CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260714T115137702Z-c0d7580f-447 #63

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260714T115137702Z-c0d7580f-447.
Run started at: 2026-07-14T11:51:37.702Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260714T115137702Z-c0d7580f-447. Run started at: 2026-07-14T11:51:37.702Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes Medium 1 1

Findings

1. Interactive auth shell still sends persona_id

Severity Category Confidence Location Status
Medium Correctness 94% frontend/src/dev-shell/components/DevShellTerminal.vue:154-155 Open

The backend now reads instance_id from /api/dev-shell/ws, but DevShellTerminal still serializes the selected AI tool instance as persona_id. In AI tool setup this prop is populated from savedInstanceId, so launching an interactive login for a non-primary instance will omit instance_id; app/dev_shell.py then defaults the auth session to primary, writing credentials to the wrong storage scope.

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Change the terminal query parameter to instance_id and update the prop naming/tests to match the new plugin instance terminology.

![CodeSnuffler review banner](https://auth.codesnuffler.com/codesnuffler_review/assets/banner_mediumIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | Medium | 1 | 1 | ### Findings #### 1. Interactive auth shell still sends persona_id | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 94% | `frontend/src/dev-shell/components/DevShellTerminal.vue:154-155` | Open | The backend now reads `instance_id` from `/api/dev-shell/ws`, but `DevShellTerminal` still serializes the selected AI tool instance as `persona_id`. In AI tool setup this prop is populated from `savedInstanceId`, so launching an interactive login for a non-primary instance will omit `instance_id`; `app/dev_shell.py` then defaults the auth session to `primary`, writing credentials to the wrong storage scope. [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-63/findings/2) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-63/findings/2/fix) **Suggested fix:** Change the terminal query parameter to `instance_id` and update the prop naming/tests to match the new plugin instance terminology.
jason-admin closed this pull request 2026-07-14 11:56:10 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!63
No description provided.