Commit Graph

12629 Commits

Author SHA1 Message Date
Jordan Ritter 6929ad1c33 refactor(harness): extract CvdiagProbeSession into shared cvdiag/probe-session
Behavior-preserving extraction of the CvdiagProbeSession lifecycle from the
d4 chat-roundtrip driver into a shared cvdiag/probe-session module, so the
d5/d6 probe path can reuse the same session boundaries. d4-chat-roundtrip
now imports the extracted session instead of defining it inline.
2026-06-22 16:42:31 -07:00
Sam Julien b9b08381ba docs: backport Threads guide to authored integrations (#5620)
## Summary

- Backports the generated/root Threads guide content into the shared
authored Threads snippet.
- Adds the CLI “Choose your starting point” path, manual path, thread
lock options, Enterprise Intelligence CTA, and corrected next-step links
to authored Threads docs.
- Standardizes authored integration Threads pages to explicitly import
the shared snippet with `components={props.components}` so authored
routes stay aligned.

## Authored routes covered

- AG2
- Agno
- AWS Strands
- Built-in Agent
- CrewAI Flows
- LangGraph
- LlamaIndex
- Mastra
- Microsoft Agent Framework
- PydanticAI

## Validation

- `npm run pretypecheck` in `showcase/shell-docs`
- `npm run lint` in `showcase/shell-docs` (passes with existing
warnings)
- `npm run test` in `showcase/shell-docs`
- `npm run typecheck` in `showcase/shell-docs`
- `npm run build` in `showcase/shell-docs` (passes with existing
Next/Turbopack warnings)
- `git diff --check`
- Manual MDX link sweep for changed docs links (`/premium/self-hosting`,
`/premium/threads-explained`, `/reference/hooks/useThreads`, and
`http://localhost:3000`)

## Formatter note

- `pnpm run check-format` currently fails on unrelated existing files
under `examples/showcases/arcade-tools/*`,
`examples/v2/react/demo/tsconfig.json`, `migrations.json`, and
`nx.json`.
- Scoped `oxfmt --check` does not treat the changed MDX files as target
files, so there is no formatter-owned MDX change to apply here.
2026-06-22 15:47:07 -07:00
Sam Julien 2fe292e4c7 docs(shell-docs): clarify tailored content selectors (#5621)
## Summary
- restyle TailoredContent selectors as native segmented path buttons
- add a selected check indicator plus hover/focus affordances
- add a rendering test for button semantics and selected state

## Verification
- pnpm exec oxfmt --check
showcase/shell-docs/src/components/react/tailored-content.tsx
showcase/shell-docs/src/components/react/__tests__/tailored-content.test.tsx
- npm run lint (showcase/shell-docs; existing warnings only)
- npm run typecheck (showcase/shell-docs)
- npm run test (showcase/shell-docs)
- npm run build (showcase/shell-docs; existing Turbopack NFT trace
warning)

## Notes
- Repo-wide pnpm check-format currently fails on unrelated pre-existing
files outside this PR; the touched files pass scoped oxfmt check.
2026-06-22 15:46:53 -07:00
Jordan Ritter 2610b87bcb perf(showcase): within-tier parallel fan-out for promote-fleet so service=all fits the timeout (#5622)
## Summary

A full `service=all` promote ran **fully serially** and exceeded the
promote job's 20-minute `timeout-minutes`, getting cancelled mid-fleet
(silent partial promotion). This adds **within-tier parallel fan-out**
so `all` completes in budget.

## Changes

- **`promote-fleet.sh`** — within a tier, `promote_one` is backgrounded
up to `PROMOTE_FANOUT` (default 5) via a **bash-3.2-safe** PID-array
bounded launcher (plain `wait <pid>`, no `wait -n`/`declare -n`).
Per-service results go to temp files (`$WORK/<svc>.rc/.drift/.log`) and
`reap_tier` repatriates them into `succeeded[]`/`failed[]`/`drift[]`
(subshell-safe — backgrounded children can't mutate parent arrays).
**Tier boundaries are hard barriers** (all PIDs drained before the next
tier); cross-tier stays serial. A present-but-empty/non-numeric `.rc`
(crash/disk-full mid-write) is treated as a clean failure, not parsed as
garbage.
- **`showcase_promote.yml`** — wires `CLOSURE_PLAN` into the promote
step (was flat `SERVICES_CSV`) so the fan-out is tier-aware; bumps the
promote job `timeout-minutes` **20 → 35**.
- **`promote-fleet.bats`** — new fan-out tests with a **deterministic
rendezvous-barrier** concurrency proof (no wall-clock sleep race;
RED-on-serial preserved via timeout), tier-barrier boundary-inclusive
(`>=`), and the empty-`.rc`-as-failure case.
- `SC2317,SC2329` shellcheck disable for the trap-only `cleanup()`
(ubuntu-24.04 CI ships shellcheck 0.9.0).

## Test plan

- [x] bats **27/27** (file) / **108/108** (dir) green
- [x] shellcheck clean on local 0.11.0 **and** pinned CI 0.9.0
- [x] actionlint clean on the workflow
- [x] within-tier concurrency ≤ cap and reaches cap; tier barrier holds;
one failure doesn't abort its tier + run exits nonzero
2026-06-22 15:45:19 -07:00
Nathan 🔶 Tarbert 7d644f22fa fix: reject pending human-in-the-loop promise on run abort (#5554) 2026-06-22 18:04:50 -04:00
Jordan Ritter c2c19c0853 perf(showcase): within-tier parallel fan-out for promote-fleet so service=all fits the timeout
promote-fleet.sh fans out promote_one within a tier up to PROMOTE_FANOUT
(default 5) via a bash-3.2-safe PID-array bounded launcher (plain `wait`, no
`wait -n`/`declare -n`); per-service results to temp files + reap_tier
repatriates (subshell-safe); tier boundaries are hard barriers (cross-tier
serial); showcase_promote.yml wires CLOSURE_PLAN + bumps timeout-minutes 20->35;
adds bats fan-out tests (deterministic rendezvous-barrier concurrency proof;
present-but-empty .rc treated as failed; tier-barrier boundary-inclusive `>=`);
SC2317/SC2329 shellcheck disable for ubuntu-24.04 0.9.0.
2026-06-22 14:50:16 -07:00
Jordan Ritter cd3844da65 refactor(showcase): make prod-vs-staging reconcile on-demand only (no cron, no Slack)
Prod sitting behind staging is often intentional (changes are batched and
promoted deliberately), so a recurring drift alert is noise. Reshape the
reconcile workflow to manual-only:

- Remove the daily `schedule:` cron trigger — leave only `workflow_dispatch`.
- Remove the auto-Slack-on-stale step (and its SLACK_WEBHOOK env / stale_line
  output derivation) — no unsolicited #oss-alerts post on mere staleness.
- A manual run surfaces the reconcile table to the GH step summary, keeps the
  cheap `--json` capture as an uploaded artifact, and still exits nonzero on a
  stale column so a manual run visibly flags drift.
- De-noise the gate script + bats comments that referenced the removed
  scheduled/Slack behavior.

The on-demand CLI (`bin/railway reconcile-prod`), the gate wrapper, and the
Ruby + bats tests are unchanged.
2026-06-22 14:20:02 -07:00
Jordan Ritter 90bcd66b09 feat(showcase): detect prod columns stale vs green staging (reconcile-prod drift gate)
Lever 1 of the promote-reliability hardening plan. The showcase deploy
model is staging=mutable :latest (continuously rebuilt), prod=immutable
@sha256: (advances only on explicit promote), so a prod column can
silently fall BEHIND a green staging — drift today is only noticed by
eyeballing a dead column. This adds proactive, automatic detection.

- bin/railway reconcile-prod: for every prod-eligible (probe.prod==true)
  service, compares the prod SERVING digest (LintProd snapshot path) vs
  the staging RUNNING digest (reuses PromoteCommand#staging_running_digest).
  Classifies green/stale/gray, prints a table + summary, exits 1 iff any
  stale. --json for machine output. Read-only: no promotes/mutations.
- scripts/reconcile-prod-gate.sh: wrapper mirroring lint-prod-gate.sh —
  surfaces the table to the GH step summary, captures JSON for the Slack
  builder, propagates the exit-code verdict.
- .github/workflows/showcase_reconcile.yml: daily cron + workflow_dispatch;
  runs the gate; on stale services posts the stale-column list to
  #oss-alerts (SLACK_WEBHOOK_OSS_ALERTS) via the fromJSON('"\n"') idiom.
- Tests: Ruby minitest (classification + exit-code, RED-anchored on a
  drift-blind classifier) and a bats gate test. Wired the gate script
  into the showcase_validate.yml shellcheck list.

Post-promote convergence verification is deferred to a fast-follow.
2026-06-22 14:14:18 -07:00
Sam Julien 3910d24aab docs(shell-docs): clarify tailored content selectors 2026-06-22 13:52:31 -07:00
Sam Julien fae187b5db docs: backport threads guide to authored integrations 2026-06-22 13:46:32 -07:00
Sam Julien f8df3abf75 docs: correct Enterprise Intelligence docs links (#5617)
## Summary
- Rename the overview capability from "Cloud-hosted web app" to
"Cloud-hosted Intelligence features".
- Remove the redirecting multi-conversation tutorial link from thread
docs, shared thread snippets, and useThreads references.

## Validation
- npm run test (showcase/shell-docs)
- npm run lint (showcase/shell-docs; exits 0 with pre-existing warnings)
- npm run typecheck (showcase/shell-docs)
- npm run build (showcase/shell-docs)
- Manual link sweep for edited MDX confirmed no remaining
/tutorials/multi-conversation-chat links
2026-06-22 13:24:30 -07:00
Austin Merrick 0f9009cca1 docs(teams): rewrite Microsoft Teams guide for @copilotkit/bot-teams
The previous guide documented an older API (createTeamsAgentBot, a local "Teams
DevTools" bridge) that shipped through copilotkitnext. Rewrite it for the new
createBot + teams() PlatformAdapter, mirroring the Slack guide: M365 Agents
Playground quickstart, interactive Adaptive Cards, a human-approval gate,
splitting the bot from its agent over AG-UI, and Azure sideloading into real
Teams. Also refresh the frontend picker summary (Playground, not DevTools).
2026-06-22 13:13:07 -07:00
Mark 33a2fbc167 fix(react-ui): add stable test ids to chat input (#4519)
## What does this PR do?

Adds stable test IDs to the CopilotChat input area so automated tests
can reliably target the default chat UI.

Changes included:

- Adds `data-testid="copilot-chat-input"` to the chat textarea.
- Adds standard `data-testid` values to the send and stop button.
- Keeps the existing `data-test-id` values for backwards compatibility.

This is a small non-breaking testability improvement for the React UI
package.

## Related PRs and Issues

Related to #4215

## Checklist

- [x] I have read the Contribution Guide
- [x] If the PR changes or adds functionality, I have updated the
relevant documentation
- [x] Allow edits by maintainers is checked
2026-06-22 12:25:04 -07:00
Mark af81e8e899 Merge branch 'main' into main 2026-06-22 12:03:31 -07:00
Jordan Ritter c432cb3d1e fix(showcase/harness): break fleet control-plane import cycle crashing the harness on boot (regression from #5616) (#5619)
## Hotfix — staging harness was crash-looping

PR #5616's on-demand-trigger code (`http/fleet-runs.ts`) imports
`control-plane.js` first, whose transitive load (`control-plane →
job-producer → run-view → control-plane`) evaluated `run-view.ts`'s
top-level `FLEET_FAMILIES` literal **before** `control-plane.ts`
finished assigning `FLEET_PRODUCER_SCHEDULE_ID` (+3 sibling schedule-id
constants) → `ReferenceError: Cannot access 'FLEET_PRODUCER_SCHEDULE_ID'
before initialization` → the harness never bound its port (staging
harness down; workers stuck on the stale digest).

The cycle was latent (prior load order happened to init the constants
first); the trigger change shifted load order and exposed it.

## Fix
New leaf module `fleet/control-plane/schedule-ids.ts` (zero imports)
holds the four `SCHEDULE_ID` constants. `control-plane.ts` re-exports
them (public surface unchanged); `run-view.ts` imports them from the
leaf instead of from `control-plane.js`. No eval-time edge into the
cycle → no TDZ.

## Verification (real boot — not just tsc; tsc passed while it crashed
at runtime)
- **RED** on main: `import('./dist/http/fleet-runs.js')` and
`import('./dist/orchestrator.js')` both threw the exact ReferenceError.
- **GREEN**: all four load orders (fleet-runs, orchestrator entrypoint,
control-plane, run-view) import clean; `FLEET_FAMILIES` builds with 4
entries.
- New regression guard `import-cycle-tdz.test.ts` (3 tests) asserts the
module graph imports without throwing.
- Fleet control-plane suite 347/347; broader fleet + fleet-runs +
orchestrator 814/814; `tsc --noEmit` clean (one pre-existing unrelated
`glob` env error, untouched).

## Note
CI's build-check compiles the harness image but never boots the fleet
control-plane, so this slipped through green. The new import test is a
boot-time regression guard.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-06-22 11:11:13 -07:00
Jordan Ritter 9a6780b853 fix(showcase/harness): break fleet control-plane import cycle — FLEET_PRODUCER_SCHEDULE_ID TDZ crashed the harness on boot (regression from #5616) 2026-06-22 11:01:48 -07:00
Sam Julien 477b1203c5 docs(shell-docs): correct intelligence docs links 2026-06-22 10:52:05 -07:00
Jordan Ritter 5f9c22a58a fix(cvdiag): complete cross-layer flap attribution (probe↔backend test_id join, failure classifier, on-demand trigger) (#5616)
## What

Completes the cvdiag observability subsystem so a single flapping
showcase run is **fully attributable end-to-end** — and makes every
probe reproducible on demand. Four fixes, all proven against the real
surface (live PocketBase writer-role, real `next` build, driver vitest):

1. **Cross-layer `test_id` join (the keystone).** Both sides were using
different ids: the backend minted its own UUIDv7, and the probe
re-minted a random UUIDv7 when its forwarded `X-Test-Id`
(`d6-<slug>-<runId>`) wasn't a UUIDv7. Now both run the same
`sanitizeJoinTestId` over the forwarded id → probe.* and backend.* rows
for one run **share `test_id`** (the join key per `schema.ts`); each
side keeps its own `trace_id`/`span`.
2. **Probe failure classifier.** `probe.exit` now stamps `outcome=err` +
`failure_classifier` (`sse-missing`/`dom-missing`/`text-unstable`) from
`waitForTurnComplete`'s reason, instead of `outcome=ok` on every run —
so reds are labeled, not inferred.
3. **Backend boundaries.** (Confirmed already on main — full 11-boundary
set incl `request.ingress`/`sse.first_byte`/`llm.call.*`.)
4. **On-demand trigger for EVERY probe.** New `POST
/api/runs/:family/trigger` (OPS-token-gated, rate-limited) fires any
fleet/D6 probe via the existing job-producer enqueue; in-process probes
keep their route. No more waiting on the hourly cron to reproduce a
flap.

## Why

cvdiag was live and persisting, but couldn't yet say "backend stall vs
frontend race" for a single red because probe and backend rows couldn't
be joined, reds weren't labeled, and D6 wasn't on-demand reproducible.
These close those gaps.

## Verification
- harness `tsc --noEmit` clean · cvdiag + drivers vitest **665 passed /
31 files** (join + classifier + boundary + trigger together) · 4
fix-test files 151 passed
- codegen `--check` + `cvdiag-stage-ts --check` in-sync (schema.json + 4
staged copies regenerated, not hand-merged)
- real Docker `next build` of built-in-agent succeeded (backend boundary
+ writer code bundles)
- live-PB writer-role RED→GREEN for the join; driver RED→GREEN for the
classifier; enqueue-assertion RED→GREEN for the trigger

## Follow-ups (not in this PR)
- Python dual-process (:8123) backend→PB shipping gap (python
integrations emit zero backend rows despite the auth fix)
- liveness-probe 400 noise → `outcome=info` + plumb real `model_id`
- Java/.NET backend writer-role auth
- break the run-view⇄control-plane import cycle the trigger routes
around

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-06-22 10:46:17 -07:00
github-actions[bot] 931e046f6d style: auto-fix formatting 2026-06-22 17:35:50 +00:00
Jordan Ritter 1a80d28f4e chore(cvdiag): regenerate schema.json + re-stage TS emitter after attribution-fix union merge
schema.json regenerated from the merged canonical schema.ts (failure_classifier
probe.exit additions UNION backend request.ingress/sse.first_byte/llm.call.*
boundaries + test_id adoption). Per-integration staged schema.ts copies
re-derived via 'showcase cvdiag-stage-ts' so codegen --check and stage --check
are both in sync. No hand-merge of generated artifacts.
2026-06-22 10:31:04 -07:00
Jordan Ritter b7576114dc feat(showcase/harness): on-demand trigger route for ALL probes incl fleet/D6 (OPS_TRIGGER_TOKEN-gated enqueue) 2026-06-22 10:30:23 -07:00
Jordan Ritter 1258c077f4 fix(cvdiag): probe.exit stamps the waitForTurnComplete failure classifier (sse-missing/text-unstable/dom-missing) so reds are labeled in cvdiag 2026-06-22 10:30:14 -07:00
Jordan Ritter e5450f7722 fix(cvdiag): probe records the forwarded X-Test-Id as its cvdiag test_id (sanitizeJoinTestId) so probe↔backend rows join 2026-06-22 10:30:09 -07:00
Jordan Ritter 4925d0fc60 fix(cvdiag): backend adopts inbound x-test-id as cross-layer test_id + emits request.ingress/sse.first_byte/llm.call.* boundaries (TS integrations) 2026-06-22 10:30:09 -07:00
Ben Taylor bfb4e171de fix(ci): pack workspace as tarball to bypass upload-artifact enumeration (#5046)
## Summary

- `upload-artifact`'s `!**/node_modules/**` filters are post-walk: the
action still descends into every `node_modules` and stats every file
(~6M with pnpm's `.pnpm/` symlink farm) before applying negations. That
enumeration is the actual bottleneck — `Upload workspace` runs 10+
minutes even with the filters added in #5044.
- Replace the filtered upload with: `rm -rf` the heavy dirs
(`node_modules`, `.nx`, `.turbo`, `.next`), `tar -czf /tmp/workspace.tgz
.`, upload that single file. Publish job `tar -xzf`'s it after download
and continues unchanged.
- Applied symmetrically to `prerelease.yml` and `publish-release.yml`.

## Measured impact

Verified on a dry-run dispatch of `release / pre` against this branch
([run
26531785850](https://github.com/CopilotKit/CopilotKit/actions/runs/26531785850)):

| Step | Before (run 26529550757) | After (this PR) |
| ------------------------------- | ------------------------ |
--------------- |
| Upload workspace | ~800s (cancelled) | **3s** |
| Pack workspace | — | 9s |
| Download workspace | — | 1s |
| Unpack workspace | — | 1s |
| **Total artifact round-trip** | **~800s** | **14s** |

- `Upload workspace` step alone: **~99.6% reduction (~267× faster)**.
- Full pack/upload/download/unpack pipeline vs the prior single upload:
**~98% reduction (~57× faster)**.

The 800s baseline is from a cancelled run, so both numbers are
conservative.

## Test plan

- [x] Dispatch `release / pre` against this branch with `dry_run=true`
- [x] Confirm `Upload workspace` completes in seconds instead of 10+ min
- [x] Confirm publish job `Unpack workspace` restores the tree and `pnpm
install` succeeds
- [x] Confirm dry-run publish step exits clean (no missing files from
the tarball round-trip)

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-06-22 11:50:43 -05:00
Tyler Slaton f4a5883bb9 docs(cookbook): add Angular + Google ADK production recipe (#5597)
## What

A new Cookbook recipe — **Build an agentic app on Angular + Google ADK**
— covering the non-obvious production gotchas when you wire an Angular
frontend to a Google ADK agent over AG-UI, with optional CopilotKit
Intelligence threads and memory. Written in the existing cookbook house
style (symptom → cause → fix callouts), and it links out to the Angular
and ADK quickstarts rather than re-teaching setup.

## Why

The Angular + ADK combination has a handful of correctness issues that
only surface in a real, multi-user, governed app, and they aren't
covered by the per-piece quickstarts:

- One agent, one store (a second composer must not create its own store)
- Scope the user via the **run body**, not an HTTP header (a header lags
by one in-session switch)
- Never reconfigure the runtime mid-submit (it recreates the agent store
and drops the message)
- Governance is server-side; the per-request allow-list rides the run
body
- Choose a capable model, and degrade gracefully when the Intelligence
platform is absent

The recipe is **model-flexible**: it frames ADK as running Gemini by
default but supporting any model ADK supports, consistent with the ADK
quickstart.

## Changes

- **New** `cookbook/angular-adk-agentic-app.mdx` — the recipe
- `cookbook/meta.json` — register in nav
- `cookbook/index.mdx` — add the index card (uses
`/logos/google-adk.svg`)
- `src/lib/sidebar-icon.tsx` — add `custom/google-adk` sidebar icon
entry
- `frontends/angular.mdx` — bidirectional cross-link into the recipe
- `src/lib/__tests__/docs-render.test.ts` — update the cookbook nav test
for the new page

## Test plan

Run from `showcase/shell-docs`:

- `npm run typecheck` — passes
- `npm run lint` — passes (only pre-existing warnings; none in changed
files)
- `npm run test` — the cookbook-nav test passes. Two
`public-assets.test.ts` cases fail **only locally** because git-LFS PNGs
are unmaterialized in a fresh worktree (the tests assert assets are not
LFS pointer stubs); they are unrelated to this change and pass in CI.
- `npm run build` — passes; all 211 static pages generate, including
`/cookbook` and `/cookbook/[...slug]`.

Verified in the browser at `localhost:3003`: recipe renders with correct
callout styling, code highlighting, populated TOC, sidebar entry, and
index card.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<img width="1026" height="586" alt="image"
src="https://github.com/user-attachments/assets/4c8d61ef-d74b-40fa-9e54-807750daed24"
/>
2026-06-22 09:16:50 -07:00
Ran Shem Tov b70de40632 fix(showcase): bump new-integration guard pins for merged main (calculator 20, shadow ceiling 137) 2026-06-22 16:33:40 +02:00
Ran Shem Tov 8768c8a7e7 Merge remote-tracking branch 'origin/main' into claude/trusting-babbage-f4d48a 2026-06-22 16:11:21 +02:00
Ran Shem Tov fdf588cfbf fix(showcase): green CI for the strands-typescript addition
Two PR checks were red on the new integration:

- check-config-files: add strands-typescript/next.config.ts to the build-
  config allowlist.
- Validate Showcase: update the new-integration guard pins that intentionally
  trip when an integration is added — BORN_IN_SHOWCASE 6→7, calculator
  _from-feature-parity count 18→19, catalog cross-join 874→920 / total_cells
  855→900 / docs_only 19→20 (46 features × 20 integrations), and the aimock
  substring-shadow ceiling 132→133 (+1 from the strands-typescript calculator
  fixture).

Also drop the premature deploy wiring: strands-typescript is removed from
showcase_build.yml (matrix + path filter + ALL_SERVICES) because it has no
Railway service yet (deployed: false) and the railway-envs SSOT test requires
a real service entry. It re-enters the deploy pipeline when the Railway
service is provisioned (external setup per INTEGRATION-CHECKLIST).
2026-06-22 15:36:28 +02:00
Ran Shem Tov 851dc1e90d feat(showcase): strands-typescript parity with strands-python (A2UI, aimock fixtures, header forwarding)
Bring the TypeScript AWS Strands integration to parity with the Python
strands sibling now that the @ag-ui/aws-strands TS adapter is confirmed to
support the same feature surface (per its examples/server):

- Restore A2UI: the declarative-gen-ui + a2ui-fixed-schema demos, their
  routes, qa, specs, the @copilotkit/a2ui-renderer dep, beautiful-chat's
  A2UI catalog, and the manifest entries (generative_ui / features / demos /
  a2ui_pattern). manifest now matches strands-python feature-for-feature.
- Header forwarding: attach `x-aimock-context: strands-typescript` as a
  static defaultHeader on the OpenAI client (model-factory + sub-agent
  client) — the TS analog of the Python integration's _header_forwarding
  shim — so aimock matches this integration's fixtures.
- aimock fixtures: add d6/strands-typescript + d4/strands-typescript
  (ported from the Python sibling, context retargeted).
- playwright.config: X-AIMock-Context → strands-typescript.

Note: the raw tests/e2e Playwright suite is flaky and not a CI merge gate
(demo e2e / `/eval` D5 are comment-triggered, not required) — it fails the
same specs for strands-python too. The auto-gates (build, validate-
constraints, oxlint/oxfmt, unit) are green.
2026-06-22 14:36:04 +02:00
Ran Shem Tov 15005794a5 feat(a2ui): passing a catalog to the provider auto-enables A2UI and tool injection
A catalog on <CopilotKit a2ui={{ catalog }}> is now enough to use A2UI
end to end. Previously developers also had to set a2ui.injectA2UITool: true
on the runtime.

The provider forwards an a2uiCatalogAvailable signal per run whenever it has
a catalog (and renders surfaces locally). handle-run reads that signal and
hands it to configureAgentForRequest, which enables A2UIMiddleware and defaults
injectA2UITool to true. An explicit injectA2UITool value (including false) and
an explicit a2ui.enabled: false are always respected via ?? / short-circuit, so
this only fills the default and never overrides a deeper opt-out.
2026-06-22 14:04:36 +02:00
Ran Shemtov 11e0760af1 fix(a2ui): declare ag-ui state channel + a2ui_params host override (py + sdk-js) (#5582) 2026-06-22 13:16:24 +02:00
Alem Tuzlak b2c28a046c Merge branch 'main' into feat/bot-whatsapp 2026-06-22 11:12:54 +02:00
Ran Shemtov 2d8f276bbe Merge branch 'main' into fix/1980-a2ui-middleware-state-channel 2026-06-22 10:29:56 +02:00
Jordan Ritter 4d3e0db8fa fix(cvdiag): backend emitters authenticate as PB writer-role so events actually persist (#5604)
## What

Fixes a production defect in the cvdiag observability subsystem (#5591):
**backend emitters never persisted to PocketBase.** The `cvdiag_events`
createRule requires an authenticated `cvdiag_api_keys` record with
`role="writer"`, but:
- The **Python** writer sent a custom `X-Cvdiag-Writer-Key` header and
never authenticated → every CREATE 403'd and was silently dropped by the
never-throw daemon.
- The **TS** backends had a *type-only* PB-writer seam — the concrete
writer lived in `harness/` and was never bundled into the deployed
Next.js runtime → `pbWriter` undefined → flush was a no-op.

So backend boundaries (`request.ingress`, `llm.call.*`, `sse.*`,
`error.caught`) emitted to stdout but never reached the DB. (The
probe/harness side already persists — it auths as superuser.)

**Why #5591's CR didn't catch it:** the M2 persistence tests
authenticated as **superuser**, which the migration itself notes
bypasses *all* collection rules — so the real writer-role auth path was
never exercised.

## Fix
- **Python** (`cvdiag_pb_writer.py`): `auth-with-password` against
`cvdiag_api_keys` (identity `cvdiag-writer@keys.local`, password =
`CVDIAG_WRITER_KEY`) → cache Bearer token → `Authorization: Bearer` on
CREATE; re-auth on token expiry; auth failure degrades to no-op
(never-throw). Identity overridable via `CVDIAG_WRITER_IDENTITY`.
- **TS** (`harness/src/cvdiag/pb-writer-fetch.ts`, staged into the 4
integrations): a plain-`fetch` writer-role writer (no SDK, bundles
cleanly in Next), injected by `withCvdiagBackend` only when
`CVDIAG_PB_URL` is set.

The writer credential already exists — the migration seeds the `writer`
record — so no provisioning needed.

## Verification (against a LIVE PocketBase, authenticating as the writer
role — not superuser)
- Python: live-PB writer-role test — header-only → **0 rows**; after fix
→ **row persists**; wrong password → **0 rows, daemon alive**. `_shared`
pytest 16/16.
- TS: live-PB writer-role tests — 0 rows → rows persist; stale-token
re-auth lands; wrong-key/no-url no-op. harness cvdiag vitest 255/255.
Real Docker `next build` of built-in-agent succeeds (writer bundles).
- `cvdiag-stage-ts --check` in-sync.

## Follow-up (not in this PR)
Java/.NET backends have the same auth gap; they're not the flap-heavy
integrations and will be fixed before enabling their columns.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-06-21 13:00:31 -07:00
Jordan Ritter 154ffb969c style(cvdiag): oxfmt the new writer-auth TS files + re-stage (preempt auto-format bot) 2026-06-21 12:52:44 -07:00
Jordan Ritter e0cb30e7b9 fix(cvdiag): narrow PB binary to concrete str in live-PB test fixture to satisfy Pyright reportArgumentType 2026-06-21 12:50:59 -07:00
Jordan Ritter 2efc99fa5b fix(cvdiag): bundle a concrete writer-role PB writer into TS integration backends (auth-with-password→Bearer fetch) so backend events persist; was a type-only no-op seam 2026-06-21 12:49:05 -07:00
Jordan Ritter aeb94b95b2 fix(cvdiag): Python PB writer authenticates as cvdiag_api_keys writer role (auth-with-password→Bearer) instead of inert X-Cvdiag-Writer-Key header — backend events now persist 2026-06-21 12:49:01 -07:00
Jeel Gor f2e69a80b7 fix(build): replace Unix-only commands in package.json scripts with Node.js equivalents 2026-06-21 21:33:51 +05:30
David McKay d351b0dfa1 docs(cookbook): use the official Google ADK logo (PNG via LFS)
Replace the placeholder logo with the official Agent Development Kit mark
from google/adk-python (assets/agent-development-kit.png), committed as an
LFS PNG like the other recipe logos (Daytona, Arcade). Point the card and
sidebar at /logos/google-adk.png and revert the unused google-adk.svg back
to its original state.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 19:31:29 -05:00
David McKay fc5c5b244f docs(cookbook): use the real ADK mark for the recipe logo
public/logos/google-adk.svg was a placeholder (a grey tile with the text
"Go"), like the other letter-stub SVGs in that directory. Replace it with
the real ADK glyph, reusing the vector paths from the `AdkIcon` component
(src/components/icons/framework-icons.tsx) on a light tile so it renders
on both light and dark surfaces. Only the new cookbook recipe references
this file, so no other page is affected. Monochrome for now; design can
recolor to official ADK colors at approval.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 19:27:54 -05:00
David McKay 1676e2b725 docs(cookbook): fix ADK user-scoping to use context/state, not forwardedProps
The ADK adapter (ag_ui_adk) builds session state from `dict(input.state)`
plus `input.context` (under `_ag_ui_context`); it does not mirror
`forwarded_props` into session state (it only reads it for the
`injectA2UITool` flag). So a user id sent via CopilotKit `properties`
(-> forwardedProps) never reaches `tool_context.state`, and the documented
scoping silently failed — the exact bug class the section warns about.

Carry the user id as agent context via `connectAgentContext` (or shared
agent state) instead, and read it from `tool_context.state["_ag_ui_context"]`
(or directly from state). Reconcile the contradictory forwardedProps/state
lines and fix the coding-agent prompt to match.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 18:05:54 -05:00
David McKay 47ffd32976 docs(cookbook): add Angular + Google ADK production recipe
Add a cookbook recipe covering the non-obvious production gotchas when
wiring an Angular frontend to a Google ADK agent over AG-UI, with optional
CopilotKit Intelligence threads and memory: one agent store, run-body user
scoping (not a header), never reconfiguring the runtime mid-submit,
server-side governance, model selection, and graceful platform degradation.

- New recipe at cookbook/angular-adk-agentic-app.mdx
- Register in cookbook nav (meta.json) and add an index card
- Add a custom/google-adk sidebar icon entry
- Cross-link from frontends/angular
- Update the cookbook nav test for the new page

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-20 13:18:06 -05:00
Jordan Ritter ca12d09c36 cvdiag: permanent showcase observability subsystem (probe→backend→aimock→edge) (#5591)
## What

Adds **cvdiag** — a permanent, always-available observability subsystem
for the showcase, built to diagnose the red↔green cell flap on the
staging dashboard and to make that diagnosis a dashboard query rather
than a multi-day forensic hunt in the future.

Captures the full request path with `X-Test-Id` correlation across
**probe → backend → aimock → edge**, across every integration
(TypeScript, Python, Java/spring-ai, .NET):
- Per-language backend emitters (canonical + staged/compile-linked
mirrors), all sharing one schema (`schema.json`, closed-world
`additionalProperties:false`).
- CREATE-only writes to two new PocketBase collections: `cvdiag_events`
and `cvdiag_raw_byte_samples` (additive migrations — no existing data
touched).
- An 8-class flap classifier mapping to the observed failure signatures
(`sse-missing` / `text-unstable` / `dom-missing`).
- DEBUG-tier raw-byte capture (secret-scrubbed) and HMAC-guarded A/B
edge-interference detection.

## Why

The runId flap-fix (`cdc1e90e`, 2026-06-09) did **not** fully resolve
the flap — it was still observed 2026-06-19. cvdiag exists so the
*remaining* cause is observed live with full correlation instead of
inferred.

## Safety / enablement

- **Inert by default.** With `CVDIAG_BACKEND_EMITTER` unset the
subsystem performs zero host mutation (no logging-config changes, no
threads/tasks, no stdout) — verified by
`test_cvdiag_inert_when_disabled`. **To accumulate data, set
`CVDIAG_BACKEND_EMITTER=1` on the showcase services.**
- All per-language scrubbers match the canonical `scrubSecrets`
(sk-/base64url, Bearer, colon-less URL userinfo, size-guard) — verified
with real toolchains (vitest / mvn / dotnet).
- Merged latest `main` (only conflict: a clean `.csproj` include union).

## Verification
- harness `tsc --noEmit` ✓ · `src/cvdiag` vitest 251/251 ✓ ·
`cvdiag-stage-ts --check` in-sync ✓
- Java MessageScrubber 17/17 (mvn) ✓ · .NET CvdiagBackend 5/5 (dotnet
sdk:9.0) ✓ · Python emitters 93/93 (3.12) ✓

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-06-19 20:45:52 -07:00
Jordan Ritter 2e54c925f0 chore(ci): allowlist examples/showcases/arcade-tools/next.config.ts (landed on main un-allowlisted, was failing check-config-files on main + this PR) 2026-06-19 20:10:49 -07:00
serhiizghama 412369a8a9 test(web-inspector): cover header forwarding on owned thread store
Assert the owned store's /threads request carries core.headers and that an
onHeadersChanged update re-applies the new headers.
2026-06-20 08:28:47 +07:00
serhiizghama 17703449b8 fix(web-inspector): forward core headers on owned thread store requests
The inspector's owned thread store (created when useThreads() isn't mounted)
initialized its context with empty headers, so its /threads requests omitted
the headers configured on <CopilotKit> (e.g. X-CSRF, auth). This produced
HTTP 403 in environments that enforce CSRF/auth checks.

Source the headers from core.headers at store creation, and re-apply them via
onHeadersChanged so the owned store stays authorized when headers are updated
at runtime, mirroring how useThreads() keeps its context in sync.
2026-06-20 08:28:47 +07:00
Tyler Slaton 38b39fccfd docs: polish cookbook navigation and partner logos (#5594)
Adding logos and reworking the cookbook page.
2026-06-19 17:47:57 -07:00
github-actions[bot] 790dfd0a75 style: auto-fix formatting 2026-06-19 17:33:38 -07:00