🔒 Security & Privacy | 🔴 Critical | ⚡ Quick win

Permission enforcement remains fail-open by default (unresolved from prior review).

enforceSubrouterPermissions is still only true when SUBROUTER_ENFORCE_STACK_PERMISSIONS === "1", and subrouterPermissions (Line 197) returns { use: true, manageAccounts: true } whenever enforcement is off. Any deployment that omits this env var still grants every authenticated team member subrouter:use and subrouter:manage_accounts, which gate credential upload, repair, deletion, and lease issuance downstream.

Invert the default so enforcement is the standard behavior and the bypass is an explicit opt-out.

🔒 Proposed fix: enforce by default
-  const enforceSubrouterPermissions =
-    process.env.SUBROUTER_ENFORCE_STACK_PERMISSIONS === "1";
+  // Opt-out only; an unset env var must not silently grant every permission.
+  const enforceSubrouterPermissions =
+    process.env.SUBROUTER_ENFORCE_STACK_PERMISSIONS !== "0";

As per coding guidelines, "Do not add an unreliable fallback, guess, default, or 'best effort' branch when an incorrect value would be a correctness bug; fail closed instead."
[source_coding_guidelines,source_other]

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/services/vms/auth.ts` around lines 144 - 145, Update the
enforceSubrouterPermissions initialization in auth.ts so subrouter permission
enforcement is enabled by default; only an explicit opt-out environment value
should disable it. Preserve the existing enforcement and subrouterPermissions
behavior once the flag is resolved, ensuring omitted or unrecognized values
remain fail-closed.
♻️ Duplicate comments (2)
web/services/vms/auth.ts (1)

210-212: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

Silent catch still hides permission-service failures.

Failing closed is correct, but with no logging an outage in Stack's permission API is indistinguishable from a legitimate denial. This was flagged in a prior review and remains unaddressed. Log the error server-side before returning the closed result.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/services/vms/auth.ts` around lines 210 - 212, Update the catch block in
the permission-checking flow to capture and server-side log the caught
permission-service error before returning { use: false, manageAccounts: false }.
Preserve the existing fail-closed return behavior while ensuring the log
includes the actual error details.
web/services/subrouter/routeHelpers.ts (1)

167-176: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Allowlist still defaults to allow-all (unresolved from prior review).

Per the described behavior, subrouterTeamAllowed still allows all teams when SUBROUTER_ALLOWED_TEAM_IDS is unset/empty. Combined with enforceSubrouterPermissions also defaulting off (web/services/vms/auth.ts Lines 144-145), an unconfigured deployment has no effective authorization on credential upload, deletion, repair, or lease issuance.

Treat an unset/empty list as "no teams allowed" and require an explicit wildcard (e.g. *) to intentionally open access.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/services/subrouter/routeHelpers.ts` around lines 167 - 176, Update
subrouterTeamAllowed so an unset or empty SUBROUTER_ALLOWED_TEAM_IDS value
denies every team instead of allowing all; only return true for all teams when
the parsed allowlist explicitly contains the wildcard entry “*”, while
preserving explicit team-ID matching.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/tests/subrouter-accounts-route.test.ts`:
- Around line 775-815: Replace the real setTimeout delay in the “resolves one
permission snapshot per scope with bounded concurrency” test with manually
controlled promise resolvers: collect each listPermissions call’s resolver, wait
until enough calls are in flight to prove overlap, then release them so all
requests complete. Keep the existing concurrency assertions and permission-call
behavior without relying on wall-clock timing.

---

Outside diff comments:
In `@web/services/vms/auth.ts`:
- Around line 144-145: Update the enforceSubrouterPermissions initialization in
auth.ts so subrouter permission enforcement is enabled by default; only an
explicit opt-out environment value should disable it. Preserve the existing
enforcement and subrouterPermissions behavior once the flag is resolved,
ensuring omitted or unrecognized values remain fail-closed.

---

Duplicate comments:
In `@web/services/subrouter/routeHelpers.ts`:
- Around line 167-176: Update subrouterTeamAllowed so an unset or empty
SUBROUTER_ALLOWED_TEAM_IDS value denies every team instead of allowing all; only
return true for all teams when the parsed allowlist explicitly contains the
wildcard entry “*”, while preserving explicit team-ID matching.

In `@web/services/vms/auth.ts`:
- Around line 210-212: Update the catch block in the permission-checking flow to
capture and server-side log the caught permission-service error before returning
{ use: false, manageAccounts: false }. Preserve the existing fail-closed return
behavior while ensuring the log includes the actual error details.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f7ed2f3a-ef75-42fc-b6d9-bdd77fc844fe

📥 Commits

Reviewing files that changed from the base of the PR and between 27424cf and 17aaf42.

📒 Files selected for processing (5)
  • web/app/api/subrouter/leases/route.ts
  • web/services/subrouter/client.ts
  • web/services/subrouter/routeHelpers.ts
  • web/services/vms/auth.ts
  • web/tests/subrouter-accounts-route.test.ts

Comment thread web/tests/subrouter-accounts-route.test.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cac38df8e6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/services/vms/auth.ts
@cursor

cursor Bot commented Jul 29, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@lawrencecchen
lawrencecchen merged commit 6f58efb into main Jul 29, 2026
6 checks passed
@lawrencecchen
lawrencecchen deleted the feat-subrouter-local-egress branch July 29, 2026 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant