fix: resolve UUID secret refs with host contract#192
Conversation
|
Ready for review at |
There was a problem hiding this comment.
Pull request overview
This PR updates the plugin worker to be compatible with newer Paperclip hosts that require UUID-backed secret references to be passed as structured { type: "secret_ref", secretId } objects (rather than raw UUID strings), while keeping legacy non-UUID references unchanged. It also tightens fallback behavior so the company-scoped token fallback is only used for specific “secret ref unavailable/invalid ref” host errors, and adds targeted regression tests.
Changes:
- Add a wrapper (
resolvePluginSecret) that converts UUID-shaped secret refs into structuredsecret_refobjects before callingctx.secrets.resolve. - Refine the “secret refs unavailable” error classification to include the documented invalid-secret-reference host error.
- Add regression tests for structured secret refs, scoped fallback behavior, and fail-closed resolver/provider errors.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| src/worker.ts | Adds UUID→structured secret ref conversion and narrows fallback eligibility to specific host error cases. |
| tests/plugin.spec.ts | Adds regression tests covering structured secret refs, fallback gating, and fail-closed resolver errors. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| return typeof value === 'string' && value.trim() ? value.trim() : undefined; | ||
| } | ||
|
|
||
| const SECRET_REF_UUID_PATTERN = /^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i; |
| const resolveSecret = ctx.secrets.resolve as unknown as (ref: string | HostSecretRef) => Promise<string>; | ||
| return await resolveSecret(toHostSecretRef(secretRef)); |
What changed
{ type: "secret_ref", secretId }form required by newer Paperclip hosts.Root cause
The published worker normalizes saved secret refs to UUID strings and passes those strings directly to
ctx.secrets.resolve. Newer Paperclip hosts require UUID-backed refs as structuredsecret_refobjects, so configured GitHub operations fail before the already provisioned company-scoped fallback can be considered.Impact
This restores compatibility with the current host secret-reference contract without rotating, reconnecting, or logging credentials. It does not widen fallback behavior for permission failures or arbitrary resolver errors.
Validation
The originating implementation run passed:
pnpm typecheckpnpm testpnpm buildgit diff --checkPublication recovery verified this branch is exactly one commit ahead of upstream
mainand changes onlysrc/worker.tsandtests/plugin.spec.ts(104 insertions, 9 deletions).