Repository navigation
Preserve server-bound session provenance in composed workflows - #9
Conversation
Context projection for includes discarded originSessionId even at the composed root, so an interactive action could not verify its live Pi session. Forward only the existing engine-bound identity through root and nested scopes; do not derive it from workflow input or projected state. Test bound and absent provenance in both scopes.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. 3 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour. 📜 Recent review details⏰ Context from checks skipped due to timeout. (4)
🔇 Additional comments (2)
📝 SummarySummary by CodeRabbit
WalkthroughWorkflow context projection now forwards a defined engine-bound origin session ID. Tests cover root and nested action contexts for bound and unbound engines, including input that claims a different session ID. ChangesSession provenance
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk is identified; the change appears ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Composed actions now receive an origin session ID. A headless run can also be started with a supplied ID, so it is not yet clear that actions can distinguish that value from a live, session-bound identity. No misuse by an action was established. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
Comment |
Bug
When
includeWorkflow()is present, the composition wrapper projects even root-node contexts viaprojectWorkflowContext(). That projection droppedoriginSessionId. The executing engine had a server-bound interactive Pi identity, but a root health action saw no identity; a nested action had the same defect. This breaks fail-closed session-bound integrations without making workflow input trustworthy.Fix
Preserve only the engine-supplied
context.originSessionIdin projected root/child contexts. Leave the field absent for headless/unbound runs; never derive it from workflow input or a saved context/claim. The existingeffect,signal, and settings projection are unchanged.Verification
npm run format:check,npm run lint,npm run typecheck,npm run build: pass.TMPDIR=/var/tmp,log.showSignature=false,--maxWorkers=4 --testTimeout=45000: 116 files / 1,439 tests passed. The unrestricted local run had 5 timeouts under heavy concurrent load; those 32 tests passed on bounded rerun before the full green run.This PR only fixes context projection. It does not change the engine's session trust boundary or claim that arbitrary extensions/trusted Pi code are OS-isolated.