Commit Graph

455 Commits

Author SHA1 Message Date
BenTaylorDev a2cabd9455 chore: release monorepo v1.62.2 2026-07-02 22:23:11 +00:00
Markus Ecker 01469359a8 merge: integrate origin/main into mme/memory-core
Resolve the single conflict in packages/web-inspector/src/index.ts by keeping
both additions: this branch's CpkMemoryList memory-tab element and main's
ɵCpkThreadDetails back-compat alias (independent top-level declarations).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-02 17:26:01 +02:00
Benjamin Taylor 95345f10ef test(suggestions): cover header/credential forwarding, multi-route dispatch, 405, explicit-false; fix comments 2026-07-02 09:32:30 -05:00
Benjamin Taylor 7cfbfe4df3 fix(runtime): log suggest failures server-side, harden route exhaustiveness, prove marker round-trip 2026-07-02 09:32:29 -05:00
Benjamin Taylor f94cc45a76 fix(runtime): make stateless suggest side-effect-free and cancel on client abort
The suggest path called configureAgentForRequest, which conditionally
attaches A2UI/MCPApps/OpenGenerativeUI middleware. MCPApps setup can
incur a listTools network round-trip per suggestion under
available:"always" — contradicting the handler's side-effect-free
contract. Since suggest runs force toolChoice: copilotkitSuggest, those
middleware-injected tools are dead weight. Replace the call with only
the header forwarding it needs (extractForwardableHeaders).

Also wire request.signal to agent.abortRun() so an aborted client
request cancels the server-side provider run instead of letting it run
to completion (best-effort; the listener never throws).

Tests: assert no middleware is attached (agent.use never called),
forwarded headers land on agent.headers, and aborting the signal calls
agent.abortRun(). Runtime mock is now typed (no as any); runner spies
kept to prove the direct-run path is preserved.
2026-07-02 09:32:29 -05:00
Benjamin Taylor cb7c8be1cb test(runtime): lock in stateless /suggest no-thread-leak + cross-mode coverage 2026-07-02 09:32:29 -05:00
Benjamin Taylor e9c4eec9e2 feat(runtime): route POST /agent/:agentId/suggest to handleSuggestAgent 2026-07-02 09:32:28 -05:00
Benjamin Taylor 52e4f6823f feat(runtime): add stateless handleSuggestAgent handler 2026-07-02 09:32:28 -05:00
Benjamin Taylor 7922e31e2c feat(runtime): advertise suggestions capability on /info 2026-07-02 09:32:28 -05:00
Nathan 🔶 Tarbert dedb3183d6 Merge branch 'main' into fix/issue-5533-agentid-runtime-sync 2026-07-01 16:08:55 -04:00
Alem Tuzlak 9cb929b40d feat(runtime): opt-in supersede for concurrent same-thread runs
InMemoryAgentRunner gains an opt-in { onConcurrentRun: "throw" | "supersede" }
(default "throw", so existing consumers are unchanged). In "supersede" mode a
new run for an already-running thread aborts the prior run (agent.abortRun(),
mirroring stop()) instead of throwing "Thread already running" — so a fast
follow-up turn, or one after a dropped/aborted run, cleanly replaces the
previous one.

Superseding overlaps two runs on the module-global per-thread store, so all
four finalization sites (both resets and both historicRuns.push) are guarded on
store.currentRunId === request.input.runId and stamp the run's own id. A
superseded run therefore drops its partial events rather than resetting or
mislabeling the new run's state/history.

Used by the Intelligence-hosted (managed) Slack listener. (OSS-417)
2026-07-01 19:10:54 +02:00
tylerslaton 617e88a069 chore: release monorepo v1.62.1 2026-07-01 17:07:44 +00:00
Austin Merrick f54e99697b fix(build): replace Unix-only commands in package.json scripts with Node.js equivalents (#5602)
## What does this PR do?

This PR fixes build failures on Windows by replacing Unix-only shell
commands (`rm -rf`, `cp`, `mkdir -p`) in `package.json` scripts with
cross-platform Node.js `fs` built-in commands.

This follows the project's existing codebase pattern for cross-platform
operations, as seen in `packages/react-ui/package.json` (line 45).

### 🛠️ Changes:
- **`packages/runtime`**: Replaced `rm -rf` in `generate-graphql-schema`
with `fs.rmSync`.
- **`packages/vue`**: Replaced `cp` in `build:types` and `rm -rf` in
`clean` with `fs.cpSync` and `fs.rmSync`.
- **`packages/angular`**: Replaced `mkdir -p` and `cp` in `build:css`
with `fs.mkdirSync` and `fs.cpSync`.
- **`examples/v1/next-openai`, `next-pages-router`, `state-machine`**:
Replaced `rm -rf` clean commands with a single Node.js loop that deletes
`.turbo`, `node_modules`, `dist`, and `.next`.

All modified packages now build successfully on Windows.

## Related PRs and Issues

- Closes #5601

## Checklist

- [x] I have read the [Contribution
Guide](https://github.com/copilotkit/copilotkit/blob/master/CONTRIBUTING.md)
- [ ] If the PR changes or adds functionality, I have updated the
relevant documentation
- [x] "Allow edits by maintainers" is checked (lets us help iterate on
your PR directly — faster turnaround for everyone)
2026-07-01 09:56:00 -07:00
MikeRyanDev ca836ff920 chore: release monorepo v1.62.0 2026-07-01 15:45:54 +00:00
Alem Tuzlak a03cd7db8b test(runtime): supply bots:[] in the intelligence runtime-like factory
CopilotIntelligenceRuntimeLike.bots became required with the managed-bots
runtime work (OSS-360); the get-runtime-info test factory still omitted it,
failing check-types. Add the missing field.
2026-07-01 12:28:20 +02:00
Jordan Ritter 7d6a2b2a9a docs(runtime): correct forwardHeaders allowlist JSDoc accuracy
Empty/whitespace-only allow/deny/denyPrefixes entries are trimmed and
dropped before the allowlist-mode decision, so allow: [""] stays in
denylist mode rather than switching on exclusive allowlist mode. Also
document that allowlist mode bypasses the built-in default denylist, so
integrators must not allow-list protected/platform headers unintentionally.
2026-06-30 17:23:05 -07:00
Jordan Ritter dde79d1c89 fix(runtime): make forwardHeaders deny authoritative in allowlist mode
`shouldForwardHeader` returned early on `policy.allow` and silently ignored
the integrator's `deny`/`denyPrefixes`, so a header listed in BOTH `allow`
and `deny` still forwarded — a footgun on a security feature.

Rework the predicate so the integrator's own `deny`/`denyPrefixes` (exact,
case-insensitive, and prefix) always strip, including in allowlist mode:
`allow` selects the candidate set, `deny` subtracts from it. The built-in
default denylist is unchanged and still applies only in denylist mode (an
explicit `allow` is a deliberate opt-in), so only the integrator's OWN deny
subtracts from an allowlist.

Also harden `resolveForwardHeadersPolicy`: trim and drop empty/whitespace-only
entries from `deny`/`denyPrefixes`/`allow`. A stray `denyPrefixes:[""]` made
`startsWith("")` true for every header (silently denying ALL forwarding), and
`allow:[""]`/`allow:[" "]` seeded the exclusive allowlist with an entry that
could never match — both integrator typos that now can't silently break
forwarding. Entries are lowercased consistently with existing handling.
2026-06-30 17:12:55 -07:00
Jordan Ritter cf951e04f2 test(runtime): harden header-forwarding coverage — clone isolation, case-collision, allowlist boundary
- agent-utils: assert configureAgentForRequest does not mutate the shared
  registered agent; only the per-request clone carries merged inbound headers
  (guards against a cross-request bearer-token leak, #5712).
- header-utils: direct mergeForwardableHeaders unit test for server Authorization
  vs inbound lowercase authorization with a different value — exactly one
  authorization-family key survives carrying the server value (#5712).
- header-utils: shouldForwardHeader boundary tests for the bare 'x' name and the
  empty-string name under both denylist and allowlist policies.
2026-06-30 16:58:11 -07:00
Jordan Ritter 4cdc1e16f5 fix(runtime): make forwardHeadersPolicy optional on CopilotRuntimeLike
The published CopilotRuntimeLike interface (v2 export surface) added
forwardHeadersPolicy as a REQUIRED field, which breaks any external
implementor of the interface — inconsistent with the minor-release
classification. The /run (agent-utils) and /connect (sse/connect) read
sites dereferenced runtime.forwardHeadersPolicy with no coalesce, so a
policy-less object crashed with "Cannot read properties of undefined
(reading 'allow')".

Make the field optional on the interface and coalesce both read sites to
the default resolved policy (resolveForwardHeadersPolicy(undefined),
default-on denylist) when absent. Concrete runtimes (BaseCopilotRuntime)
still always resolve and set it, so behavior is identical for all real
runtimes; the interface is now non-breaking and crash-proof.

Adds a red-green test driving configureAgentForRequest with a runtime
whose forwardHeadersPolicy is undefined: asserts no throw and that the
default denylist applies (x-forwarded-for dropped, custom x-* and
authorization forwarded).
2026-06-30 16:58:06 -07:00
Jordan Ritter 62ed6fa045 test(runtime): cover header-forwarding denylist + config policy on both paths (#5712)
- header-utils.test.ts: new coverage for the default denylist (exact names +
  prefix families, case-insensitive), custom x-* still forwarding, config
  overrides (useDefaultDenylist:false, deny, denyPrefixes, allow allowlist mode),
  and the breadth/precedence interaction. Migrate the inverting assertions
  (x-request-id / X-Forwarded-For now stripped; extract result drops x-request-id)
  and add the new required policy arg to all call sites.
- agent-utils-header-forwarding.test.ts + sse-connect-agent-id.test.ts: /run and
  /connect integration coverage — denylisted infra/platform headers dropped,
  custom x-* + authorization still forward, and a runtime-supplied forwardHeaders
  policy is actually applied (plumb-through). Swap denylisted filler headers for
  non-denylisted custom headers in the precedence regression tests.
- handle-run / handle-connect / intelligence-run-telemetry / get-runtime-info:
  add the resolved forwardHeadersPolicy to mock runtimes that route through the
  header merge so they satisfy the now-required policy.
2026-06-30 16:40:51 -07:00
Jordan Ritter 462fa7ad58 feat(runtime): configurable inbound-header forwarding policy with default infra/platform denylist
Tighten which inbound HTTP headers the v2 runtime forwards onto the outgoing
agent call. The old `authorization` + `x-*` allowlist leaked infrastructure,
proxy, and platform headers (x-forwarded-*, x-real-ip, x-amzn-trace-id,
x-vercel-*, and the Copilot Cloud platform key x-copilotcloud-public-api-key)
to arbitrary configured agent URLs (#5712, breadth half).

- header-utils.ts: add DEFAULT_DENY_HEADER_NAMES + DEFAULT_DENY_HEADER_PREFIXES
  constants and a policy-aware shouldForwardHeader; thread ResolvedForwardHeadersPolicy
  through extractForwardableHeaders and mergeForwardableHeaders. Add the public
  ForwardHeadersConfig and resolveForwardHeadersPolicy (useDefaultDenylist defaults
  to true; deny/denyPrefixes extend the default; allow switches to allowlist mode).
  Server-wins precedence and server-self case-dedup are unchanged.
- runtime.ts: add forwardHeaders?: ForwardHeadersConfig to BaseCopilotRuntimeOptions,
  resolve it once in the constructor into forwardHeadersPolicy (mirroring the
  debug -> ResolvedDebugConfig resolve-once), expose it on CopilotRuntimeLike /
  BaseCopilotRuntime, and add a passthrough getter on the CopilotRuntime shim.
- Apply the resolved policy at both call sites: /run (configureAgentForRequest)
  and /connect (handleSseConnect), so the two paths can never diverge.

Default-on in a minor with { useDefaultDenylist: false } as the documented opt-out.
2026-06-30 16:40:27 -07:00
Jordan Ritter 636bcad058 fix(runtime): de-duplicate server-vs-server case-collision headers in mergeForwardableHeaders
When an agent is configured with both case-variants of the same header
in agent.headers (e.g. Authorization and authorization), the prior
{ ...base } spread kept both keys — the exact undici comma-join hazard
the function guards against for inbound collisions. Collapse server-self
case-collisions to a single first-occurrence-wins entry; server-wins-over
-inbound and case-insensitive inbound suppression are unchanged.
2026-06-30 15:00:16 -07:00
Jordan Ritter 8bdb3a1c3f test(runtime): cover header precedence — /run + /connect collision, x-* uniqueness, agent-undefined forwarding
Cover the #5712 header-precedence behavior across both paths:

- agent-header-precedence.test.ts: server-configured agent.headers win
  over forwarded inbound headers on collision (case-insensitive), with
  single-key uniqueness assertions for both authorization and the x-*
  family (exactly one surviving key carrying the SERVER value).
- agent-utils-header-forwarding.test.ts: the /run path merges via
  mergeForwardableHeaders so server values are authoritative and inbound
  headers fill only unset keys.
- sse/__tests__/sse-connect-agent-id.test.ts: the /connect path applies
  the same merge, plus the agent-undefined case (no server agent.headers)
  degrades to forwarding allowlisted inbound headers only and does not
  crash.
2026-06-30 14:39:51 -07:00
Jordan Ritter abb85c727d refactor(runtime): thread merged headers into runner.connect() as forward-looking plumbing
The /connect path now builds the same server-wins merged headers as the
/run path and passes them into runner.connect(). This does NOT fix
connect-path auth: no shipped runner consumes the headers field of
AgentRunnerConnectRequest today. The in-memory, intelligence, telemetry,
and sqlite runners all read only threadId from the connect request and
ignore headers entirely. The real outbound header forwarding lives on the
/run path, where agent.headers is mutated before the agent runs.

Passing merged headers here is the correct argument shape for a future
outbound-connecting runner, and keeps the connect path's merge semantics
consistent with /run. The comments and JSDoc are rewritten to state this
plainly rather than implying an active auth fix: the connect-site
cloneAgentForRequest call is documented as the sole agentId-existence
guard (the intelligence branch never re-validates the id), and
cloneAgentForRequest's AbstractAgent | Response (404) dual-return contract
that both callers depend on is now documented.
2026-06-30 14:39:38 -07:00
Jordan Ritter bc5e56a295 fix(runtime): server-configured agent headers take precedence over forwarded inbound headers
When a request hits the /run path, inbound headers are forwarded to the
agent. Previously, forwarded inbound headers could clobber the
server-configured agent.headers on a key collision, letting a client
override server-set values (e.g. authorization). This is the #5712 bug.

Introduce mergeForwardableHeaders (header-utils.ts): a case-insensitive
merge where server-configured agent.headers always win on collision,
regardless of header-name casing. agent-utils.ts now uses this helper on
the /run path so server-configured values are authoritative and inbound
headers only fill keys the server did not set.

Fixes #5712
2026-06-30 14:39:21 -07:00
Nathan 🔶 Tarbert e55c958393 Merge remote-tracking branch 'origin/main' into fix/issue-5533-agentid-runtime-sync 2026-06-30 16:33:10 -04:00
Markus Ecker 95ed596d3a fix(memory): tighten mutation-response and runtime boundary validation 2026-06-30 15:58:35 +02:00
Markus Ecker 8a7ac74e94 fix(runtime): validate sourceThreadIds elements are strings in memory body 2026-06-30 15:14:20 +02:00
Markus Ecker bb117b1ef7 Merge remote-tracking branch 'origin/main' into mme/memory-core
# Conflicts:
#	packages/core/src/index.ts
2026-06-29 13:37:52 +02:00
Alem Tuzlak c55aa134be docs(runtime): clarify managed bots are validated at activation, not construction 2026-06-29 12:05:34 +02:00
Alem Tuzlak 9046b241e6 feat(runtime): typed managed-bots option on the Intelligence runtime (OSS-360)
Expose new CopilotRuntime({ intelligence, bots }) -- the Mode B entry point
for managed bots:

- bots is accepted only on the Intelligence runtime variant (bots?: undefined
  on the SSE variant), so TypeScript rejects bots without intelligence
- CopilotIntelligenceRuntime stores the declared bots; the facade exposes them
  via the existing isIntelligenceRuntime getter pattern
- @copilotkit/bot is imported type-only (it is pure-ESM; a value import would
  break this package's CJS output). Name validation + transport wiring happen
  in startManagedBots (called by the managed-listener bootstrap), not here.

Adds a type-only @copilotkit/bot workspace dependency.
2026-06-29 11:50:41 +02:00
Jeel Gor 9632ca901c Merge branch 'main' into fix/5601-windows-cross-platform-scripts 2026-06-27 15:48:22 +05:30
Markus Ecker cd0739800e fix(runtime): identify memory-subscribe user via header, not body
ɵsubscribeToMemories mirrored ɵsubscribeToThreads and sent userId in the
body, but the platform's memory routes resolve the app user from the
x-cpki-user-id header (like listMemories/createMemory), not the body — so
POST /api/memories/subscribe returned 401 AUTH_UNAUTHENTICATED. Send the
user via the header instead; the body is now empty.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-25 21:33:00 +02:00
Markus Ecker 4f50068244 fix(runtime): add missing /memories/subscribe route + handler
The memory store client POSTs /memories/subscribe to mint realtime join
credentials, but the runtime router had no such route — the path fell
through to /memories/:id (memories/mutate), so a POST returned 405 Method
Not Allowed. Threads had the full chain (route → handleSubscribeToThreads →
platform); memory was missing the runtime proxy between the client and the
platform's POST /api/memories/subscribe.

Add `memories/subscribe` to the route union, match it before /memories/:id
(and exclude "subscribe" from the :id rule, mirroring threads), add
handleSubscribeToMemories returning { joinToken, joinCode } (memory delivers
the join code here, unlike threads where it rides the thread-list response),
and ɵsubscribeToMemories on the platform client.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-25 21:17:37 +02:00
Markus Ecker 4211bd58d8 chore: format memory SDK files with oxfmt 2026-06-25 19:49:34 +02:00
Markus Ecker 86f08d2ce3 fix(runtime): forward platform error status for memory ops; make scope optional
Memory handlers now forward client-actionable 4xx platform statuses
verbatim (404 not-found, 409 conflict, 422 unprocessable) so a useMemories
consumer can distinguish those from a server error, and map a platform 5xx
(or malformed status) to 502 rather than collapsing everything to 500 — the
runtime is healthy, its dependency failed. This also avoids a Response
RangeError on an out-of-range status.

parseMemoryBody and the platform client's createMemory/updateMemory now
treat scope as optional, deferring the default to the platform.
2026-06-25 14:20:53 +02:00
Markus Ecker e5a93b8f92 feat(runtime): memory write endpoints (create/supersede/retire)
Adds POST /memories (create), PATCH /memories/:id (supersede), and
DELETE /memories/:id (retire) to the intelligence runtime, mirroring the GET
read route: CopilotKitIntelligence.{createMemory,updateMemory,removeMemory}
proxy the platform's /api/memories with the identifyUser-resolved user via the
x-cpki-user-id header. Completes the REST surface the client memory store's
addMemory/updateMemory/removeMemory call.
2026-06-25 13:08:05 +02:00
Markus Ecker 403bc73455 fix(runtime): allow GET for the memories/list route
memories/list fell through to the POST-only default in validateHttpMethod,
so GET /memories returned 405. Add it to the GET-allowed group alongside
threads/list.
2026-06-25 11:54:34 +02:00
Markus Ecker 454a2591f3 feat(runtime): serve GET /memories from the intelligence runtime
Adds a runtime-native memory read endpoint mirroring /threads: route
(memories/list) → handleListMemories → CopilotKitIntelligence.listMemories,
which proxies the platform's GET /api/memories with the project API key and
the user resolved via identifyUser (scoped through the x-cpki-user-id header,
never a client-supplied id). The client memory store's {runtimeUrl}/memories
fetch now resolves out of the box for any intelligence runtime — no per-app
BFF code. Read-only for now (list); mutations to follow.
2026-06-25 11:23:46 +02:00
ranst91 bb69f55c98 chore: release monorepo v1.61.2 2026-06-25 07:54:33 +00:00
Nathan 🔶 Tarbert fdbfac26f8 Merge remote-tracking branch 'origin/main' into fix/issue-5533-agentid-runtime-sync
# Conflicts:
#	packages/react-core/src/v2/hooks/use-agent.tsx
2026-06-24 16:46:18 -04:00
Markus Ecker eb65784765 chore(runtime): revert string-constraint preservation in tool conversion
Reverts 2cad274. The real fix for models filling optional tool params is to
use OpenAI's Chat Completions API (the Responses API fills every declared
optional); preserving format/pattern in convertJsonSchemaToZodSchema was
unnecessary (OpenAI ignores format) and broadened behavior for every tool.
2026-06-24 20:27:36 +02:00
Markus Ecker 2cad274c93 fix(runtime): preserve JSON-schema string constraints in tool conversion
convertJsonSchemaToZodSchema dropped every string constraint except enum,
so a tool param like { type: "string", format: "uuid" } reached the model
as a bare optional string. Models then fill such optionals with "" instead
of omitting them, and the loosened model-side validation accepts "" — only
for a stricter downstream (e.g. an MCP server) to reject it.

Carry format (uuid/email/url/date-time), pattern, and minLength/maxLength
through to the generated Zod schema so the model sees the field's real
shape and the model-side validation matches the server's.
2026-06-24 18:29:00 +02:00
Ran Shemtov 5d31ebbfb2 Merge branch 'main' into claude/stupefied-northcutt-12d382 2026-06-24 15:29:16 +02:00
Tyler Slaton f330e9b795 fix(runtime): fail loud on malformed approval request 2026-06-23 20:56:33 -07:00
Tyler Slaton a13c3ee663 chore: merge main into PR 5480 2026-06-23 20:50:16 -07:00
Jordan Ritter ec646bbf4f Merge remote-tracking branch 'origin/main' into chore/remove-harness-legacy-ssot
# Conflicts:
#	showcase/scripts/railway-envs.generated.json
#	showcase/scripts/railway-envs.ts
2026-06-23 17:56:18 -07:00
github-actions[bot] 3284bc863f style: auto-fix formatting 2026-06-23 22:34:58 +00:00
Tyler Slaton 75611b272c chore: merge main into PR 5480 2026-06-23 15:32:09 -07:00
Austin Merrick 4ba201b5c4 fix: repair check-types across all packages and gate it in CI
Repairs TypeScript check-types across the monorepo and adds a CI gate so
regressions are caught going forward:

- core: bundler module resolution and strict-mode fixes
- sdk-js: bundler module resolution; keep codegen, formatter, packaging working
- react-core: fixes across components, hooks, and tests
- react-native: restore catch binding referenced by TypeError cause
- runtime: repair check-types and bound AI SDK schema inference
- web-inspector: nodenext import extensions, export Anchor
- remaining packages and node example: assorted check-types repairs
- deps: add missing type-only devDependencies
- license context driven from /info licenseStatus
- ci: run check-types in the static quality workflow

Squashed from 12 commits for a single, easily-revertable change.
2026-06-23 15:26:47 -07:00