Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
85f705a
Add durable run identity for Gen 2 Superset agent sessions (Phase 1)
QA1S Sep 28, 2026
40e6554
Add per-launch provider credential profile module (Phase 2, unverified)
QA1S Sep 28, 2026
26cd839
Apply cargo fmt to provider_profile.rs
QA1S Sep 28, 2026
684de09
Backfill missing drizzle snapshots for migrations 0055/0056
QA1S Sep 28, 2026
65c4ecd
Add CoDev runtime adapter for Superset agent sessions (Phase 3, apps/…
QA1S Sep 28, 2026
92db9df
Add orchestrator/guestd routes for Superset agent sessions (Phase 3, …
QA1S Sep 28, 2026
aafde12
Apply cargo fmt to Phase 3 Superset agent-session routes
QA1S Sep 28, 2026
a031cbd
Fix invalid test URI in superset_agent_route_validation_and_lifecycle
QA1S Sep 28, 2026
841ab39
Add Superset host-service /codev/agents endpoints (Phase 3, completes…
QA1S Sep 28, 2026
4eac539
Wire Gen 2 agent turns to Superset behind the flag (Phase 4, unverified)
QA1S Sep 28, 2026
9b20b08
Stop reporting chat-room readiness from the Claude setup-token
QA1S Sep 29, 2026
d7e0931
Delete the retired Claude OAuth flow and unreachable connect routes
QA1S Sep 29, 2026
94975cc
Resolve every provider credential through one registry-driven path
QA1S Sep 29, 2026
475652b
Make a credential's seat a live run rather than a sixteen-minute stamp
QA1S Sep 29, 2026
93644a0
Collapse the two spellings of a shared credential into one scope
QA1S Sep 29, 2026
e59d440
Teach the guest a provider-neutral launch profile
QA1S Sep 29, 2026
45e2d1c
Format the launch-profile Rust to rustfmt's output
QA1S Sep 29, 2026
c4aef24
Reflow the model import list the way rustfmt fills it
QA1S Sep 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 0 additions & 7 deletions apps/web/app/api/auth/oauth/claude/callback/route.ts

This file was deleted.

5 changes: 0 additions & 5 deletions apps/web/app/api/auth/oauth/claude/complete/route.ts

This file was deleted.

7 changes: 0 additions & 7 deletions apps/web/app/api/auth/oauth/claude/route.ts

This file was deleted.

5 changes: 0 additions & 5 deletions apps/web/app/api/auth/oauth/claude/session/route.ts

This file was deleted.

7 changes: 0 additions & 7 deletions apps/web/app/api/auth/oauth/codex/callback/route.ts

This file was deleted.

7 changes: 0 additions & 7 deletions apps/web/app/api/auth/oauth/codex/route.ts

This file was deleted.

7 changes: 1 addition & 6 deletions apps/web/app/api/personal/connections/route.ts
Original file line number Diff line number Diff line change
Expand Up @@ -52,12 +52,7 @@ export async function PUT(request: Request) {
try {
const input = putSchema.parse(await request.json());
return Response.json(
await savePersonalProviderConnection(
user,
input.provider,
input.apiKey,
input.surface,
),
await savePersonalProviderConnection(user, input.provider, input.apiKey),
);
} catch (error) {
return apiError(error);
Expand Down
85 changes: 36 additions & 49 deletions apps/web/app/settings/org/agents/page.tsx
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
import { BedrockRoleForm } from "@/components/settings/bedrock-role-form";
import { ClaudeCliSubscriptionCard } from "@/components/settings/claude-cli-subscription-card";
import { CursorConnectCard } from "@/components/settings/cursor-connect-card";
import { HostedCodexSubscriptionCard } from "@/components/settings/hosted-codex-subscription-card";
Expand Down Expand Up @@ -27,58 +26,52 @@ export default async function OrganizationAgentsPage({
const user = await requireUser();
const context = await getActiveOrganizationSettingsContext(user.id);
const params = await searchParams;
const [openai, anthropic, bedrock, cursor, claudeCliToken, hostedCodex] =
context
? await Promise.all([
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"openai",
),
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"anthropic",
),
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"bedrock",
),
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"cursor",
),
// A shared Claude login is stored ORGANIZATION-scoped (its scope id
// is this workspace's id), not WORKSPACE — a separate scope used
// for the plain fallback keys above.
getClaudeCliTokenPublicStatus({
scopeType: "ORGANIZATION",
scopeId: context.workspace.id,
canManage: context.canWrite,
}),
getHostedCodexPublicStatus({
scopeType: "ORGANIZATION",
scopeId: context.workspace.id,
canManage: context.canWrite,
}),
])
: [null, null, null, null, null, null];
const [openai, anthropic, cursor, claudeCliToken, hostedCodex] = context
? await Promise.all([
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"openai",
),
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"anthropic",
),
getProviderCredentialStatus(
"WORKSPACE",
context.workspace.id,
"cursor",
),
// A shared Claude login is stored ORGANIZATION-scoped (its scope id
// is this workspace's id), not WORKSPACE — a separate scope used
// for the plain fallback keys above.
getClaudeCliTokenPublicStatus({
scopeType: "WORKSPACE",
scopeId: context.workspace.id,
canManage: context.canWrite,
}),
getHostedCodexPublicStatus({
scopeType: "WORKSPACE",
scopeId: context.workspace.id,
canManage: context.canWrite,
}),
])
: [null, null, null, null, null, null];

return (
<OrganizationSettingsPage
context={context}
description="Manage shared provider keys and the fallback credential pool for your workspace."
description="Logins this workspace's members can fall back to in a coding workspace."
title="Coding agents"
>
{context ? (
<>
<OrganizationSettingsCard
context={context}
description="Team credentials are used only when a member has not configured a personal key."
detail="Personal credentials always win. Shared credentials are encrypted before storage and used as the next hierarchy tier."
title="Fallback credential pool"
description="Used only when a member has not connected their own, and only in a coding workspace."
detail="A member's own login always wins. These never fund a chat-room reply or a Gen 2 turn: both run on the credential of the person who asked, so the work is billed to and authorised by them. Everything here is encrypted before storage."
title="Workspace credentials"
/>
<SettingsCard title="OpenAI">
<WorkspaceCredentialForm
Expand Down Expand Up @@ -124,12 +117,6 @@ export default async function OrganizationAgentsPage({
status={hostedCodex}
/>
) : null}
<SettingsCard title="Amazon Bedrock">
<BedrockRoleForm
currentRole={bedrock?.awsRoleArn}
workspaceId={context.workspace.id}
/>
</SettingsCard>
</>
) : null}
</OrganizationSettingsPage>
Expand Down
114 changes: 0 additions & 114 deletions apps/web/components/settings/bedrock-role-form.tsx

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ export function ClaudeCliSubscriptionCard({
const router = useRouter();
const [busy, setBusy] = useState(false);
const [message, setMessage] = useState<string | null>(null);
const isOrg = status.scopeType === "ORGANIZATION";
const isOrg = status.scopeType === "WORKSPACE";

async function disconnect() {
setBusy(true);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ export function HostedCodexSubscriptionCard({
const router = useRouter();
const [busy, setBusy] = useState(false);
const [message, setMessage] = useState<string | null>(null);
const isOrg = status.scopeType === "ORGANIZATION";
const isOrg = status.scopeType === "WORKSPACE";

async function disconnect() {
setBusy(true);
Expand Down
Loading
Loading