Skip to content

Let agents organize credentials and groups in one approved batch - #166

Merged
sudoHG merged 3 commits into
mainfrom
sudoHG/162-organize-credentials
Oct 8, 2026
Merged

sudoHG merged 3 commits into
mainfrom
sudoHG/162-organize-credentials

Conversation

@sudoHG

@sudoHG sudoHG commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Closes #162

Summary

  • Add organize_credentials: validate and freeze 1–64 ordered moves and group creations, renames and deletions under one explicit approval and one system authentication.
  • Bind affected records and named groups; atomically revalidate and commit the whole batch with its idempotency receipt, preserving unrelated App group edits.
  • Keep Hidden-only and recycled-only groups unavailable to agents; rename/delete includes every member and shows nonvisible counts only in the App, omitting the clause at zero and correctly pluralizing English member counts.
  • Add catalog credentials/groups, an ordered scrollable approval card in English and Simplified Chinese, ADR 0010's batch shape, synthetic security tests and a CI-only real MCP screenshot scenario.

Diff stat

git diff --stat origin/main: 48 files changed, 1600 insertions, 26 deletions against 01431c98868603e24cd6e1dc696028ed27e15184 (merged #161 / PR #163). Changes cover Broker types and binding, Vault freeze/transaction, helper parsing/schema/guidance, approval presentation and twelve new localization entries, scoped tests, the screenshot export entry and feature/ADR documentation. The latest revision changes only FrozenOrganizationApprovalContent.swift, the catalog and its App tests (3 files, 62 insertions, 2 deletions).

Tests

Final candidate: ebbaf107b705ba9e467a9e2ec3077415bfb42c56. Initial implementation verification below ran at 5f2113c9612f76795fee6b81d3226c4d2f162385; final App verification and CI are recorded separately.

swift build --scratch-path .build-162 --jobs 4
swift test --scratch-path .build-162 --jobs 4 --filter 'AgentOrganization|OrganizationApprovalContent|OrganizationApprovalTests|HelperMCPOrganizationTests|AgentCredentialMetadataWriteTests|AgentTextWrite|AgentAccessTests|ApprovalStateMachine|BrokerProtocolMethodTests|BrokerCatalog|ReviewCatalogLimitTests|HelperMCP|FrozenWriteSummaryContentTests|ApprovalMetadataContentTests|ApprovalPromptContentTests|PendingRequestPresentationTests|LocalizationUnificationTests|AuditBrokerBoundaryTests|ReadDeclarationAndAuditTests'
python3 scripts/check_hygiene.py
python3 scripts/check_module_deps.py
git diff --cached --check

All commands exited 0. Local affected selection: 164 passed, 0 failed, 0 skipped (85 Vault, 48 Broker and 31 App tests). Compared individual XCTest identities and outcomes with the green main baseline at 01431c98868603e24cd6e1dc696028ed27e15184: all 134 existing local outcomes are unchanged and all 30 new tests passed. Baseline full suite: 1054 executed, 1051 passed, 0 failed, 3 skipped.

New tests cover mixed ordered batches; atomic rollback and retry after a receipt-write failure; invalid operations/names/destinations and the 64-operation limit; Hidden/recycled membership and counts; no credential deletion or policy/material changes; same-timestamp stale records, newly Hidden members and named-group changes; unrelated group edits; moved-only expiry including catalog/read/write expiry interactions; capability binding, denial, cancellation, expiry, revocation, exact retransmission and idempotent replay; one ticket and one write authentication with Allow/timed read allowances unable to skip approval; wire response privacy and additive version-1 catalog decoding. App tests run English and Simplified Chinese, including 64 operations, expanded details and cancelled authentication within 680 points without invoking reveal.

Final App verification:

swift build --scratch-path .build-162-count --jobs 4
swift test --scratch-path .build-162-count --jobs 4 --filter 'OrganizationApprovalContentTests|ScreenPresentationTests|ApprovalPromptContentTests|ApprovalMetadataContentTests|FrozenWriteSummaryContentTests|LocalizationUnificationTests|LocalizationRemediationTests|ReviewLocalizationTests'
python3 scripts/check_hygiene.py
python3 scripts/check_module_deps.py
git diff --cached --check

All commands exited 0: 50 App tests passed, 0 failed, 0 skipped. The same 46 main identities retain their passing outcomes, and all four organization tests added by this PR pass. The new test checks six member/nonvisible combinations (0/0, 1/0, 2/0, 1/1, 2/1, 2/2) for both rename and delete in both English and Simplified Chinese: 24 literal row-output checks. Zero nonvisible members produce only 0 credentials, 1 credential or 2 credentials (Chinese: %lld 个凭证); positive nonvisible counts append the approved clause. Separate singular/plural catalog keys preserve the existing lookup path. All twelve PR-added zh-Hans entries use the reviewed terminology, every baseline catalog entry remains unchanged, and no Broker, Vault, digest or layout code changed in this revision.

No local full suite, desktop E2E, app launch or screenshot capture was run. Final-head CI build-and-test passed. Raw job logs contain 1085 Swift tests: 1082 passed, 0 failed, 3 skipped, and all 182 automation tests passed. Compared every XCTest identity and outcome with main CI 37772481982: all 1054 baseline outcomes are unchanged, all 31 added tests passed, and there are no missing tests or new skips. CI checkout fbb61bcf20e1cdfb2bdf0edaecdbd6f02cf1e045 merges final candidate ebbaf107b705ba9e467a9e2ec3077415bfb42c56 with main 01431c98868603e24cd6e1dc696028ed27e15184; both parent SHAs were verified through the GitHub commit API.

The same three tests are skipped in main and the candidate:

  • CodexCLIContractTests.testInstalledCodexMCPAddGetJSONContractUsesIsolatedConfiguration: installed CLI executable/version contract is not configured.
  • LegacyFileWriteTransactionTests.testAbruptFileCommitProcess: only the isolated file-commit crash subprocess invokes this entry.
  • NativeBootstrapFixtureGenerationTests.testGenerateSyntheticNativeBootstrapFixtures: explicit synthetic fixture generation only.

Final-head CI basic-ui-flows passed: 15 required desktop tests passed, 0 failed, 0 skipped. Verified every required identity against the passing receipt. The optional screenshot step also succeeded: 5 screenshot tests passed, 0 failed, 0 skipped, including ScreenshotE2ETests/testOrganizationApprovalScreen() verified individually in the exported XCTest results. All 16 expected window images were exported. Inspected the final-head 16-approval-organization.png: the four ordered operations and the rename/delete counts (3 credentials, 2 not visible to agents) are readable, both actions remain visible, and there is no reveal or timed-allowance action. The final-head CI evidence artifact expires October 15, 2026. Both required CI jobs are green on candidate ebbaf107b705ba9e467a9e2ec3077415bfb42c56.

Checks

Hygiene: zero violations. Module dependencies and whitespace checks passed. Source files remain below 600 lines. Broker protocol stays version 1; product identifiers, permission behavior, runtime delivery, the App group editor and real data/credentials are untouched. Tests use temporary synthetic stores; the screenshot scenario verifies the marked E2E bundle's isolated directory before seeding synthetic fixtures.

The unquoted pending-list key disables its own generated symbol (generatesSymbol: false) because Xcode otherwise gives it the same symbol as the quoted approval key; runtime lookup remains unchanged.

Latest local verification began with 122 GiB free; only one local build/test ran at a time. Removed the owned build directory (1,049,979,992 bytes), final-head CI download (8,224,098 bytes) and consumed logs after reading the results and inspecting the screenshot. Ownership checks passed, both build symlinks resolved inside the owned directory, the CI download contained no symlinks and lsof found no open files before removal. The worktree is clean and no task build/test process or build directory remains; final data-volume free space is 120 GiB. Branch and worktree remain for review.

Deviations and questions

The coordinator approved Step 1's batch shape, per-member existing modify access records (one credential-less event for a group-only batch), moved-only expiry, named-group snapshot binding and the 300-point card. #162 records both approvals. The scoped CI screenshot additions to ScreenshotE2ETests.swift, E2EBrokerScenario.swift and scripts/e2e-report.py are approved. The coordinator also approved replacing only three expiry-triggered cancelPending calls in catalog/runtime validation and single-credential write validation with cancelPendingForExpiry; existing reads and single writes retain their expiry rejection, and ordinary credential mutations still invalidate any batch member. No other deviations.

@luoji-bot

luoji-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown

Review: one change requested before merge (Simplified Chinese copy only).

The new zh-Hans strings use 凭据 and 代理. Everywhere else the App uses 凭证 (176 strings) and Agent (58 strings), and neither 凭据 nor 代理 appears anywhere. The sentence patterns also differ from the existing prompts. Please align them:

  1. "“%@” wants to organize credentials" → “%@”想整理凭证 (same pattern as “%@”想创建“%@”, no space before 想).
  2. The Pending requests list entry should follow its siblings (%1$@ 想新建凭证 %2$@): use an unquoted %@ wants to organize credentials key and %@ 想整理凭证.
  3. "%lld credentials, %lld not visible to agents" → %lld 个凭证,其中 %lld 个 Agent 看不到.
  4. "Rename group “%@” → “%@”" → 重命名分组“%@” → “%@”.
  5. "Proposed organization" → 待执行的整理. Check the rest of the new zh-Hans entries for the same terms; Approve Organization → 批准整理 and the move/create/delete rows are fine.
  6. Update any test that asserts these strings. Code and English copy are fine; the CI screenshot was inspected.

@luoji-bot

luoji-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown

One more copy change requested by the maintainer before merge:

  1. When no affected member is hidden from agents, rename and delete rows show only the count: %lld credentials / %lld 个凭证. The "not visible" clause (…, %lld not visible to agents / …,其中 %lld 个 Agent 看不到) appears only when that count is above zero.
  2. English must pluralize correctly: "1 credential", "2 credentials". Use the String Catalog's plural variations, or separate keys, for the English entries.
  3. Tests: zero and non-zero not-visible counts, and one versus several members, in English and Simplified Chinese.

@sudoHG
sudoHG merged commit 4cbd12b into main Oct 8, 2026
2 checks passed
@sudoHG
sudoHG deleted the sudoHG/162-organize-credentials branch October 8, 2026 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Let agents organize credentials and groups in one approved batch

1 participant