Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
eef911f
feat(control-plane): enforce session access in WebSocket DO (#2132)
ColeMurray Sep 29, 2026
671661e
feat(control-plane): filter session readers by row visibility (#2133)
ColeMurray Sep 29, 2026
a41abe0
fix: keep modal-vm sessions alive after failed Docker preparation (#2…
ColeMurray Sep 29, 2026
f3b397a
fix(modal-infra): resolve VMs with partially published tunnels (#2139)
rhlsthrm Sep 29, 2026
4e5c1f3
fix(control-plane): fail modal-vm launch on docker_not_available (#2138)
rhlsthrm Sep 29, 2026
0ce9e9d
test: establish sandbox lifecycle refactor baseline (COL-241) (#2144)
ColeMurray Sep 29, 2026
bdf314c
fix(modal-infra): restore VM saves and timed-out sandbox stops (COL-2…
ColeMurray Sep 29, 2026
7716838
feat: add GPT-6.1 Sol model support (#2147)
ajanraj Sep 29, 2026
c9a649b
fix(linear-bot): surface completion failure reasons (#2143)
ColeMurray Sep 30, 2026
44ca1a9
refactor: extract sandbox launch context (COL-242) (#2148)
ColeMurray Sep 30, 2026
0318fd9
refactor: replace sandbox launch factory with class (#2149)
open-inspect[bot] Sep 30, 2026
cf345db
feat(control-plane): manage session visibility and team scope (#2145)
ColeMurray Sep 30, 2026
9467549
fix(deps): bump PyJWT floor to >=2.14.0 (#2156)
jehiah Sep 30, 2026
6210156
fix(terraform): pass docs site variables to the Terraform workflow (#…
rhlsthrm Sep 30, 2026
2143b53
fix(terraform): pass teams enforcement to plan and apply (#2160)
ColeMurray Sep 30, 2026
8ed1aea
fix(control-plane): retry held sandbox saves from alarms (#2152)
ColeMurray Sep 30, 2026
69cad25
fix(web): improve command menu hover contrast (#2161)
ColeMurray Sep 30, 2026
d3de8c0
refactor: extract sandbox access mechanics (COL-243) (#2151)
ColeMurray Sep 30, 2026
8b1a66b
fix(control-plane): recover browser PR OAuth credentials (#2162)
ColeMurray Sep 30, 2026
3beccb0
chore(deps): bump the npm_and_yarn group across 1 directory with 2 up…
dependabot[bot] Sep 30, 2026
8b6c5fc
feat(web): add team-aware session discovery and creation (#2158)
open-inspect[bot] Sep 30, 2026
64aa395
refactor: extract VM startup reconciliation (COL-244) (#2166)
ColeMurray Sep 30, 2026
8276f63
feat(web): split session details into Changes, Info, Tasks, Tools tab…
ColeMurray Sep 30, 2026
60930ce
refactor: extract rejected allocation cleanup (COL-245) (#2170)
ColeMurray Sep 30, 2026
dd35c2f
feat(web): add team pages and session scope controls (#2164)
open-inspect[bot] Sep 30, 2026
fcea950
feat(web): open diffs in the main column beside the session sidebar (…
ColeMurray Sep 30, 2026
5be3545
test(modal-infra): validate SDK arguments with protobuf contracts (#2…
ColeMurray Sep 30, 2026
ec52d46
fix: preserve participant identity and Better Auth authority (#2165)
ColeMurray Sep 30, 2026
3b0b575
fix(web): use shared dropdowns for composer workspace controls (#2171)
ColeMurray Sep 30, 2026
19e7993
fix(web): use inline session visibility controls (#2173)
ColeMurray Oct 1, 2026
c05c6e0
fix(control-plane): quiet team reads and complete subscribe capabilit…
ColeMurray Oct 1, 2026
70b8ca4
fix(web): keep team context and scope refresh isolated (#2176)
ColeMurray Oct 1, 2026
ef4f737
fix(deps): override sharp to ^0.35.4 for libvips/libheif advisories (…
rhlsthrm Oct 1, 2026
3789205
fix: restrict directory emails and remove team activity (#2175)
ColeMurray Oct 1, 2026
eb50181
fix: require team session membership and remove ownership moves (#2184)
ColeMurray Oct 1, 2026
68e6331
chore(deps): bump hono from 4.13.5 to 4.13.12 in the npm_and_yarn gro…
dependabot[bot] Oct 1, 2026
9c2e3c8
feat(control-plane): add team-scoped secrets (#2179)
ColeMurray Oct 1, 2026
08b4513
Merge remote-tracking branch 'origin/main'
rhlsthrm Oct 1, 2026
1b44faf
test(control-plane): regenerate route snapshots after upstream sync
rhlsthrm Oct 1, 2026
85295cf
fix: tighten team session collaborator and archive follow-ups (#2186)
ColeMurray Oct 1, 2026
7707639
test(control-plane): follow upstream team-read and enrichment contracts
rhlsthrm Oct 1, 2026
974634b
chore(deps): hold prettier at upstream's locked version
rhlsthrm Oct 1, 2026
2ea6607
refactor: move collaborator eligibility query into UserStore (#2187)
ColeMurray Oct 1, 2026
0c8cd82
Merge remote-tracking branch 'origin/main'
rhlsthrm Oct 1, 2026
9efa931
fix(deps): restore workerd platform packages dropped from the lockfile
rhlsthrm Oct 1, 2026
519a906
fix(compose): take upstream's replication wait, match Litestream 0.5
rhlsthrm Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,11 @@ updates:
- dependency-name: vitest
versions:
- ">= 5.0.0"
# Prettier tracks the version locked upstream (ColeMurray/background-agents),
# not the latest. A newer formatter rewrites upstream-owned files, which then
# conflict on every sync, and fails format:check on files a sync brings in
# unchanged. Bump it only when upstream's lockfile does.
- dependency-name: prettier

- package-ecosystem: github-actions
directory: /
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/compose-smoke.yml
Original file line number Diff line number Diff line change
Expand Up @@ -119,9 +119,9 @@ jobs:
if: steps.changes.outputs.run == 'true'
run: npm ci

- name: Test smoke change detection
- name: Test smoke tooling
if: steps.changes.outputs.run == 'true'
run: node --test scripts/compose-smoke-paths.test.mjs
run: node --test scripts/compose-smoke-paths.test.mjs scripts/compose-smoke.test.mjs

- name: Build shared package
if: steps.changes.outputs.run == 'true'
Expand Down
10 changes: 10 additions & 0 deletions .github/workflows/terraform.yml
Original file line number Diff line number Diff line change
Expand Up @@ -294,6 +294,7 @@ jobs:
TF_VAR_enable_service_bindings: "${{ vars.ENABLE_SERVICE_BINDINGS || secrets.ENABLE_SERVICE_BINDINGS || 'true' }}"
TF_VAR_sandbox_provider: "${{ vars.SANDBOX_PROVIDER || secrets.SANDBOX_PROVIDER || 'modal' }}"
TF_VAR_sandbox_inactivity_timeout_ms: "${{ vars.SANDBOX_INACTIVITY_TIMEOUT_MS || secrets.SANDBOX_INACTIVITY_TIMEOUT_MS || '600000' }}"
TF_VAR_teams_enforcement: "${{ vars.TEAMS_ENFORCEMENT || secrets.TEAMS_ENFORCEMENT || 'shadow' }}"
TF_VAR_sandbox_boot_timeout_ms: "${{ vars.SANDBOX_BOOT_TIMEOUT_MS || secrets.SANDBOX_BOOT_TIMEOUT_MS || '1800000' }}"
TF_VAR_daytona_api_url: ${{ vars.DAYTONA_API_URL || secrets.DAYTONA_API_URL }}
TF_VAR_daytona_api_key: ${{ secrets.DAYTONA_API_KEY }}
Expand Down Expand Up @@ -323,6 +324,10 @@ jobs:
TF_VAR_e2b_auto_pause: "${{ vars.E2B_AUTO_PAUSE || secrets.E2B_AUTO_PAUSE || 'true' }}"
TF_VAR_e2b_template_cpu: "${{ vars.E2B_TEMPLATE_CPU || secrets.E2B_TEMPLATE_CPU || '2' }}"
TF_VAR_e2b_template_memory_mb: "${{ vars.E2B_TEMPLATE_MEMORY_MB || secrets.E2B_TEMPLATE_MEMORY_MB || '4096' }}"
# Documentation site (packages/docs). Leaving DOCS_SITE_ENABLED unset
# after provisioning the site destroys its Vercel project on apply.
TF_VAR_docs_site_enabled: "${{ vars.DOCS_SITE_ENABLED || secrets.DOCS_SITE_ENABLED || 'false' }}"
TF_VAR_docs_custom_domain: ${{ vars.DOCS_CUSTOM_DOMAIN || secrets.DOCS_CUSTOM_DOMAIN }}

- name: Post Plan Results
uses: actions/github-script@v9
Expand Down Expand Up @@ -489,6 +494,7 @@ jobs:
TF_VAR_enable_service_bindings: "${{ vars.ENABLE_SERVICE_BINDINGS || secrets.ENABLE_SERVICE_BINDINGS || 'true' }}"
TF_VAR_sandbox_provider: "${{ vars.SANDBOX_PROVIDER || secrets.SANDBOX_PROVIDER || 'modal' }}"
TF_VAR_sandbox_inactivity_timeout_ms: "${{ vars.SANDBOX_INACTIVITY_TIMEOUT_MS || secrets.SANDBOX_INACTIVITY_TIMEOUT_MS || '600000' }}"
TF_VAR_teams_enforcement: "${{ vars.TEAMS_ENFORCEMENT || secrets.TEAMS_ENFORCEMENT || 'shadow' }}"
TF_VAR_sandbox_boot_timeout_ms: "${{ vars.SANDBOX_BOOT_TIMEOUT_MS || secrets.SANDBOX_BOOT_TIMEOUT_MS || '1800000' }}"
TF_VAR_daytona_api_url: ${{ vars.DAYTONA_API_URL || secrets.DAYTONA_API_URL }}
TF_VAR_daytona_api_key: ${{ secrets.DAYTONA_API_KEY }}
Expand Down Expand Up @@ -518,6 +524,10 @@ jobs:
TF_VAR_e2b_auto_pause: "${{ vars.E2B_AUTO_PAUSE || secrets.E2B_AUTO_PAUSE || 'true' }}"
TF_VAR_e2b_template_cpu: "${{ vars.E2B_TEMPLATE_CPU || secrets.E2B_TEMPLATE_CPU || '2' }}"
TF_VAR_e2b_template_memory_mb: "${{ vars.E2B_TEMPLATE_MEMORY_MB || secrets.E2B_TEMPLATE_MEMORY_MB || '4096' }}"
# Documentation site (packages/docs). Leaving DOCS_SITE_ENABLED unset
# after provisioning the site destroys its Vercel project on apply.
TF_VAR_docs_site_enabled: "${{ vars.DOCS_SITE_ENABLED || secrets.DOCS_SITE_ENABLED || 'false' }}"
TF_VAR_docs_custom_domain: ${{ vars.DOCS_CUSTOM_DOMAIN || secrets.DOCS_CUSTOM_DOMAIN }}
MODAL_TOKEN_ID: ${{ secrets.MODAL_TOKEN_ID }}
MODAL_TOKEN_SECRET: ${{ secrets.MODAL_TOKEN_SECRET }}

Expand Down
97 changes: 92 additions & 5 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,102 @@

New features, integrations, and notable improvements to Open-Inspect — newest first.

## Unreleased

### Changed

Team-owned session actions now require current owning-team membership in every `TEAMS_ENFORCEMENT`
mode, including for Owners and Administrators. Visibility still determines read access; collaborator
self-removal requires only read access. Sessions, automations, and environments cannot move between
teams or to/from the workspace; a team-owned session never becomes workspace-owned. Visibility and
collaborator controls remain available to authorized users. Historical `session.moved` audit events
remain readable.

## October 1, 2026

### Added

Team leads and workspace administrators can manage encrypted secrets from a team's Secrets tab.
Team-owned sessions receive global secrets, then team secrets, then environment or repository
secrets, with later scopes taking precedence. Environment image builds include the environment's
team secrets; repository-shared images do not. Secret mutation audits contain key names only. Team
secret changes atomically supersede affected environment images. After the database batch, detached,
best-effort rebuild scheduling is attempted for enabled team-owned environments; enumeration or
trigger failures may leave no rebuild request. Team-owned environment images require matching
session ownership. Team-only legacy OAuth refresh tokens do not enable managed authentication; API
keys remain usable. Team-secret read and decryption errors abort environment builds rather than
falling back to other secret scopes.

### Removed

Removed the team Activity tab and `GET /teams/:id/activity` endpoint. Team operations continue to be
recorded in the workspace audit log, available to viewers with `workspace.audit.read` and filterable
by team. No audit history is deleted.

### Fixed

The team directory and collaborator picker now show email addresses only to viewers with
`workspace.members.read` (Owners and Administrators in the built-in roles). Other viewers receive
names and avatars with no email address, and unnamed users have a neutral label with a short ID
suffix. This restriction applies in every team enforcement mode.

Session navigation now defaults to **All my teams**, with the team selector available even for a
single membership. Composer team and visibility choices stay local, including automatic team
selection when new sessions require a team. Transient membership refresh failures retain loaded
data, and changing draft configuration retires the old warm session without starting a replacement
sandbox until the next prompt input or submission. Scope changes refresh lists without clearing
terminal access or per-session caches. Visibility changes require a changed selection and confirm
non-private child-session cascades. Workspace audit readers can filter by teams they do not belong
to.

## September 30, 2026

### Added

Teams now have a searchable directory with favorites, member lists, session overviews, and
visibility-filtered activity. Active users can browse team names and memberships; a team's work
remains restricted to members and administrators. Workspace audit readers can filter events by team.
Session details show the owning team and visibility, with server-authorized controls to move
sessions, change visibility, and manage private-session collaborators, including child-session
cascades. Archived team metadata and member lists remain visible only to team members and workspace
administrators. Team activity shows domain operations; HTTP authorization decisions remain in the
permission-gated workspace audit log.

**Team-aware session discovery and creation.** Following the team and visibility APIs, the web app
now supports team selection and scoped session discovery. Inbox snapshot and paged reads accept
ownership, visibility, and workspace scope filters and return effective server capabilities for
roots and descendants. The current user's team response includes the require-team creation setting
without requiring settings-management permissions. Bot team selection and automation team ownership
remain later phases; repository-backed team sessions still require existing grants, with no grant
creation API or UI yet.

### Fixed

Allowed team directory, member, session, activity, and collaborator-candidate reads no longer add
authorization-decision rows to the audit log. Capability writes and membership departures remain
audited. Unauthorized cross-member removals are recorded as denied decisions. Live session
subscriptions now include team memberships when computing capabilities in every enforcement mode,
preserving team leads' move and visibility controls without adding reads to per-command
authorization in `off` or `shadow`.

## September 29, 2026

### Added

`TEAMS_ENFORCEMENT` controls active-user session item routes (`/sessions/:id` and its subpaths)
using the persisted session row (`off`, `shadow` by default, or `on`). On those routes, private
visibility applies in every mode; team visibility and the delete ownership rule apply when `on`.
Workspace-wide session lists, bulk export, and WebSocket authorization follow in subsequent changes.
No route can make a session private or team-owned before those changes land.
**Team-scoped session access.** Teams remain optional: existing sessions stay teamless workspace
rows, and **Settings > Teams > Require a team for new sessions** is off by default. Operators can
roll out `TEAMS_ENFORCEMENT=off|shadow|on` (`shadow` by default): `shadow` records would-be team and
ownership denials without blocking non-private sessions, while `on` enforces them. Private
visibility is restricted in every mode. Session item routes, lists and aggregates, live connections,
and sandbox access use the persisted session scope; Owners' private-session break-glass reads are
audited and do not make those sessions enumerable. Session creation and team moves check membership
and repository grants; team and visibility change APIs have landed, with discovery UI following in
the next entry. Visibility, scope, and collaborator mutations enforce the resolver in every mode and
cascades refuse inaccessible descendants. The require-team setting refuses teamless session creation
API requests; automation runs remain exempt until team ownership is supported. Repository grant
creation is not yet available, so missing grants refuse repository-backed team sessions with
`target_team_missing_grant`. Team grants do not yet narrow the shared source-control installation
token in sandboxes. See [Authentication and Authorization](docs/AUTH.md).

## September 28, 2026

Expand Down
Loading
Loading