Skip to content

Move hosted Subrouter onboarding to Stack Auth - #9261

Merged
lawrencecchen merged 78 commits into
mainfrom
feat-subrouter-user-onboarding
Aug 4, 2026
Merged

lawrencecchen merged 78 commits into
mainfrom
feat-subrouter-user-onboarding

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Replaces the database-backed CLI auth bridge with Stack Auth native CLI authentication:

  • publishes non-secret CLI configuration at /api/cli/config
  • removes the hand-rolled /api/vault/cli/auth flow and its Aurora tables
  • sends dashboard account operations directly to the hosted Subrouter using the caller Stack session
  • keeps Stack team permissions and browser mutation protection on the web routes
  • removes the obsolete lease, team, and logout routes

Go service dependency: manaflow-ai/subrouter#120

Verification:

  • bun run typecheck
  • bun run test (870 pass, 128 intentionally skipped)
  • bun run db:check
  • focused ESLint with zero warnings

The commits keep the behavior tests separate from the implementation.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Moves hosted Subrouter onboarding to Stack Auth so the dashboard and API use the user’s Stack session with a strict cutover gate and resumable cleanup. Adds a public CLI config endpoint and brokers exact team → hosted tenant exchange; account deletion now retires hosted and legacy tenants with bounded, checkpointed progress.

  • New Features

    • Adds GET /api/cli/config to publish non‑secret CLI config; defaults to https://sr.cmux.com (SUBROUTER_HOSTED_URL override) and returns 503 with a provider‑neutral error when unconfigured.
    • Introduces createHostedSubrouterClient and POST /api/subrouter/exchange to broker an exact team → hosted tenant exchange using the caller’s Stack access token.
    • Gates cutover via subrouter_tenants.hosted_ready_at; blocks legacy‑mapped teams until ready and shows a migration‑pending state in the dashboard.
    • Requires tenant retirement on account deletion using SUBROUTER_STACK_TENANT_DELETE_TOKEN; retires hosted and legacy tenants with serialized, fail‑closed retries and visible checkpoints; skips cleanup when the hosted service isn’t configured.
    • Updates /dashboard/subrouter and /api/subrouter/* to use the user’s Stack token, keep team checks, and redact hosted account health to status only; preserves /api/subrouter/teams, /api/subrouter/leases, and /api/subrouter/logout; removes the legacy Vault CLI setup link. Requires Go service manaflow-ai/subrouter#120.
  • Migration

    • Env: add SUBROUTER_STACK_TENANT_DELETE_TOKEN (required outside preview) and optional SUBROUTER_HOSTED_URL; keep legacy SUBROUTER_ADMIN_TOKEN/SUBROUTER_BASE_URL only for migration and retirement of pre‑hosted tenants.
    • DB: add hosted_finalization_started_at and hosted_ready_at to subrouter_tenants; add hosted_subrouter_deleted_team_ids and legacy_subrouter_retired_tenant_ids to account_deletion_tombstones.
    • Operator: run bun subrouter:migrate-legacy to exchange legacy tenants, mark cutover readiness, and optionally finalize sources; the migration source is pinned to the explicit target (staging or production) to avoid cross‑env mistakes.

Written for commit 3f04cc4. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Added hosted Subrouter integration for team authorization and account management.
    • Added a CLI configuration endpoint with authentication and hosted-service settings.
  • Removed Features
    • Removed the Vault CLI authentication and approval flow.
    • Removed credential lease, team, logout, and related legacy API endpoints.
  • Database
    • Removed legacy tenant and CLI authentication records while retaining a recovery archive.
  • Documentation
    • Updated hosted Subrouter setup documentation.
  • Tests
    • Added coverage for hosted account management and CLI configuration.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Jul 31, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The change replaces local Subrouter tenant management with hosted-service access through Stack tokens. It removes Vault CLI authentication flows, tenant persistence, related routes and UI, and adds hosted account-route coverage and a CLI configuration endpoint.

Changes

Hosted Subrouter migration

Layer / File(s) Summary
Hosted client and authentication context
web/services/subrouter/*, web/app/env.ts
Adds hosted-service requests, Stack token exchange, account normalization, timeout handling, error mapping, and hosted-service configuration.
Hosted account route integration
web/app/[locale]/dashboard/subrouter/page.tsx, web/app/api/subrouter/accounts/*, web/app/api/cli/config/route.ts
Routes and dashboard loading exchange authenticated team context for hosted tenants. The CLI config route returns Stack and hosted Subrouter settings.
Legacy tenant and Vault CLI removal
web/app/api/account/route.ts, web/db/*, web/app/[locale]/dashboard/*, web/services/vault/*, web/messages/*
Removes local tenant cleanup, tenant tables, Vault CLI navigation and translations, and CLI-specific route helpers.
Hosted flow validation
web/tests/hosted-subrouter-*.test.ts, web/tests/cli-config-route.test.ts, web/tests/dashboard-subrouter-page.test.tsx, web/tests/account-route.test.ts, web/tests/vault-route-helpers.test.ts
Adds hosted client and route coverage and removes tests for deleted tenant and Vault CLI behavior.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Request as Account request
  participant Context as resolveSubrouterRequestContext
  participant Stack as Stack authentication
  participant Client as HostedSubrouterClient
  participant Hosted as Hosted Subrouter service
  Request->>Context: Resolve access token
  Context->>Stack: Read token or cookie authentication
  Stack-->>Context: Return access token
  Context->>Client: Create hosted client
  Client->>Hosted: exchangeTeam(accessToken, team)
  Hosted-->>Client: Return tenant
  Client->>Hosted: List, create, delete, or repair account
  Hosted-->>Client: Return account response
  Client-->>Request: Return normalized account data
Loading

Possibly related PRs


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux User-Facing Error Privacy ❌ Error hostedClient.ts copies upstream health.message into account data, and account API routes return that data directly; raw upstream failure text can reach users. Do not forward health.message; map failed health to a safe product message or omit the field, and keep upstream details in server logs.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (23 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed The full diff from origin/main contains only web TypeScript, JSON, Markdown, SQL, and TSX files; it has no Swift files or actor-isolation changes.
Cmux Swift Blocking Runtime ✅ Passed The PR diff contains no Swift files; all 45 changed files are web TypeScript/TSX, JSON, Markdown, or SQL, so the Swift blocking-runtime check is not applicable.
Cmux Browser Automation Off-Main ✅ Passed The PR range contains 45 web-only path changes and zero Swift, TerminalController, ControlCommandExecutionPolicy, or policy-test changes; it does not alter browser socket routing or worsen existing...
Cmux Expensive Synchronous Load ✅ Passed The PR diff contains no Swift files; all changes are TypeScript/TSX, JSON, SQL, or Markdown, so the production Swift synchronous-load check is not applicable.
Cmux Cache Substitution Correctness ✅ Passed The diff adds no cache substitution in persistence, history, undo, or snapshot paths. Subrouter operations use live Stack tokens and hosted requests; only CLI config has a five-minute public cache.
Cmux No Hacky Sleeps ✅ Passed The diff adds no sleep, timer, delayed dispatch, polling loop, or fixed backoff. Its only timing primitive is a bounded AbortSignal.timeout(10_000) for hosted HTTP cancellation.
Cmux Algorithmic Complexity ✅ Passed The diff adds only a linear map over the hosted account response; changed production paths add no nested scans, per-target rescans, sorting, or in-memory joins.
Cmux Swift Concurrency ✅ Passed The PR diff contains only TypeScript, TSX, SQL, JSON, and Markdown files; it introduces no cmux-owned Swift changes or legacy Swift concurrency patterns.
Cmux Swift @Concurrent ✅ Passed The full PR diff against origin/main contains no .swift paths or Swift concurrency changes; all changes are web TypeScript, JSON, SQL, and Markdown.
Cmux Swift Package Boundaries ✅ Passed The merge-base diff contains only web TypeScript/TSX, JSON, SQL, Markdown, and tests; it has no Swift or Package.swift paths, so this check is not applicable.
Cmux Swiftpm Lockfiles ✅ Passed The PR diff has zero Package.swift, Package.resolved, .gitignore, workflow, or Xcode project/workspace changes, so the SwiftPM lockfile policy is not triggered.
Cmux Swift Logging ✅ Passed The PR changes only web TypeScript, JSON, Markdown, SQL, and tests; it contains no Swift files or Swift logging changes.
Cmux Full Internationalization ✅ Passed The PR removes the CLI-auth UI and its only existing en/ja message entries; remaining dashboard UI and metadata use next-intl, while new API values are protocol/config tokens.
Cmux Swiftui State Layout ✅ Passed The PR diff contains 0 Swift files and no SwiftUI tokens; all 45 changed files are web, configuration, SQL, or documentation files.
Cmux Architecture Rethink ✅ Passed The PR diff against origin/main changes 45 web/TypeScript, SQL, JSON, and Markdown files, with no Swift paths; the Swift architecture rule is therefore not applicable.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed The PR changes only web TypeScript, SQL, JSON, Markdown, and tests; it introduces no Swift window or controller changes, so this check is not applicable.
Cmux Source Artifacts ✅ Passed The PR changes only source, tests, a migration, README/localization, and intentional deletions; all additions are regular text blobs, with no suspicious artifact paths or binary additions.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The PR diff contains 45 changed paths, all under web/; it contains no changed Swift files under any production Sources/ path.
Cmux No Ambient Global State ✅ Passed The full PR diff contains only TypeScript, TSX, SQL, JSON, and Markdown changes; it contains no Swift changes, so this Swift-only check is not applicable.
Title check ✅ Passed The title clearly summarizes the main change: moving hosted Subrouter onboarding to Stack Auth.
Description check ✅ Passed The description explains the migration and lists verification commands, covering the core summary and testing content.
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch feat-subrouter-user-onboarding
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-subrouter-user-onboarding

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
web/services/subrouter/routeHelpers.ts (1)

175-183: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Do not forward upstream 401 and 403 to the caller.

resolveSubrouterRequestContext already verified the caller's Stack session and team permission before the upstream call. If the hosted service rejects the exchanged token, Line 179 returns that 401 or 403 to the browser. The client then treats a hosted-service failure as its own session failure and can enter a sign-out loop. Map upstream 401 and 403 to 502 and keep pass-through for genuine client-input statuses.

Also add the failing operation to the log line. The previous handler logged it, and status alone does not identify which upstream call failed.

🐛 Proposed fix
-    const status = err.status >= 400 && err.status < 500
+    const status = err.status >= 400 && err.status < 500 &&
+        err.status !== 401 && err.status !== 403
       ? err.status
       : 502;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/services/subrouter/routeHelpers.ts` around lines 175 - 183, Update the
HostedSubrouterError handling in resolveSubrouterRequestContext to map upstream
401 and 403 responses to 502 while preserving pass-through for other genuine 4xx
client-input statuses. Extend the console.error log to include the failing
upstream operation alongside the status, using the operation context already
available to this handler.
web/app/api/subrouter/accounts/[accountId]/repair/route.ts (1)

36-45: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Repair is now a non-atomic create-then-delete with no rollback.

Lines 38-41 create the replacement account first and then delete the requested account. If deleteAccount throws, Line 44 returns an error to the caller while the new account remains upstream. The tenant is left with both the stale account and the replacement, and the caller has no signal that a partial write occurred. A client retry creates a further duplicate, because the request carries no idempotency key.

Choose one of the following:

  • Ask the hosted service for a single atomic replace endpoint and call it here, keeping one mutation path.
  • Delete the stale account before creating the replacement, and roll back the delete failure explicitly.
  • Report the partial state distinctly, so the caller can reconcile instead of retrying blindly.

Note that web/tests/hosted-subrouter-routes.test.ts Lines 210-237 asserts the POST, POST, DELETE order and therefore locks in the current non-atomic sequence. Add a case where the delete fails, and assert the reconciliation behavior you choose.

As per coding guidelines: "For optimistic UI or CLI updates, use one mutation path, track pending state with a request ID or previous snapshot, reconcile with the authoritative result, and explicitly roll back on failure."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/app/api/subrouter/accounts/`[accountId]/repair/route.ts around lines 36 -
45, Replace the non-atomic create-then-delete flow in the repair route with a
single atomic hosted-service replacement operation, if available, and keep the
response based on that operation’s authoritative result. Update the existing
hosted-subrouter tests to cover replacement failure and verify no partial
mutation or blind-retry behavior; remove the test’s dependency on the current
POST, POST, DELETE sequence.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/app/api/cli/config/route.ts`:
- Around line 10-22: Update the GET function to validate
env.NEXT_PUBLIC_STACK_PROJECT_ID and
env.NEXT_PUBLIC_STACK_PUBLISHABLE_CLIENT_KEY before constructing the success
payload; when either is absent, return an HTTP 503 response with an actionable
configuration error instead of version 1 data. Preserve the existing 200
response and auth payload when both values are configured.
- Around line 6-8: Update the route constants so STACK_CONFIRM_URL derives from
the current deployment origin or an appropriate environment value instead of
hardcoding cmux.com. Replace HOSTED_SUBROUTER_URL with the exported
DEFAULT_HOSTED_SUBROUTER_URL from hostedClient.ts, updating that symbol’s export
and the route import so advertised and called URLs share one default.

In `@web/app/api/subrouter/accounts/route.ts`:
- Around line 20-22: The tenant is resolved repeatedly by account handlers
instead of being shared per request. Extend SubrouterRequestContext and
resolveSubrouterRequestContext in web/services/subrouter/requestContext.ts to
include the resolved tenant, then remove exchangeTeam calls and use the context
tenant in GET and POST in web/app/api/subrouter/accounts/route.ts, the account
handler in web/app/api/subrouter/accounts/[accountId]/route.ts, and the repair
handler in web/app/api/subrouter/accounts/[accountId]/repair/route.ts; preserve
existing account operations while ensuring each request performs the exchange
only once.

In `@web/db/migrations/20260730210000_drop_vault_cli_auth_requests/migration.sql`:
- Around line 1-2: Preserve the tenant-key source before removing
subrouter_tenants: update the migration to archive/export its tenant_id and
encrypted_tenant_key data, or remove/comment out the subrouter_tenants drop
while documenting the hosted service’s authoritative and reversible recovery
path. Keep the vault_cli_auth_requests removal intact, and if this migration is
intended for web.dbMigrations, add the required registration and explanatory
comment.

In `@web/tests/hosted-subrouter-routes.test.ts`:
- Around line 43-50: Add a test in the hosted subrouter route suite that
overrides the mocked getAuthJson behavior to return no access token, then invoke
the cookie-authenticated request and assert a 401 response with calls remaining
empty. Keep the existing beforeEach setup and authenticated test behavior
unchanged.
- Around line 3-6: Capture the original values of the four SUBROUTER_*
environment variables before mutating them, then update the existing afterAll
cleanup to restore each prior value, removing the variable when it was
originally undefined. Keep the current globalThis.fetch restoration unchanged.

---

Outside diff comments:
In `@web/app/api/subrouter/accounts/`[accountId]/repair/route.ts:
- Around line 36-45: Replace the non-atomic create-then-delete flow in the
repair route with a single atomic hosted-service replacement operation, if
available, and keep the response based on that operation’s authoritative result.
Update the existing hosted-subrouter tests to cover replacement failure and
verify no partial mutation or blind-retry behavior; remove the test’s dependency
on the current POST, POST, DELETE sequence.

In `@web/services/subrouter/routeHelpers.ts`:
- Around line 175-183: Update the HostedSubrouterError handling in
resolveSubrouterRequestContext to map upstream 401 and 403 responses to 502
while preserving pass-through for other genuine 4xx client-input statuses.
Extend the console.error log to include the failing upstream operation alongside
the status, using the operation context already available to this handler.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 9ea67e2b-318a-4ee0-9e13-d758c5cf25c7

📥 Commits

Reviewing files that changed from the base of the PR and between b5294c4 and fc68170.

📒 Files selected for processing (44)
  • web/app/[locale]/dashboard/dashboard-shell.tsx
  • web/app/[locale]/dashboard/layout.tsx
  • web/app/[locale]/dashboard/subrouter/page.tsx
  • web/app/[locale]/dashboard/vault/cli-auth/approve-form.tsx
  • web/app/[locale]/dashboard/vault/cli-auth/loading.tsx
  • web/app/[locale]/dashboard/vault/cli-auth/page.tsx
  • web/app/api/account/route.ts
  • web/app/api/cli/config/route.ts
  • web/app/api/subrouter/accounts/[accountId]/repair/route.ts
  • web/app/api/subrouter/accounts/[accountId]/route.ts
  • web/app/api/subrouter/accounts/route.ts
  • web/app/api/subrouter/leases/[leaseId]/events/route.ts
  • web/app/api/subrouter/leases/route.ts
  • web/app/api/subrouter/logout/route.ts
  • web/app/api/subrouter/teams/route.ts
  • web/app/api/vault/cli/auth/approve/route.ts
  • web/app/api/vault/cli/auth/poll/route.ts
  • web/app/api/vault/cli/auth/start/route.ts
  • web/app/env.ts
  • web/db/migrations/20260730210000_drop_vault_cli_auth_requests/migration.sql
  • web/db/schema.ts
  • web/messages/en.json
  • web/messages/ja.json
  • web/services/subrouter/README.md
  • web/services/subrouter/accountInput.ts
  • web/services/subrouter/client.ts
  • web/services/subrouter/crypto.ts
  • web/services/subrouter/hostedClient.ts
  • web/services/subrouter/requestContext.ts
  • web/services/subrouter/routeHelpers.ts
  • web/services/subrouter/tenants.ts
  • web/services/subrouter/types.ts
  • web/services/vault/cliAuth.ts
  • web/services/vault/routeHelpers.ts
  • web/tests/account-route.test.ts
  • web/tests/cli-config-route.test.ts
  • web/tests/dashboard-subrouter-page.test.tsx
  • web/tests/hosted-subrouter-client.test.ts
  • web/tests/hosted-subrouter-routes.test.ts
  • web/tests/subrouter-accounts-route.test.ts
  • web/tests/subrouter-crypto.test.ts
  • web/tests/subrouter-tenants.test.ts
  • web/tests/vault-cli-auth.test.ts
  • web/tests/vault-route-helpers.test.ts
💤 Files with no reviewable changes (26)
  • web/tests/vault-route-helpers.test.ts
  • web/app/api/vault/cli/auth/start/route.ts
  • web/app/[locale]/dashboard/vault/cli-auth/loading.tsx
  • web/tests/subrouter-crypto.test.ts
  • web/tests/subrouter-tenants.test.ts
  • web/services/vault/cliAuth.ts
  • web/app/[locale]/dashboard/vault/cli-auth/approve-form.tsx
  • web/services/subrouter/crypto.ts
  • web/tests/subrouter-accounts-route.test.ts
  • web/db/schema.ts
  • web/app/[locale]/dashboard/vault/cli-auth/page.tsx
  • web/tests/vault-cli-auth.test.ts
  • web/messages/ja.json
  • web/messages/en.json
  • web/services/subrouter/tenants.ts
  • web/app/api/vault/cli/auth/approve/route.ts
  • web/app/api/subrouter/logout/route.ts
  • web/app/api/vault/cli/auth/poll/route.ts
  • web/app/api/subrouter/leases/route.ts
  • web/app/api/subrouter/leases/[leaseId]/events/route.ts
  • web/app/[locale]/dashboard/dashboard-shell.tsx
  • web/services/vault/routeHelpers.ts
  • web/services/subrouter/client.ts
  • web/app/api/account/route.ts
  • web/tests/account-route.test.ts
  • web/app/api/subrouter/teams/route.ts

Comment thread web/app/api/cli/config/route.ts Outdated
Comment thread web/app/api/cli/config/route.ts Outdated
Comment thread web/app/api/subrouter/accounts/route.ts
Comment thread web/db/migrations/20260730210000_drop_vault_cli_auth_requests/migration.sql Outdated
Comment thread web/tests/hosted-subrouter-routes.test.ts
Comment thread web/tests/hosted-subrouter-routes.test.ts
@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Vercel preview: https://cmux-ach3z85fl-manaflow.vercel.app

The preview is READY. Vercel SSO protection applies to browser access. The same worktree API is also running locally on port 3928 for CLI onboarding dogfood.

@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Updated Vercel preview: https://cmux-qn18ci3eq-manaflow.vercel.app\n\nDeployment is READY for commit 1d0af02.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/app/api/cli/config/route.ts`:
- Line 18: Replace the provider-specific error value in the CLI config route
with the stable provider-neutral code "cli_auth_unavailable". Update the CLI
consumer to recognize this code and adjust web/tests/cli-config-route.test.ts to
assert the new response and consumer behavior, ensuring no provider names or
implementation details remain in the public API body.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f63d5169-6723-451c-baf9-84a189b9a045

📥 Commits

Reviewing files that changed from the base of the PR and between fc68170 and 1d0af02.

📒 Files selected for processing (8)
  • web/app/api/cli/config/route.ts
  • web/db/migrations/20260730210000_drop_vault_cli_auth_requests/migration.sql
  • web/services/subrouter/README.md
  • web/services/subrouter/constants.ts
  • web/services/subrouter/hostedClient.ts
  • web/tests/cli-config-route.test.ts
  • web/tests/hosted-subrouter-client.test.ts
  • web/tests/hosted-subrouter-routes.test.ts

Comment thread web/app/api/cli/config/route.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
web/tests/cli-config-route.test.ts (1)

5-19: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

Make the success test independent of ambient environment variables.

If either Stack variable is absent, GET() correctly returns 503, so this test fails before checking the success payload. If SUBROUTER_HOSTED_URL is set, the expected default URL is also incorrect. The route trims values, but the test compares the untrimmed environment values.

Set explicit test values for all three variables, then restore the originals in finally.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/tests/cli-config-route.test.ts` around lines 5 - 19, Update the success
test around GET() to set explicit values for NEXT_PUBLIC_STACK_PROJECT_ID,
NEXT_PUBLIC_STACK_PUBLISHABLE_CLIENT_KEY, and SUBROUTER_HOSTED_URL before
invoking the route. Assert the payload using those configured values, then
restore each original environment value in a finally block, preserving undefined
values when they were initially absent.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@web/tests/cli-config-route.test.ts`:
- Around line 5-19: Update the success test around GET() to set explicit values
for NEXT_PUBLIC_STACK_PROJECT_ID, NEXT_PUBLIC_STACK_PUBLISHABLE_CLIENT_KEY, and
SUBROUTER_HOSTED_URL before invoking the route. Assert the payload using those
configured values, then restore each original environment value in a finally
block, preserving undefined values when they were initially absent.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 54b25ba1-021e-4ac2-89aa-3d1d649bee62

📥 Commits

Reviewing files that changed from the base of the PR and between 1d0af02 and a6f73a8.

📒 Files selected for processing (2)
  • web/app/api/cli/config/route.ts
  • web/tests/cli-config-route.test.ts

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Current Vercel preview: https://cmux-44folm436-manaflow.vercel.app\n\nDeployment is READY for commit a6f73a8.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/tests/cli-config-route.test.ts`:
- Line 17: Update the test around the GET request to control
SUBROUTER_HOSTED_URL and the required Stack credential environment variables
with known values, then assert the corresponding URL response. Restore every
original environment value in a finally block so the test does not depend on or
leak ambient CI state.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b367e257-ceb6-435e-87ec-299e7f8322d6

📥 Commits

Reviewing files that changed from the base of the PR and between a6f73a8 and 6e107e5.

📒 Files selected for processing (3)
  • web/services/subrouter/README.md
  • web/services/subrouter/constants.ts
  • web/tests/cli-config-route.test.ts

Comment thread web/tests/cli-config-route.test.ts Outdated
@cursor

cursor Bot commented Aug 1, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Exact-head Vercel preview for 50a6bb78313b1c04e813fc7cfbb8f942d525b930: https://cmux-dpu5l4oxc-manaflow.vercel.app

Deployment is READY and returns HTTP 200 through authenticated Vercel CLI access. The same head completed a tagged srgcp cloud build. End-user Stack OAuth and the resulting public hosted Subrouter tenant exchange succeeded with an isolated local Codex login.

@cursor

cursor Bot commented Aug 3, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@vercel

vercel Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview Aug 3, 2026 4:51am

@cursor

cursor Bot commented Aug 4, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@lawrencecchen
lawrencecchen merged commit 622d2f7 into main Aug 4, 2026
6 checks passed
lawrencecchen added a commit that referenced this pull request Sep 17, 2026
The hosted Subrouter account and Stack authentication flows landed in #9261. CodeRouter now stores credentials with KMS encryption (#9686) and enforces private/team account permissions and VM pools (#12771).

Keep those shipped implementations instead of adding an unused SR_VAULT_KEY credential store and incomplete device-code flow. The resulting tree is identical to main at a149b7e. Current-path focused tests: 63 passed; web complexity gate passed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant