Skip to content

feat(product-workflow): add WebUI service facade - #3691

Merged
serrrfirat merged 5 commits into
reborn-integrationfrom
feat/webui-service-facade-3611
May 16, 2026
Merged

serrrfirat merged 5 commits into
reborn-integrationfrom
feat/webui-service-facade-3611

Conversation

@italic-jinxin

@italic-jinxin italic-jinxin commented May 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Consolidates the WebUI-facing facade in ironclaw_product_workflow
onto RebornServicesApi (the canonical facade reborn-integration
introduced in parallel) and ports forward the security checks the
earlier WebUiService carried that the canonical version was missing:
thread-ownership gating on cancel_run / resolve_gate, gate-parking
verification on denied/cancelled resolutions, explicit rejection of
persistent (always: true) approvals, and a ThreadScopeMismatch →
NotFound remap that prevents existence leaks. Five regression tests
cover those paths. The earlier-added WebUiService, FakeWebUiService,
and tests/webui_service_contract.rs are removed so the crate exposes
exactly one facade for browser handlers — satisfying #3611 acceptance
criterion #3.

Dependency

The follow-up handler PR that closes #3611 is blocked on
#3683 (host-owned
ingress contracts, closes #3578). Handlers need #3683's
RouteDescriptor / IngressPolicy vocabulary to declare auth / CORS /
body / rate / streaming policies, and #3683 also introduces the
architecture guardrail that forbids product crates from binding
listeners directly. This PR has no such dependency and is reviewable
on its own.

Introduces `WebUiService` (with `DefaultWebUiService` + `FakeWebUiService`)
as the typed surface that Slice 2 WebChat v2 route handlers will depend
on. Per #3611 acceptance criterion 3, handlers must consume only this
facade and never reach the dispatcher / HostRuntime / run-state / DB /
runtime-lane adapters directly.
@italic-jinxin italic-jinxin self-assigned this May 15, 2026
@github-actions github-actions Bot added scope: docs Documentation scope: dependencies Dependency updates size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules contributor: experienced 6-19 merged PRs labels May 15, 2026
@italic-jinxin
italic-jinxin requested a review from serrrfirat May 15, 2026 15:34

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces the WebUiService facade and its default implementation, DefaultWebUiService, to handle native WebChat v2 operations. It integrates with the thread service, turn coordinator, and event projection service to provide a unified interface for thread creation, message submission, run cancellation, gate resolution, and timeline retrieval. Additionally, a FakeWebUiService and comprehensive contract tests have been added. Feedback highlights an idempotency issue in thread creation where the client_action_id should be used to derive thread IDs deterministically. There is also a suggestion to log internal SessionThreadError details before redacting them to improve observability.

Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a native WebUI-facing service facade in ironclaw_product_workflow for WebChat v2 route handlers, composing thread, turn, and projection services behind a typed API.

Changes:

  • Introduces WebUiService, DefaultWebUiService, command/result DTOs, timeline cursor/read support, and redacted service errors.
  • Adds FakeWebUiService behind test-support for downstream handler tests.
  • Adds contract tests covering thread creation, message submission, run cancellation, gate resolution, and timeline reads.

Reviewed changes

Copilot reviewed 6 out of 7 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
Cargo.lock Records new workflow crate dependencies.
crates/ironclaw_product_workflow/Cargo.toml Adds event projection/event crates required for timeline reads.
crates/ironclaw_product_workflow/CLAUDE.md Documents the new WebUI facade and dependencies.
crates/ironclaw_product_workflow/src/fakes.rs Adds FakeWebUiService and call recording/programmed outcomes.
crates/ironclaw_product_workflow/src/lib.rs Exports the new WebUI service types and fake.
crates/ironclaw_product_workflow/src/webui_service.rs Implements the WebUI facade, default service, errors, helpers, and timeline projection routing.
crates/ironclaw_product_workflow/tests/webui_service_contract.rs Adds contract tests for service behavior and fake sanity checks.
Comments suppressed due to low confidence (2)

crates/ironclaw_product_workflow/src/webui_service.rs:627

  • The denied/cancelled gate path also reaches the coordinator without checking thread ownership. Since coordinator authorization is limited to TurnScope and ignores actor, this can let a user cancel another user's gated run in the same tenant/agent/project when they know the thread/run identifiers; perform the same owner-scoped thread validation before this call.
                let response = self
                    .turn_coordinator
                    .cancel_run(CancelRunRequest {

crates/ironclaw_product_workflow/src/webui_service.rs:600

  • Approved gate resolution reaches the coordinator without checking that the authenticated user owns the thread. TurnScope does not include owner_user_id, and the coordinator only compares scope/run/gate, so a caller who knows another user's thread_id/run_id/gate_ref in the same tenant/agent/project could resume that run. Validate owner-scoped thread access before this call.
                let response = self
                    .turn_coordinator
                    .resume_turn(ResumeTurnRequest {

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
Comment thread crates/ironclaw_product_workflow/src/webui_service.rs Outdated
@italic-jinxin italic-jinxin linked an issue May 16, 2026 that may be closed by this pull request
@italic-jinxin
italic-jinxin force-pushed the feat/webui-service-facade-3611 branch from 3cd4c98 to c13f990 Compare May 16, 2026 15:08
The reborn-integration merge brought in `RebornServicesApi`, an
independently-built parallel facade with overlapping responsibility to the
`WebUiService` we landed earlier. Two facades for the same browser-handler
surface defeats the single-entry goal: handlers would have to choose between
them and the boundary tests cannot keep both honest. Consolidate onto
`RebornServicesApi` (the canonical surface the integration team has been
tracking in AGENTS.md and the docs/reborn briefs) and port across the
security fixes that the old `WebUiService` carried but the upstream version
was missing.
@github-actions github-actions Bot added size: M 50-199 changed lines and removed size: XL 500+ changed lines labels May 16, 2026

@serrrfirat serrrfirat left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blocking findings from my review.

Checked the final diff against the RebornServices/thread/turn contracts, including the new thread-ownership probe, denied/cancelled gate-ref validation, and deterministic create-thread id behavior. The added caller-level contract tests cover the mutation side effects rather than just helpers.

Verification run in an isolated worktree:

  • cargo test -p ironclaw_product_workflow --test reborn_services_contract
  • cargo test -p ironclaw_product_workflow
  • cargo clippy -p ironclaw_product_workflow --all-targets -- -D warnings

@serrrfirat
serrrfirat merged commit dc8b3b3 into reborn-integration May 16, 2026
15 checks passed
@serrrfirat
serrrfirat deleted the feat/webui-service-facade-3611 branch May 16, 2026 21:16
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
…3611

feat(product-workflow): add WebUI service facade
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: experienced 6-19 merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Reborn WebUI Beta] Implement minimal native WebChat v2 routes

3 participants