mirror of
https://github.com/software-mansion/argent.git
synced 2026-09-14 19:27:14 +08:00
ee97c443b7
## Why The tools-server shows an update reminder (a `note` appended to every tool response) once a newer `@swmansion/argent` lands on npm. Two pain points: 1. **No way to turn it off.** Suppression is in-memory only (`dismiss-update`, 30-min auto), so it comes back on every server restart. 2. **It nags about versions you can't install yet.** Registries with a **minimum-release-age** (package-cooldown) security policy refuse to install a version until it has been public for N days. Until then the reminder repeats every day for the whole cooldown window with nothing the user can do about it — exactly the "reminded for 5+ days" situation. ## What's in this PR **1. A config option to disable the reminder** - New env var **`ARGENT_DISABLE_UPDATE_NOTIFICATIONS=1`** (`"1"` or `"true"`). - When set, `startUpdateChecker()` is a no-op: **no registry request** is made and **no note** is ever attached. - The opt-out is also surfaced inside the reminder text itself, so the agent can tell the user how to silence it permanently. **2. Minimum-release-age awareness** (answers "detect the policy and check the update is actually installable first") - The checker now fetches the **npm packument** (`registry.npmjs.org/@swmansion/argent`) instead of `/latest`, because only the packument carries the `time` map of version → publish timestamp. - It detects the machine's policy and only reminds once the latest version has **aged past** it. Notification is gated on a new **`updateInstallable`** flag (newer **and** old enough) rather than `updateAvailable`. - `updateAvailable` keeps its pure version-comparison meaning; with no policy, `updateInstallable === updateAvailable` (no behavior change for users without a policy). ### Is detecting the user's min-age policy possible? Yes — partially. Each package manager stores it differently, and the tools-server has no reliable signal for *which* PM installed argent, so we probe every PM present and take the **most restrictive** (largest) value. Erring toward over-waiting is intentional: a slightly late reminder beats nagging about a forbidden version. | PM | Config key | Unit | Detect via | Min PM version | |----|-----------|------|-----------|----------------| | npm | `min-release-age` | days | `npm config get min-release-age` | 11.10.0 | | pnpm | `minimumReleaseAge` | minutes | `pnpm config get minimumReleaseAge` | 10.16 | | yarn (berry) | `npmMinimalAgeGate` | minutes | `yarn config get npmMinimalAgeGate` | 4.10 | | bun | `minimumReleaseAge` (bunfig.toml `[install]`) | seconds | no `config get` — not auto-probed | 1.3 | | yarn classic | — (unsupported) | — | — | — | Because bun has no `config get` for this and auto-detection is best-effort, there's also an explicit override: - **`ARGENT_MIN_RELEASE_AGE_DAYS`** — positive number of days; wins outright and skips probing (useful for bun users, locked-down CI, or pinning the value). When a policy holds an update back, a single stderr line explains the silence; no reminder reaches the agent. ## Conservative edge handling - Network/registry failure → state unchanged (never crashes the server). - Policy in effect but publish time missing/unparseable → treated as **not** installable (stay silent rather than nag). - PM probe errors / PM absent → treated as no policy (0). - Probes shell out via PATH (`exec`, 3s timeout, constant commands only — no caller input) so Windows `.cmd`/`.ps1` shims resolve. ## Tests - `test/min-release-age.test.ts` (new): unit-level parsing, override precedence, unit normalization, most-restrictive-wins, PM-absent. - `test/update-checker.test.ts`: rewritten for the packument shape; new cases for held-by-policy, aged-past-policy, unknown publish time, and the disable flag (probe mocked so tests never spawn a real PM). - `test/http-update-note.test.ts`: gate now keys off `updateInstallable`; added a "available but held by policy → no note" case. - Full tool-server suite green (**732 tests**), `tsc --noEmit` and `typecheck:tests` clean. ## Follow-up (not in this PR) The env-var reference lives in the `argent-private` submodule (`docs/environment-variables.md`), which is a separate repo — needs a companion PR. Suggested rows for the tools-server table: ``` | `ARGENT_DISABLE_UPDATE_NOTIFICATIONS` | `"1"`/`"true"` or unset | disabled | When truthy, disables the update reminder entirely (no registry check, no note). | | `ARGENT_MIN_RELEASE_AGE_DAYS` | number | _(auto-detect)_ | Minimum age (days) a newer version must reach before it is advertised. Overrides auto-detection of the npm/pnpm/yarn minimum-release-age policy. | ``` ## Open questions for review - **Most-restrictive-across-PMs** vs. detecting a single PM — is "max wins" the behavior we want, or should it follow `npm_config_user_agent`? - Should an update held by policy stay fully silent (current), or emit a softened "available, installable in ~N days" note? --------- Co-authored-by: Cursor <cursoragent@cursor.com>
72 lines
2.4 KiB
TypeScript
72 lines
2.4 KiB
TypeScript
import { describe, it, expect } from "vitest";
|
|
import {
|
|
parseConfigValue,
|
|
parseBeforeAgeMs,
|
|
parseYarnAgeGateMs,
|
|
DAY_MS,
|
|
MINUTE_MS,
|
|
} from "../src/config-parse";
|
|
|
|
const NOW = new Date("2026-06-01T00:00:00Z").getTime();
|
|
|
|
describe("parseConfigValue", () => {
|
|
it("treats unset markers as no policy (0)", () => {
|
|
expect(parseConfigValue("undefined")).toBe(0);
|
|
expect(parseConfigValue("null")).toBe(0);
|
|
expect(parseConfigValue("")).toBe(0);
|
|
expect(parseConfigValue(" \n")).toBe(0);
|
|
});
|
|
|
|
it("parses positive numbers and ignores surrounding whitespace and quotes", () => {
|
|
expect(parseConfigValue("1440\n")).toBe(1440);
|
|
expect(parseConfigValue(" 7 ")).toBe(7);
|
|
expect(parseConfigValue('"30"')).toBe(30);
|
|
});
|
|
|
|
it("rejects non-positive and non-finite values", () => {
|
|
expect(parseConfigValue("0")).toBe(0);
|
|
expect(parseConfigValue("-5")).toBe(0);
|
|
expect(parseConfigValue("Infinity")).toBe(0);
|
|
expect(parseConfigValue("not-a-number")).toBe(0);
|
|
});
|
|
});
|
|
|
|
describe("parseBeforeAgeMs", () => {
|
|
it("treats unset markers as no policy (0)", () => {
|
|
expect(parseBeforeAgeMs("undefined", NOW)).toBe(0);
|
|
expect(parseBeforeAgeMs("null", NOW)).toBe(0);
|
|
expect(parseBeforeAgeMs("", NOW)).toBe(0);
|
|
});
|
|
|
|
it("converts npm's effective `before` date into an equivalent age", () => {
|
|
const twoDaysAgo = new Date(NOW - 2 * DAY_MS).toISOString();
|
|
expect(parseBeforeAgeMs(twoDaysAgo, NOW)).toBe(2 * DAY_MS);
|
|
});
|
|
|
|
it("parses npm's human-readable date output with a trailing timezone label", () => {
|
|
const value = "Fri Apr 03 2026 00:00:12 GMT+0200 (Central European Summer Time)";
|
|
expect(parseBeforeAgeMs(value, Date.parse("2026-04-05T00:00:12+02:00"))).toBe(2 * DAY_MS);
|
|
});
|
|
|
|
it("returns 0 for invalid or future cutoff dates", () => {
|
|
expect(parseBeforeAgeMs("not-a-date", NOW)).toBe(0);
|
|
expect(parseBeforeAgeMs("2030-01-01T00:00:00Z", NOW)).toBe(0);
|
|
});
|
|
});
|
|
|
|
describe("parseYarnAgeGateMs", () => {
|
|
it("treats a bare number as minutes", () => {
|
|
expect(parseYarnAgeGateMs("90")).toBe(90 * MINUTE_MS);
|
|
});
|
|
|
|
it("parses Yarn's quoted duration syntax with units", () => {
|
|
expect(parseYarnAgeGateMs('"1d"')).toBe(DAY_MS);
|
|
expect(parseYarnAgeGateMs("2w")).toBe(2 * 7 * DAY_MS);
|
|
});
|
|
|
|
it("returns 0 for unset or unparseable values", () => {
|
|
expect(parseYarnAgeGateMs("undefined")).toBe(0);
|
|
expect(parseYarnAgeGateMs("garbage")).toBe(0);
|
|
});
|
|
});
|