Skip to content

fix(ruby): improve Rails setup and prepare Fizzy acceptance - #258

Open
nicknisi wants to merge 6 commits into
mainfrom
riker/16-carry-auth-6736-forward-with-concrete-ra
Open

nicknisi wants to merge 6 commits into
mainfrom
riker/16-carry-auth-6736-forward-with-concrete-ra

Conversation

@nicknisi

@nicknisi nicknisi commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

Carry AUTH-6736 forward with scoped CLI fixes and offline Fizzy fixture preparation—not successful hosted Fizzy acceptance.

  • Fix Ruby credential delivery and callback/origin consistency while retaining the common post-agent URL provisioning safeguards.
  • Require visible login/account/logout UI and real application session integration without choosing account-linking or auth-coexistence policy; report unverified behavior truthfully.
  • Add a pinned, isolated Fizzy fixture/bootstrap path, explicitly selectable evaluation scenario, and offline regression coverage. Static source checks do not count as behavioral acceptance.

Acceptance status and blockers

AUTH-6736 remains incomplete until real-app acceptance is proven. No paid agents, live auth/provisioning, or hosted AuthKit acceptance run was executed for this work.

Remaining prerequisites:

  • Nick-approved account/identity mapping, creation, membership/role, and authentication-coexistence policy. No proposed policy is implemented here.
  • The pinned toolchain: Ruby 3.4.8 and Bundler 4.0.18; the available local versions did not match.
  • Explicit sandbox/access and spending approval before any paid agent, live authentication, provisioning, or dashboard changes.
  • Retained browser/session/hosted evidence for visible controls, callback identity/account association, repeat-login idempotence, logout access denial, correctly targeted URL settings, and preserved account boundaries/routes.

The Fizzy acceptance runbook and evidence matrix documents the immutable source pin, isolated preparation, precise remaining prerequisites, and future-run procedure. Source path: tests/fixtures/ruby/fizzy/README.md.

Branch-creation behavior and existing authentication-coexistence decisions are unchanged.

Validation

Local and supervisor checks passed: 3,231 tests, TypeScript, lint, and formatting. bun run build also passed. Offline fixture preparation verified the pinned archive; runtime and hosted acceptance remain unverified.

@linear-code

linear-code Bot commented Sep 28, 2026

Copy link
Copy Markdown

AUTH-6736

@nicknisi nicknisi changed the title Carry AUTH-6736 forward with concrete Rails integration fixes and a rep… fix(ruby): improve Rails setup and prepare Fizzy acceptance Sep 28, 2026
@nicknisi
nicknisi marked this pull request as ready for review September 28, 2026 21:08
@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Adds Ruby integration setup and evaluation test infrastructure.

The changes since the previous review appear safe to merge; Fizzy acceptance remains explicitly unverified.

Summary

The PR updates Ruby credential delivery and setup guidance, adds an isolated Fizzy fixture and opt-in evaluation path, and keeps behavioral acceptance explicitly unverified. Changes since the previous review protect non-JS eval credentials and prevent automatic repeat Fizzy runs.

Reviews (2) · Last reviewed commit: "test: isolate destructive skills extract..."

Comment thread tests/evals/runner.ts
@greptile-apps

This comment has been minimized.

The extraction race specs deleted the version/UID-keyed temp cache used by parallel doctor --fix tests. A deletion between materialization and discoverSkills made real refreshWorkOSSkills return null, failing the sibling-protection assertion.

Reproduced the exact null failure with a filesystem scheduling barrier in isolated archives of base 2f19926 and AUTH-6733 d8f5a4e (3/3 each). The same barrier passes 3/3 with this fixture isolation; an unchanged baseline still fails. Ordinary paired runs passed 12/12 each, confirming the timing sensitivity rather than relying on a retry until green.

Mock only this spec's tmpdir to a unique directory, clean it afterward, and assert it differs from the real shared temp directory. Keep real materialization, allowlist and sibling-write protection assertions unchanged. No production or installer branch behavior changes.

(cherry picked from commit c9fd8b6654a206c5c7fc8cc820f15923c5e88c8a)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant