chore(guards): add durable markers so fixes aren't silently dropped

Introduce AGENTS.md (root, primary agent instruction file) documenting six
hard-won fixes with explicit DO NOT / WHY, plus executable enforcement so a
future AI cannot delete or reintroduce them:

1. package-lock.json must be generated with npm 10 (Docker's npm 10.9.8).
   npm 11 drops the top-level @emnapi/core + @emnapi/runtime entries npm 10
   needs, breaking the tag-triggered Docker build at `npm ci` (happened on
   v1.0.14). Add scripts/verify-lockfile-npm10.mjs + .npmrc + a Dockerfile
   fail-fast check + a CI step + tests/unit/lockfile-npm10-guard.test.js.
   Also re-fix the lockfile itself (regenerated with npm 10.9.8).
2. Tests must never write to the real ~/.9router DB (isolateDataDir).
3. Hidden providers must not leak into Usage (usageProviders !p.hidden).
4. codebuddy-intl connection test + OAuth identity.
5. Fork-only features that must survive upstream syncs.
6. Upstream sync procedure.

Each marker cross-references AGENTS.md and the covering test. CLAUDE.md now
points to AGENTS.md at the top. Verified: build ok, guard script passes,
full suite leaves the real DB count unchanged (38), 0 new regressions.
This commit is contained in:
MUH. IQRAM BAHRING
2026-09-19 12:52:19 +08:00
parent 9c37af90a9
commit 25df5e6a9d
13 changed files with 365 additions and 28 deletions
+7 -4
View File
@@ -93,10 +93,13 @@ const OAUTH_TEST_CONFIG = {
authPrefix: "Bearer ",
},
"codebuddy-cn": { tokenExists: true },
// CodeBuddy Intl access tokens are Keycloak JWTs (iss .../auth/realms/copilot);
// probe the realm's userinfo endpoint so a revoked/expired token is caught.
// Derive the realm URL from the token's `iss` claim, falling back to the
// known copilot realm. 200 = valid, 401 = invalid/revoked.
// GUARD — DO NOT REMOVE. See AGENTS.md §4. Without this entry, Test Connection
// returns "Provider test not supported". codebuddy-intl access tokens are
// Keycloak JWTs (iss .../auth/realms/copilot); probe the realm's userinfo
// endpoint so a revoked/expired token is caught. Derive the realm URL from the
// token's `iss` claim, falling back to the known copilot realm.
// 200 = valid, 401 = invalid/revoked.
// Covered by tests/unit/codebuddy-intl-connection.test.js.
"codebuddy-intl": {
buildUrl: (token) => {
const iss = decodeJwtPayload(token)?.iss;
+4 -3
View File
@@ -68,9 +68,10 @@ const codebuddyIntl = {
accessToken: tokens.access_token,
refreshToken: tokens.refresh_token,
expiresIn: tokens.expires_in || 86400,
// The CodeBuddy access token is a Keycloak JWT carrying email/name claims;
// surface them so a fresh OAuth login is named by identity (and deduped on
// re-login) instead of falling back to "Account N".
// GUARD — DO NOT REMOVE. See AGENTS.md §4. The CodeBuddy access token is a
// Keycloak JWT carrying email/name claims; surface them so a fresh OAuth
// login is named by identity (and deduped on re-login) instead of falling
// back to "Account N". Covered by tests/unit/codebuddy-intl-connection.test.js.
email: extractEmailFromAccessToken(tokens.access_token) || null,
displayName: extractDisplayNameFromAccessToken(tokens.access_token) || null,
providerSpecificData: {},
+3
View File
@@ -1,5 +1,7 @@
// Provider list for the Usage page.
//
// GUARD — DO NOT DELETE the `!p.hidden` filter below. See AGENTS.md §3.
//
// Two sources, deduped by provider id:
// 1. Active LLM connections (one entry per provider).
// 2. noAuth free providers that need no connection (e.g. opencode).
@@ -7,6 +9,7 @@
// Hidden providers are excluded — the Providers page filters `hidden`, so a
// hidden noAuth provider (devin-cli, mimo-free) must not leak into Usage with
// zero connections and zero traffic.
// Covered by tests/unit/usage-provider-list.test.js.
export function buildUsageProviderList({
connections = [],
freeProviders = {},