feat(FN-2987): merge fusion/fn-2987

- **Archived task read-only enforcement** — `packages/core/src/store.ts` adds guards that prevent log entries and documents from being written to archived tasks; `packages/engine/src/agent-tools.ts` surfaces meaningful errors instead of silent failures when tools are called on archived tasks
- **Type safety for archived guards** — resolved typecheck issues around the archived-task write guards in core
- **Tests for archived behavior** — added regression coverage in `packages/core/src/__tests__/store.test.ts` and `packages/core/src/__tests__/task-documents.test.ts`; also added `packages/engine/src/__tests__/agent-tools.test.ts` to cover archived-task error paths
- **Documentation** — updated `docs/task-management.md` to document the archived read-only behavior
- **Also merged** `fusion/fn-2959-2` (CustomProviderForm component, SettingsModal routing, custom provider API routes, and associated tests)

Commits merged:
- feat(FN-2987): complete Step 6 — document archived read-only behavior
- fix(FN-2987): complete Step 5 — resolve typecheck for archived guards
- test(FN-2987): complete Step 4 — add archived-task regression coverage
- feat(FN-2987): complete Step 3 — handle archived log tool errors
- feat(FN-2987): complete Step 2 — enforce archived document write guard
- feat(FN-2987): complete Step 1 — harden archived logEntry checks
- feat(FN-2959): merge fusion/fn-2959-2

Files changed:
.changeset/custom-openai-anthropic-providers.md    |   5 +
 docs/task-management.md                            |   4 +
 packages/core/src/__tests__/store.test.ts          |  38 +++
 packages/core/src/__tests__/task-documents.test.ts |  32 +++
 packages/core/src/store.ts                         |  34 ++-
 packages/dashboard/app/api/legacy.ts               |  41 ++++
 .../app/components/CustomProviderForm.css          |  45 ++++
 .../app/components/CustomProviderForm.tsx          | 203 ++++++++++++++++
 .../app/components/ModelOnboardingModal.css        |  14 ++
 .../app/components/ModelOnboardingModal.tsx        |  62 ++++-
 .../dashboard/app/components/SettingsModal.css     |  38 +++
 .../dashboard/app/components/SettingsModal.tsx     |  91 +++++++-
 .../__tests__/CustomProviderForm.test.tsx          |  60 +++++
 .../__tests__/ModelOnboardingModal.test.tsx        |  23 ++
 .../components/__tests__/SettingsModal.test.tsx    |  13 ++
 .../__tests__/SettingsModalNodeRouting.test.tsx    |   4 +
 .../components/__tests__/settings-mobile.test.tsx  |   4 +
 packages/dashboard/src/auth-paths.ts               |   4 +
 packages/dashboard/src/routes.ts                   |   2 +
 .../__tests__/custom-provider-routes.test.ts       | 118 ++++++++++
 .../src/routes/register-custom-provider-routes.ts  | 254 +++++++++++++++++++++
 .../src/__tests__/agent-document-tools.test.ts     |  15 ++
 packages/engine/src/__tests__/agent-tools.test.ts  |  43 ++++
 packages/engine/src/agent-tools.ts                 |  28 ++-
 24 files changed, 1166 insertions(+), 9 deletions(-)

Fusion-Task-Id: FN-2987
This commit is contained in:
Fusion
2026-04-29 20:16:45 -07:00
committed by gsxdsm
parent 19cdf7f448
commit 3c37f8d4bb
7 changed files with 189 additions and 5 deletions

View File

@@ -1152,6 +1152,15 @@ export class TaskStore extends EventEmitter<TaskStoreEvents> {
return this.rowToTask(row);
}
private isTaskArchived(id: string): boolean {
const row = this.db.prepare('SELECT "column" FROM tasks WHERE id = ?').get(id) as { column: Column } | undefined;
if (row) {
return row.column === "archived";
}
return this.archiveDb.get(id) !== undefined;
}
/**
* Return the ids of live tasks whose `dependencies` array contains `id`.
*
@@ -3166,6 +3175,10 @@ export class TaskStore extends EventEmitter<TaskStoreEvents> {
outcome: truncateTaskLogOutcome(outcome),
};
if (runContext) {
if (this.isTaskArchived(id)) {
throw new Error(`Task ${id} is archived — logging is read-only`);
}
const dir = this.taskDir(id);
const task = await this.readTaskJson(dir);
@@ -3199,11 +3212,20 @@ export class TaskStore extends EventEmitter<TaskStoreEvents> {
// Fast path for high-volume log entries: update only the log + updatedAt fields
// instead of reading/writing the entire task payload on every append.
const row = this.db.prepare("SELECT log FROM tasks WHERE id = ?").get(id) as { log: string | null } | undefined;
const row = this.db.prepare('SELECT log, "column" FROM tasks WHERE id = ?').get(id) as
| { log: string | null; column: Column }
| undefined;
if (!row) {
if (this.isTaskArchived(id)) {
throw new Error(`Task ${id} is archived — logging is read-only`);
}
throw new Error(`Task ${id} not found`);
}
if (row.column === "archived") {
throw new Error(`Task ${id} is archived — logging is read-only`);
}
const log = fromJson<TaskLogEntry[]>(row.log) || [];
log.push(entry);
if (log.length > TASK_ACTIVITY_LOG_ENTRY_LIMIT) {
@@ -4750,10 +4772,16 @@ export class TaskStore extends EventEmitter<TaskStoreEvents> {
);
}
const taskExists = this.db.prepare("SELECT id FROM tasks WHERE id = ?").get(taskId) as
| { id: string }
const taskExists = this.db.prepare('SELECT id, "column" FROM tasks WHERE id = ?').get(taskId) as
| { id: string; column: Column }
| undefined;
if (taskExists?.column === "archived") {
throw new Error(`Task ${taskId} is archived — documents are read-only`);
}
if (!taskExists) {
if (this.isTaskArchived(taskId)) {
throw new Error(`Task ${taskId} is archived — documents are read-only`);
}
throw new Error(`Task ${taskId} not found`);
}