Fix stale workspace resolution#1349
Conversation
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
📝 WalkthroughWalkthroughChangesWorkspace bootstrap and repair
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related issues
Possibly related PRs
Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 ESLint
ESLint install timed out. The project may have too many dependencies for the sandbox. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/cloud/src/workspaces.ts`:
- Around line 420-451: Update the join repair flow in repairActiveWorkspace and
joinWorkspaceKey so interactive and refreshTimeoutMs from
ResolveActiveWorkspaceOptions are included in the helper options and forwarded
through tryPostJson. Preserve the caller-provided values, including interactive:
false, to prevent browser-login fallback and honor the configured timeout.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 66aeb9a5-9244-47f9-b183-6b2bf0fe3e4b
📒 Files selected for processing (4)
packages/cli/src/cli/commands/workspace.test.tspackages/cli/src/cli/commands/workspace.tspackages/cloud/src/workspaces.test.tspackages/cloud/src/workspaces.ts
| async function repairActiveWorkspace( | ||
| options: ResolveActiveWorkspaceOptions | ||
| ): Promise<ActiveWorkspaceDescriptor> { | ||
| const apiUrl = options.apiUrl || defaultApiUrl(); | ||
| const auth = await ensureAuthenticated(apiUrl, { | ||
| interactive: options.interactive ?? false, | ||
| refreshTimeoutMs: options.refreshTimeoutMs, | ||
| }); | ||
| const { response } = await authorizedApiFetch( | ||
| auth, | ||
| '/api/v1/auth/whoami', | ||
| { method: 'GET' }, | ||
| { | ||
| interactive: options.interactive ?? false, | ||
| refreshTimeoutMs: options.refreshTimeoutMs, | ||
| } | ||
| ); | ||
| const payload = (await readJson(response)) as (WhoAmIResponse & { error?: string }) | null; | ||
| if (!response.ok || !payload?.authenticated || !payload.currentWorkspace?.id) { | ||
| const detail = payload?.error ?? (response.statusText || 'Failed to resolve auth status'); | ||
| throw new Error(`Active workspace repair failed: ${response.status} ${detail}`.trim()); | ||
| } | ||
|
|
||
| const workspaceName = payload.currentWorkspace.name?.trim() || payload.currentWorkspace.id; | ||
| const workspaceKey = await joinWorkspaceKey(payload.currentWorkspace.id, 'agent-relay-cli', { | ||
| apiUrl: auth.apiUrl, | ||
| }); | ||
| setWorkspaceKey(workspaceName, workspaceKey, options.env); | ||
| setActiveWorkspace(workspaceName, options.env); | ||
|
|
||
| return resolveWorkspaceKey(workspaceKey, options); | ||
| } |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Description: Inspect WorkspaceClientOptions / tryPostJson / tryGetJson to confirm default
# `interactive` behavior when the field is omitted.
rg -n -B2 -A 20 'type WorkspaceClientOptions|async function tryPostJson|async function tryGetJson' packages/cloud/src/workspaces.tsRepository: AgentWorkforce/relay
Length of output: 2175
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Inspect joinWorkspaceKey and its callers for option threading and defaults.
ast-grep outline packages/cloud/src/workspaces.ts --view expanded
printf '\n--- joinWorkspaceKey references ---\n'
rg -n -A 20 -B 10 'joinWorkspaceKey\(' packages/cloud/src/workspaces.ts
printf '\n--- active workspace callers ---\n'
rg -n -A 6 -B 6 'repairActiveWorkspace|resolveWorkspaceKey\(' packages/cloud/src/workspaces.tsRepository: AgentWorkforce/relay
Length of output: 7544
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Inspect ensureAuthenticated defaults and whether joinWorkspaceKey uses the same auth path.
rg -n -A 25 -B 10 'async function ensureAuthenticated|function ensureAuthenticated|joinWorkspaceKey\(' packages/cloud/srcRepository: AgentWorkforce/relay
Length of output: 10465
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Read the joinWorkspaceKey definition and the nearby auth helpers.
ast-grep outline packages/cloud/src/workspaces.ts --view expanded | sed -n '1,220p'
printf '\n--- definition excerpt ---\n'
sed -n '300,470p' packages/cloud/src/workspaces.ts | cat -nRepository: AgentWorkforce/relay
Length of output: 8556
Thread interactive/refreshTimeoutMs through the join repair path. repairActiveWorkspace() passes interactive: false, but joinWorkspaceKey() → tryPostJson() drops both auth flags, so this can still fall back to browser login and ignore the caller timeout. Update the helper options and forward them here.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/cloud/src/workspaces.ts` around lines 420 - 451, Update the join
repair flow in repairActiveWorkspace and joinWorkspaceKey so interactive and
refreshTimeoutMs from ResolveActiveWorkspaceOptions are included in the helper
options and forwarded through tryPostJson. Preserve the caller-provided values,
including interactive: false, to prevent browser-login fallback and honor the
configured timeout.
What changed
agent-relay workspace activeRoot cause
Cloud authentication and local workspace selection are separate state. A valid
agent-relay cloud logincould coexist with a global active alias that referenced a deleted workspace.workspace activetrusted only that stale alias, so every resolve endpoint returned 404 even thoughcloud whoamireported a valid current workspace. Current Cloud deployments expose canonical workspace recovery through the authenticated/joincontract, while the dedicated token issue compatibility routes can be absent.User impact
agent-relay workspace activenow repairs stale or missing local workspace state from the user's authenticated Cloud workspace. SDK consumers also recover stale keys, while callers that require an explicitly configured key still fail closed when the store is empty.Validation
npm run typecheck0600permissions