Skip to content

fix(webui): scope workspace and memory views - #5831

Closed
serrrfirat wants to merge 10 commits into
mainfrom
codex/webui-workspace-isolation
Closed

serrrfirat wants to merge 10 commits into
mainfrom
codex/webui-workspace-isolation

Conversation

@serrrfirat

@serrrfirat serrrfirat commented Jul 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Scope WebUI Workspace and Memory presentation to the authenticated tenant/user instead of exposing shared storage paths.
  • Fail closed for signed/non-operator sessions and for missing scoped roots, while preserving local operator fallback.
  • Preserve current source-thread workspace browsing and regression-artifact feature gates after merging latest main.
  • Collapse internal memory wrapper directories and hide sidecar files from the user-facing view.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

None.

Validation

  • cargo fmt --all -- --check
  • cargo clippy -p ironclaw_webui --all-features --all-targets -- -D warnings
  • cargo clippy -p ironclaw --all-features --all-targets -- -D warnings
  • Relevant tests pass: WebUI Rust suite, architecture boundary, CLI profile classifier, frontend typecheck and all frontend tests
  • cargo build — Not applicable: the owning crate tests and all-target clippy compiled the affected targets.
  • cargo test --features integration — Not applicable: no database-backed behavior changed.
  • Manual testing — Not run; deterministic caller/API and presentation tests cover the changed seams.
  • Agent review workflow — Not run; final diff and required local checks were audited directly.

Test Strategy

User behavior: A signed hosted user sees only their scoped Workspace/Memory projection; missing scoped roots render empty, while local operator sessions retain raw workspace fallback.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: frontend workspace API tests cover caller scoping, fail-closed roots, memory projection, and source-thread browsing; WebUI handler contracts cover effective session flags; CLI unit test covers every deployment profile.
  • Reborn integration: composed-router tests cover serve-config propagation, multi-user auth, and composite signed-session versus operator-token behavior.
  • Recorded fixture: Not applicable: no model selection or tool arguments changed.
  • Browser E2E: Not applicable: the change is in deterministic API projection and session bootstrap logic, covered by frontend API/presentation tests and composed HTTP router tests; no new browser interaction was introduced.
  • Backend or runtime: Not applicable: no storage backend, schema, Docker, WASM, or external runtime behavior changed.
  • Live canary: Not applicable: no provider or real-model behavior changed.

What the tests prove: Tenant/user storage prefixes are hidden from presented paths; hosted and non-operator sessions cannot fall back to shared roots; local operators keep existing fallback; source-thread workspace routes remain isolated and functional after conflict resolution.

Commands run:

  • pnpm typecheck
  • pnpm test (124 files, 1,056 tests)
  • cargo test -p ironclaw_webui --all-features
  • cargo test -p ironclaw workspace_projection_scope_follows_deployment_profile
  • cargo clippy -p ironclaw_webui --all-features --all-targets -- -D warnings
  • cargo clippy -p ironclaw --all-features --all-targets -- -D warnings
  • cargo test -p ironclaw_architecture reborn_crate_dependency_boundaries_hold
  • cargo fmt --all -- --check

Security Impact

Changes file-view access presentation. Hosted/non-operator sessions now fail closed when caller identity or scoped roots are unavailable. No authentication bypass, secret handling, tool execution, or network policy is weakened.

Reborn Trust-Boundary Checklist

  • Public policy/evidence/trust-bearing types: no new public trust-bearing type; the existing authenticated caller and per-token capability determine the effective browser flag.
  • Untrusted content enters prompts only through an envelope/escaping primitive: N/A, no prompt path changed.
  • Hashes declare purpose: N/A, no hashing changed.
  • Status/policy/runtime/error variants audited: N/A, no variants changed.
  • Security/durability serde(default) fields fail closed: the new session feature defaults fail closed in the browser; no durable serde field added.
  • Queues/maps/buffers/counters bounded: N/A, none added.
  • Driver/operator-visible errors have stable class semantics: N/A, error vocabulary unchanged.
  • Sandbox/native/host names accurately describe trust boundary: scoped projection is explicitly a browser presentation gate; host/tool filesystem execution is unchanged.

Database Impact

None.

Blast Radius

WebUI session bootstrap, workspace/memory API projection, frontend workspace navigation, and CLI profile-to-WebUI configuration. Source-thread file browsing and artifact-export gating were explicitly preserved during the merge.

Rollback Plan

Revert merge commit c3bd57214 and the original scoped-projection commits, restoring prior raw-mount presentation. No schema or persisted-data rollback is required.

Review Follow-Through

CI must confirm changed-line coverage after the added CLI profile-matrix test. No known follow-up is required in this PR; tool/host execution scoping remains outside this UI-only change.


Review track: C (security boundary and hosted multi-user file visibility)

@ironloopai

ironloopai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: b541dd664c95ee0bbe5778c6ca922d3679f1ee6d
Result: No reviewer jobs are scheduled yet.
Next: Run @ironloopai review to start reviewers.
Updated: 2026-07-10T11:49:58.804Z

Current reviewers:

Reviewer State Verdict Findings Last update
none Queued N/A No reviewer jobs scheduled yet. N/A
Reviewer summaries
Reviewer Detail
none No reviewer jobs scheduled yet.
Recent activity
Time Reviewer State Detail
N/A N/A Waiting No progress events recorded yet.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
  • @ironloopai status
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 14:08 Destroyed
@github-actions github-actions Bot added size: L 200-499 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 8, 2026
@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Threads a scoped-workspace flag from serve config into session and frontend context, rewires workspace filesystem resolution for scoped workspace and memory mounts, and scopes local-dev workspace mounts and write routing.

Changes

Scoped projection flag plumbing

Layer / File(s) Summary
Serve config and session feature
crates/ironclaw_reborn_composition/src/webui/webui_serve.rs, crates/ironclaw_webui_v2/src/handlers.rs, crates/ironclaw_reborn_composition/tests/webui_v2_serve.rs, crates/ironclaw_webui_v2/tests/webui_v2_handlers_contract.rs
Adds workspace_requires_scoped_projection to WebuiServeConfig, forwards it into WebUiV2State, exposes it in WebUiV2Features, and verifies the session response reflects the configured flag.
CLI profile mapping
crates/ironclaw_reborn_cli/src/commands/serve.rs
Derives the new serve config flag from RebornProfile and sets it during ServeCommand::execute.
Auth and layout context
crates/ironclaw_webui_v2/frontend/src/app/auth.ts, crates/ironclaw_webui_v2/frontend/src/app/app.tsx, crates/ironclaw_webui_v2/frontend/src/layout/gateway-layout.tsx, crates/ironclaw_webui_v2/frontend/src/pages/workspace/workspace-page.tsx, crates/ironclaw_webui_v2/frontend/src/pages/workspace/components/workspace-sidebar.tsx, crates/ironclaw_webui_v2/frontend/src/pages/workspace/components/workspace-tree.tsx, crates/ironclaw_webui_v2/frontend/src/pages/workspace/hooks/useWorkspaceBrowser.ts
useAuthSession returns the new feature flag, AuthenticatedLayout passes it into GatewayLayout, and GatewayLayout forwards it through Outlet context. WorkspacePage reads outlet context, passes scope state into the workspace browser, and forwards scoped props into the sidebar and tree.

Workspace filesystem scoping

Layer / File(s) Summary
Scoped path resolution
crates/ironclaw_webui_v2/frontend/src/pages/workspace/lib/workspace-api.ts
Adds workspace and memory mount scoping helpers, rewrites listing results to use resolved backend paths, and changes file preview requests to use scoped actualPath values and derived download URLs.
Workspace API contract tests
crates/ironclaw_webui_v2/frontend/src/pages/workspace/lib/workspace-api.test.ts
Adds mocked fetch/window/session harnesses and covers scoped listing, fallback handling, preview routing, and memory mount behavior across caller-scoped and unscoped cases.

Local-dev workspace mount scoping

Layer / File(s) Summary
Scoped workspace mount view
crates/ironclaw_reborn_composition/src/local_dev_mounts.rs
Adds a tenant/user-derived workspace mount view helper and a unit test for its target path and permissions.
Local-dev mount selection
crates/ironclaw_reborn_composition/src/runtime/local_dev.rs
Selects a scoped workspace mount for non-owner local-dev runs and keeps the fallback user on the shared mount view.
Scoped write regression test
crates/ironclaw_reborn_composition/src/runtime/local_dev/tests.rs
Adds a helper for invoking the write-file tool and a regression test that checks scoped write destination behavior for owner and non-owner runs.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant ServeCommand
  participant WebuiServeConfig
  participant WebUiV2State
  participant SessionHandler

  ServeCommand->>WebuiServeConfig: with_workspace_requires_scoped_projection(...)
  WebuiServeConfig->>WebUiV2State: with_workspace_requires_scoped_projection(...)
  SessionHandler->>WebUiV2State: workspace_requires_scoped_projection()
  SessionHandler-->>SessionHandler: features.workspace_requires_scoped_projection
Loading

Possibly related PRs

  • nearai/ironclaw#4672: Introduces the user-scoped workspace mount helper used by the local-dev scoping changes here.
  • nearai/ironclaw#5019: Shares the WebUiV2Features and GET /api/webchat/v2/session feature-response plumbing changed here.
  • nearai/ironclaw#5185: Shares the operator_webui_config capability path used here to gate workspace_requires_scoped_projection session state.

Suggested labels: size: L, risk: medium, contributor: core

Suggested reviewers: ilblackdragon

Poem

I hop through scoped paths, soft and neat,
With carrots of context at my feet. 🥕
The session flag now knows the way,
And hidden roots don’t steal the day.
In mounted burrows, all is clear—
A rabbit grin from ear to ear.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title follows Conventional Commits style and accurately summarizes the workspace and memory scoping changes.
Description check ✅ Passed The description covers the required summary, change type, validation, test strategy, security, database, blast radius, rollback, and review sections.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request transitions the WebUI workspace and browse filesystems from a static, project-scoped mount view to a dynamic, caller-scoped mount view, ensuring that workspace files, attachments, and persistent memory are isolated by the authenticated caller's scope (tenant, user, and project). Feedback highlights an inconsistency in the fallback strings ("_none" vs "none") used for missing optional fields between scoped_memory_target and scoped_agent_project_root. Additionally, it is recommended to preserve the original behavior of the default thread_scope() test helper to avoid unintended side effects on existing tests.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread crates/ironclaw_reborn_composition/src/local_dev_mounts.rs Outdated

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 2 0 2 fbf3649c5597

Head: fbf3649c5597e6a54c731422d33ba5fc73987dfc
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Found blocking regressions in the workspace scoping change: attachment bytes and the file browser now use a different workspace root than the runtime/tool paths that need to read or write the same files.

Findings

Blocking: 2 / Notes: 0

Blocking findings

1. ❌ [HIGH] Attachment landing no longer matches the runtime read port

Location: crates/ironclaw_reborn_composition/src/factory.rs:536
webui_workspace_filesystem() now lands /workspace/attachments/... through the scoped WebUI resolver, but build_reborn_runtime still wires attachment_read_port from local_runtime.workspace_filesystem, whose fixed view resolves /workspace to /projects/workspace. The landed files therefore sit under /projects/tenants/.../workspace while the model-side reader looks in /projects/workspace, so WebUI/OpenAI-compatible image attachments are persisted but model reads return NotFound and the image parts are skipped. Wire the runtime attachment reader to the same scoped workspace, or keep landing on the same mount the runtime reads.

2. ❌ [MEDIUM] Workspace browser is disconnected from agent tool output

Location: crates/ironclaw_reborn_composition/src/local_dev_mounts.rs:162
The standalone Workspace/Files browser now resolves /workspace to the scoped WebUI tree, but local-dev capability execution still uses local_runtime.workspace_mounts built from WORKSPACE_TARGET (/projects/workspace). Files created by the agent's coding/shell tools will remain in /projects/workspace, while the browser reads /projects/tenants/.../workspace, so agent-produced files disappear from the WebUI. The browser/project readers and the tool execution mounts need to share the same workspace target.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/stale/stalled state while reviewers run.

Comment thread crates/ironclaw_reborn_composition/src/factory.rs Outdated
Comment thread crates/ironclaw_reborn_composition/src/local_dev_mounts.rs Outdated
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 14:22 Destroyed
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review --agent reviewer

@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai status

@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_composition/src/local_dev_mounts.rs`:
- Around line 176-195: scoped_workspace_mount_view currently rewrites only
mounts whose target matches WORKSPACE_TARGET, so if ambient_workspace_mount_view
or its callers stop including that grant the function will quietly return an
unscoped MountView. Add a fail-loud guard in scoped_workspace_mount_view that
tracks whether any mount was rewritten and then either debug-assert or return a
HostApiError when no targets match; use the existing scoped_workspace_target,
WORKSPACE_TARGET, and MountView/MountGrant flow to keep the check close to the
rewrite logic.
- Around line 201-217: The scoped_memory_target helper is using a different
missing-segment sentinel than the rest of the memory path logic, so mounts
without agent/project end up under the wrong tree. Update scoped_memory_target
to match MemoryDocumentScope::virtual_prefix() and the memory path parser by
using the shared memory path builder (or the same _none sentinel) for missing
agent_id and project_id instead of hardcoding __none__.

In
`@crates/ironclaw_reborn_composition/src/support/fs/mount_filesystem_reader.rs`:
- Around line 373-409: Add a memory-isolation-by-project test alongside
scoped_browser_reads_memory_from_existing_memory_namespace to cover the
same-user/different-project case. Use the existing scoped_memory_writer,
scope_for, MountScopedFilesystemReader, and FsMount::Memory flow, but create two
scopes for the same caller with different project_id values and verify the
second scope cannot list the first scope’s seeded MEMORY.md. This should mirror
the workspace isolation coverage and confirm scoped_memory_target keeps memory
namespaced by project.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 7b39bcc7-44b6-426c-a3a4-bc606f60c2fc

📥 Commits

Reviewing files that changed from the base of the PR and between 053f550 and f5f4f43.

📒 Files selected for processing (7)
  • crates/ironclaw_reborn_composition/src/factory.rs
  • crates/ironclaw_reborn_composition/src/local_dev_mounts.rs
  • crates/ironclaw_reborn_composition/src/runtime.rs
  • crates/ironclaw_reborn_composition/src/runtime/local_dev.rs
  • crates/ironclaw_reborn_composition/src/support/fs/attachment_landing.rs
  • crates/ironclaw_reborn_composition/src/support/fs/mount_filesystem_reader.rs
  • crates/ironclaw_reborn_composition/src/support/fs/project_filesystem_reader.rs

Comment thread crates/ironclaw_reborn_composition/src/local_dev_mounts.rs Outdated
Comment thread crates/ironclaw_reborn_composition/src/local_dev_mounts.rs Outdated
Comment thread crates/ironclaw_reborn_composition/src/support/fs/mount_filesystem_reader.rs Outdated

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 2 0 2 f5f4f439e03d

Head: f5f4f439e03d8f30b3d4dc06045fae6e3eb61b85
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Found two blocking regressions in the new scoped filesystem wiring: approval lease terms still use the unscoped workspace mount view, and WebUI memory browsing uses a non-canonical sentinel for missing project/agent scope.

Findings

Blocking: 2 / Notes: 0

Blocking findings

1. ❌ [MEDIUM] Approval leases still use unscoped workspace mounts

Location: crates/ironclaw_reborn_composition/src/runtime.rs:801
The PR scopes local-dev workspace execution mounts per run in LocalDevLoopCapabilityPortFactory::create_capability_port, but this approval lease provider is still constructed with local_runtime.workspace_mounts.clone(), the composition-time unscoped /projects/workspace view. When a workspace capability opens an approval gate, the resulting lease grant carries unscoped mount constraints while the resumed invocation context uses the scoped mounts. scoped_mount_obligation requires the lease mounts to be a subset of the invocation mounts, so approved workspace operations can be rejected after approval; in any path that consumed the lease mounts directly this would also widen workspace scope. Build the lease terms from the approval gate/run scope or original request context, and add a caller-level approval test for a non-default user/project workspace operation.

2. ❌ [MEDIUM] Memory browser points missing project scope at the wrong namespace

Location: crates/ironclaw_reborn_composition/src/local_dev_mounts.rs:215
scoped_memory_target substitutes __none__ for absent agent_id or project_id, but the memory subsystem's canonical virtual paths use _none for missing axes. For the common/default case where project_id is absent, memory writes and profile-backed documents land under /memory/.../projects/_none/..., while the WebUI browse mount now points at /memory/.../projects/__none__/..., making those documents appear missing. Use the shared memory path helper or the same _none sentinel, and cover project_id: None in the WebUI memory mount tests.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/stale/stalled state while reviewers run.
Inline review fallback

Inline comment projection fell back to a body-only PR Review because GitHub rejected the inline payload.
Reason: Unprocessable Entity: "Line could not be resolved" - https://docs.github.com/rest/pulls/reviews#create-a-review-for-a-pull-request

IronLoop preserved the inline review comment payloads below instead of dropping them.

Inline fallback 1: crates/ironclaw_reborn_composition/src/runtime.rs:801

This provider is still using the unscoped composition-time workspace mounts, while the PR now scopes execution mounts per run in create_capability_port. Approval leases for workspace operations will carry unscoped mount constraints that are not a subset of the scoped invocation mounts at resume time, so approved operations can be rejected by the scoped-mount obligation check. Please derive these lease terms from the approval gate/run scope or original request context and add a non-default user/project approval test.

Inline fallback 2: crates/ironclaw_reborn_composition/src/local_dev_mounts.rs:215

The memory path convention uses _none for absent project/agent axes, but this new browse target uses __none__. For callers without a project, memory documents created under /memory/.../projects/_none/... will be browsed under /memory/.../projects/__none__/... and appear missing. Please reuse the memory path helper or match the _none sentinel, with a test for project_id: None.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 14:37 Destroyed
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 14:43 Destroyed
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review

@github-actions github-actions Bot added size: XL 500+ changed lines and removed size: L 200-499 changed lines labels Jul 8, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 14:49 Destroyed
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
crates/ironclaw_reborn_composition/src/local_dev_mounts.rs (1)

210-216: 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Fail closed when workspace scope lacks project_id.

scoped_workspace_target falls back to fixed WORKSPACE_TARGET for project_id: None, so an incomplete WebUI ResourceScope can still land on shared /projects/workspace. Return an error or use a caller-scoped fallback; don’t silently reintroduce the ambient workspace. As per path instructions, “Fail closed on local-only or missing required handles in production and migration-dry-run profiles.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/ironclaw_reborn_composition/src/local_dev_mounts.rs` around lines 210
- 216, The scoped_workspace_target path currently falls back to the shared
WORKSPACE_TARGET when ResourceScope.project_id is missing, which can reintroduce
the ambient workspace. Update scoped_workspace_target and its callers to fail
closed for missing project_id, either by returning an error or by using a
caller-scoped fallback that cannot resolve to the shared /projects/workspace
target. Make sure the change is applied where scoped_workspace_target and
scoped_agent_project_root are used so incomplete ResourceScope values cannot
silently proceed.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@crates/ironclaw_reborn_composition/src/local_dev_mounts.rs`:
- Around line 210-216: The scoped_workspace_target path currently falls back to
the shared WORKSPACE_TARGET when ResourceScope.project_id is missing, which can
reintroduce the ambient workspace. Update scoped_workspace_target and its
callers to fail closed for missing project_id, either by returning an error or
by using a caller-scoped fallback that cannot resolve to the shared
/projects/workspace target. Make sure the change is applied where
scoped_workspace_target and scoped_agent_project_root are used so incomplete
ResourceScope values cannot silently proceed.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 0b239646-fffd-43a5-883e-3888122ce056

📥 Commits

Reviewing files that changed from the base of the PR and between 88ad501 and 33a0830.

📒 Files selected for processing (2)
  • crates/ironclaw_reborn_composition/src/local_dev_mounts.rs
  • crates/ironclaw_reborn_composition/src/support/fs/mount_filesystem_reader.rs

@railway-app

railway-app Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5831 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ❌ Build Failed (View Logs) Web Aug 3, 2026 at 11:21 am

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_composition/src/runtime/approval.rs`:
- Around line 136-142: Add an inline `// silent-ok: ...` comment on the fallback
branch in `ApprovalLease::workspace_mounts` where `scoped_workspace_mount_view`
returns `Err(error)` and `self.workspace_mounts.mounts.is_empty()` is accepted;
keep the existing `tracing::debug!` call and make the comment explicitly name
the workspace-mount read/fallback so the intentional unscoped `workspace_mounts`
return is obvious.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 817d5e84-e6e9-475e-9ed9-ac5a78f3407f

📥 Commits

Reviewing files that changed from the base of the PR and between 33a0830 and 0375b61.

📒 Files selected for processing (1)
  • crates/ironclaw_reborn_composition/src/runtime/approval.rs

Comment thread crates/ironclaw_reborn_composition/src/runtime/approval.rs Outdated

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 1 0 1 0375b614b042

Head: 0375b614b0428e213b98df9d6e4b8d552f63f6cd
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Found a blocking workspace isolation gap in the new scoped mount resolver.

Findings

Blocking: 1 / Notes: 0

Blocking findings

1. ❌ [HIGH] Projectless WebUI scopes still share one workspace

Location: crates/ironclaw_reborn_composition/src/local_dev_mounts.rs:211-212
The new scoped workspace resolver falls back to the legacy /projects/workspace target whenever project_id is None. That case is still supported: WebuiServeConfig::default_project_id is optional, and create-thread keeps the caller scope unchanged when no project is requested. As a result, projectless WebUI callers still land attachments, browse/download workspace files, and receive workspace tool grants against one shared backing directory, so users without a default/requested project can see each other's files. Scope the None case by tenant/user/agent with a reserved project segment, or fail closed for projectless workspace access, and add an isolation test for project_id: None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/stale/stalled state while reviewers run.

Comment thread crates/ironclaw_reborn_composition/src/local_dev_mounts.rs Outdated
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 15:01 Destroyed
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 8, 2026 15:05 Destroyed
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

@ironloopai review

@github-actions github-actions Bot added the size: XL 500+ changed lines label Jul 9, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_composition/src/runtime/local_dev.rs`:
- Around line 220-234: The shell capability still bypasses the new workspace
scoping, so non-owner shell paths can resolve against the shared root instead of
the per-run workspace. Update the shell grant path in the local dev runtime
setup so `SHELL_CAPABILITY_ID` uses the same scoped workspace target as
`workspace_mounts` (via the `local_dev_resource_scope_for_run` /
`scoped_workspace_mount_view` flow), or otherwise make the exemption explicit
and justified; use the existing `RefreshingLocalDevCapabilityPortConfig` and
`factory.rs` shell alias wiring to locate the integration point.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: de2f91e5-4f74-4a8c-a2f4-4df25e29bce8

📥 Commits

Reviewing files that changed from the base of the PR and between 7ebb513 and 50401b0.

📒 Files selected for processing (3)
  • crates/ironclaw_reborn_composition/src/local_dev_mounts.rs
  • crates/ironclaw_reborn_composition/src/runtime/local_dev.rs
  • crates/ironclaw_reborn_composition/src/runtime/local_dev/tests.rs

Comment thread crates/ironclaw_reborn_composition/src/runtime/local_dev.rs Outdated
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 13:01 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 15:31 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 16:44 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 998fec0 to 3e53257 Compare July 9, 2026 16:49
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 16:50 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 3e53257 to 04d9751 Compare July 9, 2026 16:59
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 16:59 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 04d9751 to 26ee6b7 Compare July 9, 2026 17:15
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 17:15 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 26ee6b7 to 23f3f2c Compare July 9, 2026 17:39
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 9, 2026 17:39 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 10, 2026 09:03 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from e88428a to 6ae669b Compare July 10, 2026 09:24
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 10, 2026 09:24 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 6ae669b to 254a70d Compare July 10, 2026 09:48
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 10, 2026 09:48 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 254a70d to 54f34b0 Compare July 10, 2026 10:33
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5831 July 10, 2026 10:33 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/webui-workspace-isolation branch from 54f34b0 to 7ebb513 Compare July 10, 2026 11:28
@github-actions github-actions Bot added size: L 200-499 changed lines and removed size: XL 500+ changed lines labels Jul 10, 2026
serrrfirat and others added 4 commits July 10, 2026 14:49
…-isolation

# Conflicts:
#	crates/ironclaw_webui/frontend/src/app/app.tsx
#	crates/ironclaw_webui/frontend/src/app/auth.ts
#	crates/ironclaw_webui/frontend/src/layout/gateway-layout.tsx
#	crates/ironclaw_webui/frontend/src/pages/workspace/components/workspace-tree.tsx
#	crates/ironclaw_webui/frontend/src/pages/workspace/hooks/useWorkspaceBrowser.ts
#	crates/ironclaw_webui/frontend/src/pages/workspace/lib/workspace-api.test.ts
#	crates/ironclaw_webui/frontend/src/pages/workspace/lib/workspace-api.ts
#	crates/ironclaw_webui/frontend/src/pages/workspace/workspace-page.tsx
#	crates/ironclaw_webui/src/webui_serve.rs
#	crates/ironclaw_webui/src/webui_v2/handlers.rs
#	crates/ironclaw_webui/src/webui_v2/router.rs
#	crates/ironclaw_webui/tests/webui_v2_handlers_contract.rs
@serrrfirat

Copy link
Copy Markdown
Collaborator Author

Closing to reopen on top of current main. The branch had accumulated 5 merge commits keeping it in sync with main's ironclaw_webui_v2 → ironclaw_webui crate rename. Reopening fresh avoids carrying stale merge commits and replays the net 13-file change as a single squashed commit on top of the latest main.

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5831 — c3bd5721 Deployed Aug 3, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Same home directory shared across all users; workspaces visible to others

1 participant