chore: promote staging to staging-promote/315c4cf8-24151502580 (2026-04-08 19:29 UTC) - #2163
Conversation
* feat(workspace): admin system prompt shared with all users (#2088) Introduce SYSTEM.md in a well-known __admin__ scope so admins can set a system prompt that all tenants receive. Gated behind multi-tenant mode (WorkspacePool sets admin_prompt_enabled on each workspace; owner workspace in app.rs also gets the flag when has_any_users() is true). New endpoints: - GET /api/admin/system-prompt — read admin system prompt - PUT /api/admin/system-prompt — set admin system prompt (64 KB limit) Safety: - SYSTEM.md added to injection scan list - is_reserved_scope() guard on user creation (defense-in-depth) - Multi-tenancy gate on both API and prompt assembly layers Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * chore: remove review audit file from tracked files Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add 64 KB size limit to admin system prompt PUT handler Addresses PR review feedback: - Enforce 64 KB limit on system prompt content to prevent token budget exhaustion (the content is injected into every user's system prompt) - Add regression tests for the size limit (413 for oversized, not-413 for at-limit) - Document that is_multi_tenant is evaluated once at startup and the owner workspace requires a restart after the first user is created Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address remaining review feedback on admin system prompt - Restore rustdoc comments stripped from document.rs (DocumentMetadata, HygieneMetadata, DocumentVersion, VersionSummary, PatchResult, etc.) to keep the diff focused on feature additions only - Replace silent error swallowing (if let Ok) with discriminated match in admin prompt read — only DocumentNotFound is silent, other errors logged at debug! level - Cache admin system prompt on WorkspacePool to avoid an extra DB read on every turn; invalidated on PUT via invalidate_admin_prompt() - Add cache invalidation integration test Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(workspace): tighten reserved-scope check and admin-prompt body limit - is_reserved_scope: case-insensitive, whitespace-tolerant, and reserves the entire `__*__` namespace so future system scopes (alongside `__admin__`) cannot be impersonated by hand-crafted user IDs - admin system-prompt route: layer-level DefaultBodyLimit of 128 KB rejects oversized payloads before JSON parse, complementing the in-handler 64 KB content cap - system_prompt put_handler: clarify that the in-handler size check is a clearer-error fallback for the layer cap - users_create_handler: drop the dead is_reserved_scope check on a freshly-minted UUID; the guard belongs at a code path that actually accepts user-supplied IDs - expand is_reserved_scope tests for case, whitespace, and the wider `__*__` namespace Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Illia Polosukhin <ilblackdragon@gmail.com>
* Fix skill installs for invalid catalog names * Fix clippy test module ordering * fix: address PR review feedback * fix: use PairingStore::new_noop() in SSRF test after merge with staging The staging branch introduced a new test (test_http_request_rejects_private_ip_targets) that calls PairingStore::new(), but this branch changed the signature to require db and cache arguments. Use new_noop() since this is a test context. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address PR #2040 review — remove expect() and dead strip_prefix - Restructure download_key flow in skills_install_handler to use the value directly instead of round-tripping through Option + expect(), satisfying the no-expect-in-production-code rule. - Remove dead strip_prefix("---\n") in render_skill_md — serde_yml does not emit a leading document marker for structs. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(skills): preserve unknown frontmatter and tighten install matching - rewrite install-recovery to mutate the `name` field via raw YAML Value rather than re-serializing the typed SkillManifest, so unknown frontmatter keys (vendor extensions, future fields) survive the install rewrite - catalog_entry_is_installed: case-insensitive comparison for the display-name and normalized-slug branches, matching the slug branch - normalize_skill_identifier: document non-ASCII handling - normalizing-invalid-name log: warn -> debug (REPL/TUI rule) - add round-trip test asserting unknown top-level keys, nested mappings, and sequences survive install recovery Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Illia Polosukhin <ilblackdragon@gmail.com>
Code reviewFound 13 issues:
Summary: No critical or security issues found. The code is well-structured with proper auth gating and error handling. All findings are performance optimizations and type-safety improvements. Main concerns: cache consistency patterns (items 4-6) and catalog resolution hotspots (items 1-3). |
The test used a hyphenated channel name ("test-failing-channel") but
canonicalize_extension_name() converts hyphens to underscores. This
caused configure() to look for "test_failing_channel.capabilities.json"
which didn't exist, returning an early Err before reaching the
activation code path the test was designed to exercise.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…1770 chore: promote staging to staging-promote/bb2c3e1d-24154330911 (2026-04-08 21:41 UTC)
9e89f77
into
staging-promote/315c4cf8-24151502580
…4154330911 chore: promote staging to staging-promote/a1b88640-24151502580 (2026-04-08 19:29 UTC)
Auto-promotion from staging CI
Batch range:
a55aff980a4e235590c3af57ded2542512e2f9f6..bb2c3e1dd17c9fe40c0f5490fc0c28e1680c02cbPromotion branch:
staging-promote/bb2c3e1d-24154330911Base:
staging-promote/315c4cf8-24151502580Triggered by: Staging CI batch at 2026-04-08 19:29 UTC
Commits in this batch (62):
Current commits in this promotion (0)
Current base:
staging-promote/315c4cf8-24151502580Current head:
staging-promote/bb2c3e1d-24154330911Current range:
origin/staging-promote/315c4cf8-24151502580..origin/staging-promote/bb2c3e1d-24154330911Auto-updated by staging promotion metadata workflow
Waiting for gates:
Auto-created by staging-ci workflow