Commit Graph

12110 Commits

Author SHA1 Message Date
Mark 508a7ab267 Merge branch 'main' into mark/oss-191-fix-mcp-apps-zod-4-record-schema-incompatibility 2026-05-26 15:25:20 -07:00
Jordan Ritter db9ef2e412 fix(showcase-harness): repair 3 pre-existing probe failures (qa, pin-drift, aimock-wiring) (#5028)
## Summary

Post-Slice 3 cleanup. Restores qa + pin-drift + aimock-wiring probes
that broke from path/wiring changes.

- **qa probe**: `manifest.yaml` lookup corrected from
`showcase/packages/` to `showcase/integrations/` (Slice 3 moved files;
probe code and test fixture still referenced the old path)
- **pin-drift probe**: `fail-baseline.json` ENOENT in container — the
5-level `import.meta.url` walk-up from `dist/probes/drivers/` overshoots
`/app` and lands at `/`. Added `PIN_DRIFT_REPO_ROOT=/app` env var and
COPY of the baseline file into the runtime stage
- **aimock-wiring probe**: `showcase-ms-agent-harness-dotnet`
(`deployed: false`) was not in the `EXCLUDE_SERVICES` set, causing it to
be flagged as unwired. Added to the exclude list in both
`aimock-wiring.ts` and `smoke.yml`

## Files touched

- `showcase/harness/src/probes/drivers/qa.ts` — path fix
- `showcase/harness/src/probes/drivers/qa.test.ts` — matching test
fixture fix
- `showcase/harness/Dockerfile` — `PIN_DRIFT_REPO_ROOT` env +
`fail-baseline.json` COPY
- `showcase/harness/src/probes/aimock-wiring.ts` — exclude list addition
- `showcase/harness/config/probes/smoke.yml` — matching exclude list
addition

## Test plan

- [x] `qa.test.ts` — 13/13 pass
- [x] `pin-drift.test.ts` — 26/26 pass
- [x] `aimock-wiring.test.ts` (driver) — 16/16 pass
- [x] `aimock-wiring.test.ts` (probe) — 25/25 pass
- [ ] CI green

No fixture changes. No behaviour changes to probe logic.
2026-05-26 15:25:10 -07:00
Jordan Ritter 8daaf3c4b9 fix(showcase-harness): repair three pre-existing probe failures post-Slice 3
- qa probe: manifest.yaml path corrected from showcase/packages/ to
  showcase/integrations/ (Slice 3 moved files; probe code and test
  fixture still referenced the old path).
- pin-drift probe: fail-baseline.json ENOENT in container — the 5-level
  import.meta.url walk-up from dist/probes/drivers/ overshoots /app and
  lands at /. Added PIN_DRIFT_REPO_ROOT=/app env var and COPY of the
  baseline file into the runtime stage.
- aimock-wiring probe: showcase-ms-agent-harness-dotnet (deployed: false)
  was not in the EXCLUDE_SERVICES set, causing it to be flagged as
  unwired. Added to the exclude list in both aimock-wiring.ts and
  smoke.yml.
2026-05-26 15:24:27 -07:00
Jordan Ritter b1c4b3ffbf chore(showcase-agno): mark gen-ui-interrupt + interrupt-headless as not_supported (#5027)
agno uses useFrontendTool Strategy B (not LangGraph interrupt()).
Matches google-adk precedent. Lets the D6 probe skip these features
cleanly. Removes the corresponding agno D6 fixtures.
2026-05-26 15:21:22 -07:00
Jordan Ritter 250d33d91d docs(showcase): rename probe references e2e-deep → d6-all-pills (#5026)
Slice 3 renamed the probe drivers; two docs still referenced the old
name. Pure docs change, no behavior.
2026-05-26 15:21:21 -07:00
Jordan Ritter 43ddf0372c chore(showcase-agno): mark gen-ui-interrupt + interrupt-headless as not_supported
agno uses useFrontendTool (Strategy B) — async Promise handler in the
frontend — rather than LangGraph's native interrupt() primitive. The D5
probe asserts via useInterrupt hook which routes through the LangGraph
interrupt event path. agno doesn't emit those events; the D5 probe
fundamentally cannot pass against agno's HITL architecture without
per-integration probe-code divergence (which would violate the D6
apples-to-apples invariant).

Excluding these two features at the manifest level (matching google-adk
precedent) lets the D6 probe skip them cleanly. Removes the
corresponding D6 aimock fixtures since they're no longer reachable.

If agno gains LangGraph-style interrupt() support, or if aimock gains
AG-UI-event fixture authoring, this exclusion can be reverted.
2026-05-26 15:20:58 -07:00
Jordan Ritter 0d25521969 docs(showcase): rename probe references e2e-deep → d6-all-pills
Slice 3 (#5022) renamed the e2e-deep probe driver to d6-all-pills
(also d4-chat-roundtrip + d5-single-pill in the same family). The
two operator-facing docs still referenced the old names. Fix.

No probe behavior change.
2026-05-26 15:20:55 -07:00
Mark c25c14fcac Merge branch 'main' into mark/oss-191-fix-mcp-apps-zod-4-record-schema-incompatibility 2026-05-26 15:01:40 -07:00
Austin Merrick 7255531e2e docs: port coding-agents → build-with-agents rename to shell-docs (#5023)
## Summary

Ports the changes from PR #4927 to the live shell-docs app. PR #4927
renamed \`coding-agents\` → \`build-with-agents\` in the legacy
\`docs/\` tree, but \`showcase/shell-docs\` has its own independent
content directory that was never updated.

## Changes

- **11 file renames:** \`coding-agents.mdx\` → \`build-with-agents.mdx\`
(root + 10 integrations: ag2, agno, aws-strands, built-in-agent,
crewai-flows, langgraph, llamaindex, mastra, microsoft-agent-framework,
pydantic-ai)
- **Frontmatter titles:** \`"Coding Agents"\` → \`"Build with agents"\`
in all 11 files
- **Root \`build-with-agents.mdx\`:** replaced 291 lines of hardcoded
content with \`<MCPSetup />\` shared snippet (content had drifted from
the canonical snippet)
- **9 integration \`meta.json\` files:** \`"coding-agents"\` →
\`"build-with-agents"\` in sidebar nav
- **Root \`meta.json\`:** rename entry + add React Native under new
\`---Platforms---\` section (mirrors PR #4927's second commit)
- **\`seo-redirects.ts\`:**
- Update S4 (\`vibe-coding-mcp\`) and S15 (\`mcp\`) subpath destinations
to \`build-with-agents\`
- Add S16: \`coding-agents\` → \`build-with-agents\` subpath rename for
all 13 legacy framework slugs
- Add \`CODING_AGENTS_RENAMES\`: root \`/coding-agents\` + all canonical
framework \`/*/coding-agents\` → \`/*/build-with-agents\` (exact 301s)
  - Fix stale destinations in F20, R12, R18, R19
- **\`docs-render.tsx\`:** update \`SUBPATH_TO_COMPONENT\` key
\`"coding-agents"\` → \`"build-with-agents"\` so pages at the new slug
still resolve the shared MCP snippet

## Test plan

- [x] \`/coding-agents\` 301-redirects to \`/build-with-agents\`
- [x] \`/langgraph-python/coding-agents\` 301-redirects to
\`/langgraph-python/build-with-agents\`
- [x] \`/mcp\` and \`/vibe-coding-mcp\` redirect to
\`/build-with-agents\`
- [x] Sidebar shows "Build with agents" entry in each integration
- [x] React Native appears under Platforms section in root sidebar
- [x] All 11 \`build-with-agents\` pages render content correctly (MCP
setup snippet loads)
- [x] Root \`/build-with-agents\` shows correct MCP setup content
2026-05-26 15:01:17 -07:00
Mark 648b1aa8c7 Merge branch 'main' into mark/oss-191-fix-mcp-apps-zod-4-record-schema-incompatibility 2026-05-26 14:46:11 -07:00
Mark Fogle 70f54a8403 fix: use two-argument z.record for Zod 4 compatibility, add lint guard
Zod 4 made the key schema mandatory for z.record, so the single-argument
z.record(valueType) form is a compile-time error (TS2554) when built against
Zod 4. @copilotkit/react-core declares zod ">=3.0.0", so downstream apps on
Zod 4 are affected; runtime parsing is unaffected under both majors.

- react-core + vue MCPAppsActivityContentSchema: toolInput now uses the
  two-argument z.record(z.string(), z.unknown()) form
- react-core defineToolCallRenderer test: same fix for a metadata schema
- add a toolInput field-contract test (round-trips mixed value types)
- add copilotkit/no-single-arg-zod-record oxlint rule (autofix), enabled as
  error for packages/**; the incompatibility is type-level, so no runtime
  test can guard it while the workspace lockfile pins Zod 3

Closes #4295

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 21:33:55 +00:00
Austin Merrick 50b4fd8b60 docs(shell-docs): remove internal ticket reference from seo-redirects comment 2026-05-26 14:18:17 -07:00
Jordan Ritter e39f1ab4ed feat(showcase-aimock): per-integration D6 fixtures across 18 integrations (#5024)
## Summary

Adds per-integration D6 aimock fixtures for 18 showcase integrations,
completing the D6 probe coverage that #5022 (Slice 3) scaffolded. Each
integration now has the standard set of D5 feature-type fixtures
(agent-config, auth, byoc, gen-ui-*, interrupt-headless, multimodal,
prebuilt-*, tool-rendering-*) under `showcase/aimock/d6/<integration>/`.

## Why

Slice 3 (#5022) shipped the per-integration directory structure + D6
probe driver + harness scoping. The first D6 probe run reported most
integrations RED because most integrations' D6 directories were missing
per-feature fixtures (only langgraph-python had any). This PR fills in
those gaps.

## Authoring rules applied

- Every fixture has `match.context = "<integration>"` for
cross-integration isolation
- toolCall responses use `hasToolResult: false` (or
`toolName`/`toolCallId` gates) to prevent re-match loops
- Conversation turns match the corresponding D5 probe scripts at
`showcase/harness/src/probes/scripts/d5-<feature>.ts`
- Reference shape: langgraph-python's fixtures + each integration's
existing D5/D6 fixture conventions
- Skipped features: each integration's `not_supported_features` list
(e.g., google-adk skips gen-ui-interrupt + interrupt-headless)

## CR

Two rounds of 7-agent unbiased CR converged. R1 surfaced 5 bucket-(a)
findings, all addressed in R2 fix commit. R2 confirmation converged with
no in-scope regressions.

## Test plan

- [ ] Showcase auto-redeploys on merge (path filter matches
`showcase/**`)
- [ ] Next D6 probe cycle on production harness writes
`d6:<slug>/<featureId>` rows for all 18 integrations
- [ ] Dashboard D6 chips reflect real per-integration state instead of
all-gray
2026-05-26 14:08:33 -07:00
Jordan Ritter 98b6963d8d fix(showcase): bump aimock fixture collision ceilings for D6 coverage
Bumps exact-duplicate ceiling 11 → 230 and substring-shadow ceiling
126 → 151. The D6 per-integration fixtures naturally share match keys
with pre-existing demo fixtures in the same context scope, disambiguated
at runtime by the active demo/probe path.
2026-05-26 14:02:18 -07:00
Jordan Ritter 03ce685ae6 feat(showcase-aimock): D6 fixtures for ag2, agno, crewai-crews, langroid,
llamaindex, mastra, pydantic-ai, spring-ai, strands, built-in-agent

Adds per-integration D6 fixtures across 10 additional showcase
integrations, completing coverage for all 18 integrations.
2026-05-26 14:02:18 -07:00
Jordan Ritter 89d8440e7d feat(showcase-aimock): D6 fixtures for google-adk
Adds D6 fixtures for google-adk; skips gen-ui-interrupt and
interrupt-headless per the integration's not_supported_features.
2026-05-26 14:02:17 -07:00
Jordan Ritter abe69c3d56 feat(showcase-aimock): D6 fixtures for Microsoft Agent Framework integrations
Adds per-integration D6 fixtures for ms-agent-python and ms-agent-dotnet.
2026-05-26 14:02:17 -07:00
Jordan Ritter 4df07816b8 feat(showcase-aimock): D6 fixtures for Claude SDK integrations
Adds per-integration D6 fixtures for claude-sdk-python and
claude-sdk-typescript with Anthropic-style request/response shapes.
2026-05-26 14:02:17 -07:00
Jordan Ritter 69c964aca2 feat(showcase-aimock): D6 fixtures for LangGraph-based integrations
Adds per-integration D6 fixtures for langgraph-python, langgraph-typescript,
and langgraph-fastapi. Each fixture is keyed by match.context for cross-
integration isolation and uses hasToolResult:false on toolCall responses
to prevent re-match loops.
2026-05-26 14:02:17 -07:00
github-actions[bot] c9167b54e7 style: auto-fix formatting 2026-05-26 13:36:38 -07:00
Jordan Ritter 12fbc78802 fix(showcase/ms-agent-harness-dotnet): use Uri.IsLoopback for robust loopback detection
The previous wave-4 fix added `host == "::1"` for IPv6 loopback support,
but verification against `mcr.microsoft.com/dotnet/sdk:9.0` showed that
`new Uri("http://[::1]:8000/").Host` returns `"[::1]"` WITH brackets, not
`"::1"`. The string-equality check therefore never matched and IPv6
loopback detection was silently broken.

Switch to `Uri.IsLoopback`, which is the framework-provided helper that
robustly identifies all loopback variations: `localhost`, the entire
`127.0.0.0/8` range, `::1` in any bracketed form, and IPv4-mapped IPv6
loopback (`::ffff:127.0.0.1`). This sidesteps `Uri.Host`'s bracket-
formatting quirks entirely.

The explicit `0.0.0.0` (unspecified address, kept for back-compat) and
`aimock` (Docker-compose service name) checks are retained because they
are not loopback addresses.
2026-05-26 13:36:38 -07:00
Jordan Ritter 973c6dc800 fix(showcase/ms-agent-harness-dotnet): treat empty-string env vars as absent in ApiKeyResolver
ResolveApiKey and ResolveEndpoint previously cascaded through env var →
configuration sources using the `??` operator, which only short-circuits
on null. When `OPENAI_API_KEY=""` or `OPENAI_BASE_URL=""` was set in the
environment, the empty string was returned by the cascade WITHOUT
consulting the configuration fallbacks (`configuration["OPENAI_API_KEY"]`,
`configuration["GitHubToken"]`, `configuration["OPENAI_BASE_URL"]`),
masking the configured values entirely. The downstream
`IsNullOrWhiteSpace` check would then push the resolver into the
mock-or-throw path even when a valid key was configured.

Replace the `??` chains with a `FirstNonBlank` helper that treats both
null and whitespace-only candidates as absent, so empty env vars fall
through to the configuration fallbacks as intended.
2026-05-26 13:36:38 -07:00
Jordan Ritter fa5692c0da fix(showcase/ms-agent-harness-dotnet): narrow GenerateA2ui catch list so fail-fast exceptions propagate
Wave-1 widened the catch list in BeautifulChatAgent.GenerateA2ui from
specific upstream exceptions to a blanket catch (Exception ex). That
inadvertently swallowed InvalidOperationException thrown by
ApiKeyResolver.ResolveApiKey, which is the intentional fail-fast contract
for misconfigured deployments. With the blanket catch in place, a missing
or invalid API key produced a generic "unexpected_error" structured
response to end users while the operator received no clear startup-level
signal — exactly the silent-degradation failure mode the fail-fast was
designed to prevent.

Replace the blanket catch with specific catches for the two
runtime-recoverable exception types the secondary tool caller can throw
after the transport/SDK/cancellation handlers:

- JsonException — upstream returned malformed JSON
- KeyNotFoundException — upstream JSON missing required fields
  (defensive; TryGetProperty guards most paths after wave-1)

Both map to the existing "upstream_malformed" structured-error taxonomy.
All other exceptions, including configuration errors like
ApiKeyResolver's InvalidOperationException, now propagate so a
misconfigured deployment fails loudly at the operator layer instead of
limping along behind a generic user-facing message.
2026-05-26 13:36:38 -07:00
Jordan Ritter 4f66ba23ed fix(showcase/ms-agent-harness-dotnet): keep aimock header context for streaming response tail
ASP.NET Core hands control back to the middleware once the endpoint handler
completes via `await _next(context)`, but for streaming endpoints (AG-UI uses
`IAsyncEnumerable`/SSE) the response delegate continues writing to the response
body — and may issue downstream OpenAI calls — AFTER `_next` returns. The
previous `finally` clause reset `AimockHeaderContext` to an empty dictionary at
that point, which caused `AimockHeaderPolicy` to silently drop aimock headers
on those streaming-tail calls. That defeated the entire purpose of the
middleware for the exact codepath it was built to serve.

The `finally`-clear was also unnecessary for isolation: `AsyncLocal<T>` is
scoped to the current execution context, so each ASP.NET request gets its own
slot automatically. There is no cross-request leakage to defend against.

Remove the `try`/`finally` and just call `AimockHeaderContext.Set(headers)`
followed by `await _next(context)`. Add a comment documenting why no reset is
performed.
2026-05-26 13:36:38 -07:00
Jordan Ritter fc1be111b0 fix(showcase/ms-agent-harness-dotnet): correct IPv6 loopback host check
ApiKeyResolver.IsMockEndpoint compared Uri.Host against "[::1]", but
System.Uri.Host strips the surrounding brackets and returns "::1" for
inputs like http://[::1]:8000/. The bracketed comparison was therefore
dead code: developers running aimock on IPv6 loopback got the fail-fast
error instead of the intended mock-key fallback.

Change the literal to "::1" and update the inline + docstring comments
to reflect the bracket-less form.
2026-05-26 13:36:38 -07:00
Jordan Ritter 0f667c79a2 fix(showcase/ms-agent-harness-dotnet): guard null Messages and unify empty-output error shape
- BeautifulChatStateSnapshotAgent.RunCoreAsync now coalesces a null
  response.Messages to an empty array before constructing the new
  List<ChatMessage>. Previously, an inner agent that returned no
  messages would cause `new List<ChatMessage>(null)` to throw
  ArgumentNullException, masking the real upstream behaviour.
- GenerateA2ui's empty-content branch now returns the canonical
  BeautifulChatA2ui.StructuredError shape (error / message /
  remediation / errorId) like every other error path in the method,
  instead of an ad-hoc { error, errorId } object. The frontend
  expects the structured shape with remediation guidance.
2026-05-26 13:36:38 -07:00
Jordan Ritter c974b01721 fix(showcase/ms-agent-harness-dotnet): unify endpoint resolution between primary and secondary clients
Program.cs#CreateOpenAiClient previously read the OpenAI endpoint solely from
the OPENAI_BASE_URL environment variable and fell back to
ApiKeyResolver.DefaultOpenAiEndpoint. The secondary tool-calling HTTP client
(A2uiSecondaryToolCaller) instead routes through ApiKeyResolver.ResolveEndpoint,
which checks env, then configuration[OPENAI_BASE_URL] (appsettings.json /
user-secrets), then the default.

When OPENAI_BASE_URL was supplied only via configuration (e.g. user-secrets in
local dev), the primary client silently dialed the public Azure-hosted models
endpoint while the secondary client dialed the configured aimock. The two
endpoints diverged with no visible signal, breaking aimock-routed flows and
masking misconfigurations.

Switch CreateOpenAiClient to call ApiKeyResolver.ResolveEndpoint so both
clients share a single source of truth. Logging is preserved and now reports
which source supplied the endpoint (env, configuration, or default).
2026-05-26 13:36:38 -07:00
Jordan Ritter 44733961ad fix(showcase/ms-agent-harness-dotnet): log silent header drops in aimock middleware
When iterating IHeaderDictionary's underlying store yields case-variant
duplicates (e.g., a misbehaving proxy injecting both `X-Foo` and `x-foo`),
the previous GroupBy + ToDictionary path silently kept only the first value
and discarded the rest. For aimock context routing — where header semantics
drive fixture selection — silent drops are a debugging nightmare.

We still keep `.First()` because HTTP defines no canonical merge for
case-variant collisions across distinct keys (the comma-join rule only
applies when keys are ASCII-equal). Instead, when a group has more than
one entry, we emit a structured warning naming the key, the kept value,
and the number of dropped variants, so operators can spot the upstream
misbehavior in logs.

Constructor now takes `ILogger<AimockHeaderMiddleware>` — ASP.NET's
middleware activator injects it automatically via `UseMiddleware<T>()`.
2026-05-26 13:36:38 -07:00
Jordan Ritter 3366674c3b fix(showcase/ms-agent-harness-dotnet): tighten IsMockEndpoint and reject whitespace API keys
Two surgical hardening fixes to ApiKeyResolver:

1. IsMockEndpoint: drop host.StartsWith("aimock.", ...) and
   host.EndsWith(".aimock", ...). The StartsWith match is exploitable
   — an attacker-registered domain like aimock.attacker.example.com
   would be classified as a mock endpoint and bypass the fail-fast,
   silently returning the mock key. The EndsWith match is unused
   noise (no .aimock TLD exists). Only exact, well-known mock hosts
   ("localhost", "127.0.0.1", "0.0.0.0", "[::1]", "aimock") are
   accepted. IPv6 loopback [::1] is added so dual-stack dev paths
   are still covered.

2. ResolveApiKey: change !string.IsNullOrEmpty(apiKey) to
   !string.IsNullOrWhiteSpace(apiKey). A whitespace-only key such as
   " " would otherwise be accepted as valid, bypassing the mock-key
   /fail-fast logic entirely and sending a bogus key upstream.
2026-05-26 13:36:38 -07:00
Jordan Ritter d6f19475c1 fix(showcase/ms-agent-harness-dotnet): make state snapshot emission defensive
- RunCoreAsync: avoid mutating AgentResponse.Messages in place. Reassign
  Messages to a fresh List<ChatMessage> so the path is safe regardless of
  whether the inner agent returns a mutable list or an immutable
  IReadOnlyList wrapper. Prevents NotSupportedException at runtime; all
  other response metadata (AgentId, ResponseId, Usage, RawRepresentation,
  ...) is preserved via the property setter.

- RunCoreStreamingAsync: only emit the trailing todos snapshot if the
  inner stream completed normally. Wrap the inner enumerator in
  try/finally with a streamCompletedNormally flag; on early exit
  (throw or cancellation) log a warning and skip the snapshot rather
  than emitting potentially stale state to the frontend. The trailing
  yield lives outside the try block (idiomatic C# pattern since `yield`
  cannot live inside `try { } catch { }`).
2026-05-26 13:36:38 -07:00
Jordan Ritter 2e33d58a63 fix(showcase/ms-agent-harness-dotnet): tighten IsMockEndpoint to host-only match
The previous implementation used Contains() substring matching against the
full endpoint URL, which is exploitable. An attacker-controlled endpoint
such as https://attacker.example.com/aimock-decoy or
https://api.openai.com/?env=localhost would be classified as a mock and
bypass the fail-fast guard, silently returning the sk-mock-local key for
what is actually a non-mock destination.

Parse the URL and inspect only the host component, matching exact dev
hosts (localhost, 127.0.0.1, 0.0.0.0, aimock) plus aimock subdomains.
Path, query, and arbitrary subdomain segments containing "aimock" or
"localhost" no longer trigger the mock fallback.
2026-05-26 13:36:38 -07:00
Jordan Ritter 514f630904 fix(showcase/ms-agent-harness-dotnet): unify aimock header casing and dedupe-safety
The header propagation chain (middleware -> context -> policy) had two bugs
that combined to threaten D5/D6 header-forwarding:

1. AimockHeaderMiddleware.ToDictionary used the default ORDINAL case-sensitive
   comparer. ASP.NET's IHeaderDictionary is case-insensitive, but iterating
   the underlying store can yield case-variant duplicates (e.g., a misbehaving
   proxy injecting both `X-Foo` and `x-foo`). Default-comparer ToDictionary
   throws ArgumentException on duplicates and fails the request.

2. AimockHeaderContext.Set lowercased all keys via ToLowerInvariant.
   AimockHeaderMiddleware captured original case; the context then mutated
   the casing; AimockHeaderPolicy.TryGetValue then matched against whatever
   case the OpenAI SDK happened to use. This is inconsistent and aimock
   fixture matching can be case-sensitive depending on configuration.

Canonical strategy: preserve original header casing as captured by the
middleware, but compare case-insensitively throughout via
StringComparer.OrdinalIgnoreCase. The middleware now also groups variants
defensively so duplicate keys cannot blow up the dictionary build.
AimockHeaderPolicy's add-if-absent TryGetValue then works correctly under
case-insensitive comparison without any further changes.
2026-05-26 13:36:38 -07:00
Jordan Ritter 2005203725 fix(showcase/ms-agent-harness-dotnet): empty placeholder values in .env.example
The GitHubToken line shipped `ghp_...` as a literal placeholder VALUE. When
a developer runs `cp .env.example .env` and forgets to edit, the entrypoint's
`-z "$GitHubToken"` check sees a non-empty string and skips the "key missing"
warning. The literal `ghp_...` is then sent upstream, producing a confusing
401 that looks like an OpenAI/GitHub Models bug rather than a setup issue.

Move the format example into a comment above the line and leave the value
empty so the empty-value check in entrypoint.sh fires the clear warning.
OPENAI_API_KEY was already empty (prior fix); verified still empty.
2026-05-26 13:36:38 -07:00
Jordan Ritter d1169ca8be fix(showcase/ms-agent-harness-dotnet): harden container startup and align .env.example
- entrypoint.sh: replace `sleep 3 && kill -0` agent-startup gate with a curl
  retry loop against /health on :8000 (up to 30s). The bare PID check only
  proved the process existed; if Kestrel hadn't finished binding, Next.js
  would proxy to a dead backend for ~90s until the watchdog killed the
  container.
- entrypoint.sh: watchdog now also supervises Next.js. If Next.js dies while
  the agent stays healthy the watchdog breaks out so wait -n can return and
  Railway can restart the container instead of serving a broken page.
- entrypoint.sh + .env.example: align the env-var contract with what
  agent/Program.cs actually reads. The .NET agent uses OPENAI_API_KEY,
  GitHubToken (fallback), and optional OPENAI_BASE_URL — it never reads
  AZURE_OPENAI_API_KEY. The startup warning and .env.example now document
  the real key precedence plus every Next.js-side var (AGENT_URL,
  NEXT_PUBLIC_BASE_URL, MCP_SERVER_URL, SHOWCASE_DEBUG_TOKEN).
2026-05-26 13:36:38 -07:00
Jordan Ritter 7ca976ada0 fix(showcase/ms-agent-harness-dotnet): rename ProverbsAgent → BeautifulChatAgent csproj, regen UserSecretsId, drop dead InternalsVisibleTo 2026-05-26 13:36:38 -07:00
Jordan Ritter a939054d8a fix(showcase/ms-agent-harness-dotnet): harden A2uiSecondaryToolCaller + centralize API key resolution
- Replace silent `return null` paths in A2uiSecondaryToolCaller with
  TryGetProperty guards that each emit a structured LogWarning naming
  the exact missing/unexpected field (choices, message, tool_calls,
  function, name mismatch, arguments). Callers can now tell why a
  design-tool call produced no content.
- Add ILogger parameter to GetDesignToolArgumentsAsync and pass
  BeautifulChatAgent._logger from the single call site so warnings
  flow into the existing log stream.
- Log the response body (truncated to 1 KB) at LogWarning before
  EnsureSuccessStatusCode throws, so upstream error payloads survive
  the throw and reach operators.
- Extract the OPENAI_API_KEY/GitHubToken/sk-mock-local fallback chain
  from Program.cs and A2uiSecondaryToolCaller.cs into a new
  ApiKeyResolver helper. Both call sites now share one implementation.
- ApiKeyResolver fails fast with InvalidOperationException + LogCritical
  when no real key is present and OPENAI_BASE_URL is not an
  aimock/localhost endpoint, so misconfigured prod deploys cannot
  silently send sk-mock-local to a real LLM provider. The silent
  mock-key fallback is preserved for aimock/localhost dev endpoints.
2026-05-26 13:36:38 -07:00
Jordan Ritter 4ecfb23874 fix(showcase/ms-agent-harness-dotnet): harden BeautifulChatAgent defensive paths
- RunCoreAsync: append todos snapshot DataContent to AgentResponse so non-streaming
  callers receive the same state mirror that RunCoreStreamingAsync already emits.
- ManageTodos: defensive-copy each incoming todo before storing (mirrors the
  symmetry of GetTodosSnapshot) so callers cannot mutate our backing list by
  retaining input references.
- ManageTodos: validate Status against the documented "pending" | "completed" set;
  coerce out-of-range values to "pending" with a LogWarning instead of letting
  arbitrary LLM-supplied strings into shared state.
- GenerateA2ui: add a final catch (Exception) returning a StructuredError
  ("unexpected_error", ...) matching the existing taxonomy, and log an info-level
  entry when OperationCanceledException flows through (was previously silent).
2026-05-26 13:36:38 -07:00
Jordan Ritter 85d24b5246 fix(showcase/ms-agent-harness-dotnet): preserve existing headers in AimockHeaderPolicy
AimockHeaderPolicy previously called message.Request.Headers.Set(...)
unconditionally for every key returned by AimockHeaderContext, which
silently clobbered any header already set by an earlier pipeline policy
or the SDK itself (e.g. x-request-id, x-correlation-id).

Switch both Process and ProcessAsync to add-if-absent semantics, using
PipelineRequestHeaders.TryGetValue to skip keys that already have a value
on the outbound request. New aimock x-* headers still propagate; existing
correlation/SDK headers are preserved.
2026-05-26 13:36:38 -07:00
Jordan Ritter 84c0ccf538 fix(showcase/ms-agent-harness-dotnet): preserve agent state when updating todos 2026-05-26 13:36:38 -07:00
Jordan Ritter 8c8c563389 fix(showcase/ms-agent-harness-dotnet): align package manager
Aligned everything to npm to match what the Dockerfile already uses
(`npm ci --legacy-peer-deps`) and the committed `package-lock.json`.
The sibling `ms-agent-dotnet` integration uses the same npm-based
setup, so npm is the established convention.

Changes:
- playwright.config.ts: webServer.command now `npm run dev` (was `pnpm dev`),
  so local E2E works in environments without pnpm installed.
- package.json: removed the redundant top-level `pnpm.overrides` block.
  The equivalent override is already declared under npm's `overrides`
  field, so the pnpm block was dead weight given that npm is canonical.
- package.json: `scripts.dev` now uses `concurrently -k --success first`
  so a crashing .NET agent surfaces during local dev instead of leaving
  Next running headlessly.
2026-05-26 13:36:38 -07:00
Jordan Ritter c03e6f048a chore(showcase): flag aimock --proxy-only as dev-only in docker-compose.local
Add a prominent warning banner above the aimock service block in
showcase/docker-compose.local.yml documenting that --proxy-only lets
unmatched fixture requests fall through to real OpenAI/Anthropic/Gemini.

That behavior is fine for interactive local dev (you can capture new
fixtures from real responses) but dangerous in any automated context:
a missing fixture produces a real LLM response, and tests/CI see a
green check that is actually a false positive while burning real
provider tokens. Comment-only change; no behavior change.
2026-05-26 13:36:38 -07:00
Alem Tuzlak 2405a46fa6 feat(showcase): add ms agent harness dotnet chat 2026-05-26 13:36:38 -07:00
Austin Merrick 268b8c1a18 docs(shell-docs): remove Tadata callout from MCP server setup snippet 2026-05-26 13:31:02 -07:00
Austin Merrick f7463fb5b1 fix(oss-133): remove CANONICAL_FRAMEWORKS decl to avoid merge conflict with main
main added its own CANONICAL_FRAMEWORKS const after this branch was cut.
CI tests the merge commit, so the duplicate declaration caused a build
error. Replace with an inline derivation from FRAMEWORKS so the variable
is self-contained and never conflicts with whatever main defines.
2026-05-26 13:13:11 -07:00
Austin Merrick dbfe929d78 fix(oss-133): replace hardcoded root build-with-agents.mdx with shared snippet
The root /build-with-agents page had 290 lines of inline content that had
drifted from the canonical mcp-server-setup.mdx snippet: wrong MCP endpoint
paths (/mcp vs /sse), and missing Tadata attribution Callout that every
per-framework build-with-agents page renders.

Replace with <MCPSetup /> to use the same shared snippet as the langgraph
integration page, ensuring the root page and all framework pages render
identical, authoritative content from a single source of truth.
2026-05-26 12:36:16 -07:00
Austin Merrick d3d5fb4bd0 fix(oss-133): deduplicate CODING_AGENTS_RENAMES by excluding unchanged-slug frameworks
S16 in SUBPATH_RENAMES already generates /<fw>/coding-agents → /<fw>/build-with-agents
for all 13 legacy frameworks including unchanged-slug ones (agno, ag2, pydantic-ai,
llamaindex, mastra, agent-spec, a2a). Including them in CANONICAL_FRAMEWORKS created
7 duplicate source entries in the redirect table, corrupting PostHog decommission
attribution (the CA×<fw> IDs would never get traffic).

Restrict CANONICAL_FRAMEWORKS to frameworks whose canonical slug differs from their
legacy slug (langgraph-python, google-adk, crewai-crews, ms-agent-dotnet, strands,
built-in-agent) — these are the ones S16 can't cover since S16 sources use legacy slugs.
2026-05-26 12:21:01 -07:00
Austin Merrick 5a5781a191 fix(oss-133): define CANONICAL_FRAMEWORKS to fix TS2304 compile error
CANONICAL_FRAMEWORKS was referenced in CODING_AGENTS_RENAMES but never
defined, causing a TypeScript error. Derive it from FRAMEWORKS.map(canonicalSlug)
so all 13 canonical slugs (langgraph-python, google-adk, strands, etc.) get
/coding-agents → /build-with-agents redirects.
2026-05-26 12:08:45 -07:00
Jordan Ritter 76020857e2 feat(showcase): per-framework D4/D6 aimock fixtures + D6 probe driver + harness scoping (#5022)
## Summary

Lands the per-framework fixture reorg + D6 probe driver + harness
scoping work that was parked behind the ag-ui header-forwarding chain
(now shipped via #4984, #4951, #5015, #5016).

This is the foundational data layer the D6 dashboard needs to populate.
Slice 1 (#5018) shipped the rendering plumbing earlier today; this PR
makes d6:<slug>/<featureId> PB rows start flowing.

## What ships

- 477 per-integration aimock fixtures organized under `d4/`, `d6/`,
`shared/` directories (flat `d5-all.json` / `feature-parity.json`
deprecated)
- Every fixture keyed by `match.context` to enforce per-integration
isolation (server-side routing already merged in aimock #226)
- D6 all-pills probe driver + per-integration scoping in
showcase-harness
- X-AIMock-Context header propagation in 18 integration Playwright
configs
- D6-ceiling chip color algorithm (D6 is integration-scoped aggregate,
maxPossible raised from 5 to 6)
- Docker-compose updates for the new fixture dir layout
- 12 HITL fixtures migrated from main's d5-all.json additions into
shared/_migrated-from-d5-all-hitl.json

## Why this is safe to ship now

- ag-ui/LangGraph configurable+context HTTP 400 blocker is fixed (#5015
+ #5016)
- sdk-python 0.1.91 with `_extract_forwarded_headers_from_config` is on
PyPI and pinned across showcase
- aimock server-side context routing is already live (aimock #226)
- The SDK overlay hacks the branch carried locally are now redundant —
discarded before rebase

## Pre-existing CI note

`@copilotkit/web-inspector:test` has a pre-existing failure
(`window.localStorage.clear is not a function` in telemetry tests) —
verified on clean main checkout. Not introduced by this PR.

## Follow-ups

- Distribute migrated HITL fixtures from shared/_migrated-from-*.json
into per-integration d6/<slug>/ files
- Slice 2: D6 drilldown DIMENSIONS + AdaptiveStatsBar rollup section
- LGP gen-ui-interrupt second-pill framework bug (Hypothesis B in
useInterrupt hook)
2026-05-26 11:59:46 -07:00
Austin Merrick 7669016c3d docs(OSS-133): port coding-agents → build-with-agents rename to shell-docs
PR #4927 landed this rename in the legacy `docs/` tree, but `showcase/shell-docs`
has its own content directory that was never updated.

Changes:
- Rename 11 `coding-agents.mdx` → `build-with-agents.mdx` (root + 10 integrations)
- Update frontmatter title "Coding Agents" → "Build with agents" in all 11 files
- Update `"coding-agents"` → `"build-with-agents"` in 9 integration meta.json nav files
- Update root meta.json: rename entry + add React Native under new ---Platforms--- section
- seo-redirects.ts: update S4/S15 subpath destinations; add S16 (coding-agents→build-with-agents)
  subpath rename for all legacy framework slugs; add CODING_AGENTS_RENAMES for root + all
  canonical framework slugs; fix stale destinations in F20, R12, R18, R19
- docs-render.tsx: update SUBPATH_TO_COMPONENT key "coding-agents" → "build-with-agents"
2026-05-26 11:55:28 -07:00
Jordan Ritter ef3e59643b fix(showcase): update fixture routing tests for per-integration D6 layout
The four fixture routing regression tests still referenced the old
monolithic d5-all.json / smoke.json / feature-parity.json files that
were reorganized into per-integration d4/ d6/ shared/ directories.

Changes:
- Load fixtures via glob from d6/langgraph-python/ (reference
  integration) instead of deleted monolithic files
- Add _context to test requests (aimock 1.26.1 checks req._context
  against match.context for per-integration scoping)
- Adapt subagents test from toolCallId-based chaining to
  turnIndex-based chaining (matches new D6 fixture structure)
- Adapt state-context test to D6 context-scoping model (no
  systemMessage matching; routing happens via X-AIMock-Context)
- Remove _migrated-from-*.json shared files (all fixtures already
  exist in per-integration D6 dirs; the migration files caused
  620 shared-vs-scoped collisions)
- Add KNOWN_DUPLICATE_CEILING=11 ratchet for pre-existing D6
  intra-feature duplicate match keys
2026-05-26 11:54:06 -07:00