fix: bump Feishu registry version for PR #1698 - #1765
Merged
henrypark133 merged 1 commit intoMar 30, 2026
Merged
henrypark133 merged 1 commit into
henrypark133 merged 1 commit into
Conversation
henrypark133
merged commit Mar 30, 2026
ef9283c
into
staging-promote/7234700c-23635804857
12 of 13 checks passed
This was referenced Mar 30, 2026
drchirag1991
pushed a commit
to drchirag1991/ironclaw
that referenced
this pull request
Apr 8, 2026
errol-t3
added a commit
to Terminal-3/t3-claw
that referenced
this pull request
Jun 22, 2026
…1765) Pins the sidecar MCP tool surface to trinity main 6be8d032c (the nearai#1765 squash — org-owned z-payroll). Supersedes 4d38b134 (payroll-v2 era): the payroll tools now dispatch z:<org-tid>:payroll.* and resolve the tenant from T3N_Z_PAYROLL_ORG_TID, and tee:payroll is gone. Pairs with this PR's milestone-matcher + org-tid env changes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
errol-t3
added a commit
to Terminal-3/t3-claw
that referenced
this pull request
Jun 30, 2026
…-TS-044/046) (#29) * feat(payroll-audit): extend milestone matcher to z-payroll tool names During the T3-TS-044 side-by-side window the MCP surface carries both the original tee:payroll tool names and their z-space equivalents (zRunPayrollComputation, zExecuteDisbursement, zFinalizeAudit, zSubmitEscalationResolutions). Extend is_payroll_milestone and the format_milestone match arms to recognise all eight names so the t3claw::payroll_audit log stream fires for z-payroll runs too. Old names are retained — they drop only at tee:payroll retirement. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * style: cargo fmt on payroll-audit milestone matcher rustfmt layout pass on the z-payroll tool-name additions to satisfy the Formatting / Code Style CI gate. No behaviour change. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore(payroll-audit): revert milestone matcher to canonical tool names Remove the Z_* constants, their match arms in is_payroll_milestone and format_milestone, and the z-name test assertions. The backed contract tools now use plain product names (runPayrollComputation et al.), so the z-prefix expansion is no longer needed. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(compose): default the gateway host port to 3100 Restore the convention of running the t3claw gateway on :3100 by default so it no longer collides with a local Trinity node cluster (N1 binds :3000). Override with T3CLAW_HOST_PORT in .env as before. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compose): pass T3N_Z_PAYROLL_ORG_TID through to the mcp sidecar The payroll-z MCP tools resolve which tenant's payroll to operate on from T3N_Z_PAYROLL_ORG_TID (or a per-call tenant_org_did). Without it the sidecar returns "Cannot resolve payroll org tid", so the tools 5xx before reaching the contract. Surfaced while verifying the five-tool z-payroll cycle over the sidecar's MCP socket against a local cluster. Set the value per deployment in .env. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(sidecar): bump trinity-sdk-ref to the merged T3-TS-044 (nearai#1765) Pins the sidecar MCP tool surface to trinity main 6be8d032c (the nearai#1765 squash — org-owned z-payroll). Supersedes 4d38b134 (payroll-v2 era): the payroll tools now dispatch z:<org-tid>:payroll.* and resolve the tenant from T3N_Z_PAYROLL_ORG_TID, and tee:payroll is gone. Pairs with this PR's milestone-matcher + org-tid env changes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(sidecar): regenerate trinity tool-surface snapshot for the bumped ref Surface manifest for the z-payroll MCP tools at trinity 6be8d032c — payroll/* + listScopeEntries metadata/schema hashes changed (z-retargeted descriptions). Mechanical regen via gen-trinity-tool-surface-snapshot.sh; unblocks the tool-surface-snapshot CI gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(z-payroll): retire the delegation-envelope injection — envelope-free agent dispatch (T3-TS-046) Trinity's z-payroll surface dropped the per-call delegation envelope: payroll MCP tools now carry agent-supplied org_did + pii_did, and authority is the standing on-chain agent_auth ∩ UserGrant the Trinity host re-reads and enforces — fail-closed — on every call. There is no delegation credential to inject, store, validate, or prompt for. Remove the injection machinery entirely — nothing of the previous design remains: - client.rs: call_tool forwards arguments unchanged; deleted inject_t3n_delegation_credential, tool_requires_delegation, strip_delegation_fields_if_present, the __inject__ placeholder, and their tests. - protocol.rs: dropped the requires_delegation tool annotation. - config.rs: dropped the T3N_DELEGATION_TOKEN_SECRET secret name. - extensions/manager.rs: dropped the t3n-mcp delegation-credential setup-form field and its configure allow-list entry (the MCP server's own auth token is unchanged). - channels/web/handlers/secrets.rs: dropped validate_delegation_token, the per-secret validation hook, and its tests. Net +18 / -1443. cargo check + clippy clean; 64 mcp::client + 106 secrets-area unit tests pass. Verified end-to-end against a local cluster on the envelope-free Trinity: the chat agent drives a full z-payroll cycle (createT3nAuthSession -> addUserDid -> listMyContext -> runPayrollComputation -> executeDisbursement -> finalizeAudit) to an on-chain merkle root with delegated audit evidence, with no "delegation token" prompt anywhere. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(sidecar): bump trinity-sdk-ref to envelope-free nearai#1816 + regen tool-surface snapshot Trinity nearai#1816 (T3-TS-046, claw-agnostic / envelope-free authorisation) merged to trinity main as 1b9c9dff. Bump the pinned ref so deployed sidecars bundle the envelope-free MCP tool surface, and regenerate .github/trinity-tool-surface.snapshot to match (the trinity-tool-surface workflow fails the PR otherwise). Surface delta vs the prior T3-TS-044 pin: +delegation/checkDelegation and +delegation/getDelegationInstructions tools; reshaped metadata/schema for listMyContext, listScopeEntries, and all payroll tools (direct-wire org_did/pii_did, no credential envelope). 56 → 62 surface entries. Verified: gen-trinity-tool-surface-snapshot.sh against trinity@1b9c9dff tool sources matches the committed snapshot (CI tool-surface check passes). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification