Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
3fd6817
feat(managed-agent): broker authentication and broker-provisioned wri…
Oct 2, 2026
e2517ed
fix(managed-agent): harden broker guards from adversarial audit
Oct 2, 2026
ecccb86
fix(managed-agent): renumber the session creator migration to V31
Oct 2, 2026
825f237
chore(web-shell): regenerate the managed agent API types
Oct 2, 2026
9496105
fix(managed-agent): address the PR review round on broker auth
Oct 2, 2026
5709c80
fix(managed-agent): renumber the session creator migration to V33
Oct 2, 2026
201051a
fix(managed-agent): renumber the session creator migration to V34
Oct 2, 2026
e86c2a5
test(managed-agent): create the pre-upgrade session with the legacy c…
Oct 2, 2026
8dc87e3
fix(managed-agent): close the signed-mode coverage, buffering and con…
Oct 3, 2026
3e9881f
fix(managed-agent): renumber the session creator migration to V35
Oct 3, 2026
0ad419d
Merge remote-tracking branch 'origin/main' into feat/managed-agent-br…
Oct 3, 2026
66ad0cf
Merge remote-tracking branch 'origin/main' into feat/managed-agent-br…
Oct 3, 2026
c5655cc
chore: restore NOTICES.txt to the upstream content
Oct 3, 2026
59e4f96
fix(managed-agent): address the R3 review round
Oct 3, 2026
984e1d3
fix(managed-agent): address the R4 review round
Oct 3, 2026
2b13ca9
Merge remote-tracking branch 'origin/main' into feat/managed-agent-br…
Oct 4, 2026
995b306
Merge remote-tracking branch 'origin/main' into feat/managed-agent-br…
Oct 4, 2026
68d458d
docs(managed-agent): reconcile the README intro with the signed mode
Oct 4, 2026
8cf9b17
Merge remote-tracking branch 'origin/main' into feat/managed-agent-br…
Oct 4, 2026
55dd5c0
test(managed-runtime): mark the fake-host store test as allowing inse…
Oct 4, 2026
2f5a9eb
test(cli): give Hosted Harness status-settle waits an explicit 10s ti…
Oct 4, 2026
26943c9
fix(managed-agent): pin signed JSON decoding to UTF-8 (R6-1)
Oct 4, 2026
64fe514
test(cli): cover the remaining default-timeout HTTP polls in the Host…
Oct 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Merge remote-tracking branch 'origin/main' into feat/managed-agent-br…
…oker-auth

# Conflicts:
#	packages/sdk-java/managed-agent-server/src/main/resources/openapi/managed-agent-public-api.openapi.json
  • Loading branch information
wenshao
wenshao committed Oct 3, 2026
commit 0ad419dc6330debfe6983a543cb354316d64c01e
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"info": {
"title": "Qwen Managed Agent Public and WebShell API",
"version": "1.30.0",
"description": "Canonical contract for the public Managed Agent resources and the WebShell adapter. partial means that the route exists but generated types and full contract tests are pending; planned means that the route or field is not implemented. Workspace context and cwd operations are v1.9 target contracts, not current server capabilities. v1.10 adds planned command admission, Actions, lifecycle and actor authorization. v1.12 refines planned W0 creation discovery, actor-specific create hints and explicit default selection. Filter planned fields as well as routes from production SDKs. v1.13 moves this contract into the Qwen Code repository as its single source and records the shipped rename, archive, unarchive and delete routes as partial. v1.14 integrates W0d workspace discovery, the WebShell workspace lookup, and empty-session binding as partial; workspace_binding/workspaceBinding advertises this narrow flow without enabling workspace execution or context switching. v1.15 adds the archived, archiving and deleting Session statuses and the cancelling Turn status, requires request_id in error envelopes, declares the error responses that the server returns, and marks Session create, list and get on both surfaces implemented. v1.16 adds the planned Stage H task contract (SessionTaskView as PublicTask, task list, detail, events and cancel) and names the MCP catalog, hook catalog, automation and channel resources as planned; their shapes arrive with Stages H1 to H6. v1.17 implements event replay: events carry their schema and projection versions and a top-level Item and Part identity, JSON event pages return has_more and next_cursor and accept limits up to 1000, and a persisted replay floor answers expired cursors with 409 cursor_expired in JSON and one agent.session.resync_required frame over SSE; it marks the public event query and stream, the WebShell event stream and the WebShell transcript implemented. v1.18 implements the durable Session lifecycle (Stage D4): close, archive and delete answer 202 with a command operation on both surfaces, an archive requires a closed Session, a deleted Session leaves a tombstone whose operations stay readable, and the operation query serves them; unarchive restores a closed Session, and Session capabilities advertise session_lifecycle. v1.19 serves the task list and detail on both surfaces as partial (Stage H0c): the Session store projects them from the Stage H records the Session authority commits, a task.updated Session event announces each change of a task's view, and Session capabilities advertise tasks. Task events and cancel stay planned until a slice's tasks produce output and accept a cancel. v1.20 implements the Turn read model (Stage D5): the public Turn list and detail read a Session's Turns without their input, newest first by creation time in milliseconds and then Turn ID, with an opaque cursor; a deleted Session's Turns are not readable, and the durable admission fields of a Turn stay planned until D7. v1.21 declares on the task list, detail and event routes of both surfaces the 403 actor_scope_mismatch that the tenant filter answers on every /v1/agents/ and WebShell route, as the Session and Turn reads already do, and the shared Forbidden response names it; a caller that cannot read a task still gets 404. v1.22 adds deployment-opted-in creation with an initial Workspace file-tool Turn (G0) on the public and WebShell surfaces; the fixed server-owned profile does not enable later Workspace operations. v1.23 settles the planned task event and cancel semantics: a durable retention floor, committed-prefix publication, stable cursors, Artifact visibility before expiry, bounded backlog under archival failure, ordered idempotent cancellation and command outcomes. Clients tolerate unknown optional event fields across minor versions. Task events and cancel remain planned. v1.24 serves the read-only Session MCP catalog as partial (Stage H1), projecting display metadata and schemas from committed records without Runtime identities, credentials or production profile enablement. v1.25 implements permission Actions (Stage D6b) on both surfaces: list, get and respond, projected from the Session's action.changed records; a WebShell permission Action carries inputRevision, policyRevision, functionCallId, toolName and expiresAt, its option ids allow and deny are stable, a Turn has at most one requested approval at a time, and a response is a durable command operation carrying requestId. v1.26 declares the tenant filter's 403 actor_scope_mismatch on every covered public and WebShell route, including planned routes, and pins the refusal code in contract traffic. v1.27 adds O3 durable tool-result projection, artifact metadata, immutable range/streaming content and WebShell result reads. Artifact capability requires a configured O3 reader and a Workspace-bound Session; execution admission remains independent. v1.29 implements the AgentDefinition routes (Stage D8a): create, get and update store tenant-scoped, immutable revisions with a content digest, and an unchanged update adds no revision. Sessions still pin qwen-code and the configured revision, and no definition field changes execution yet. v1.30 adds the qwenSignature security scheme for gateway-free deployments: in signed authentication mode the broker authenticates the X-Qwen-Tenant-Id and X-Qwen-Actor-Id header pair itself with an HMAC signature over method, path, query, tenant, actor, timestamp, body digest and Idempotency-Key, carried in X-Qwen-Signature and X-Qwen-Signature-Timestamp, and answers 401 authentication_required or invalid_signature, 400 invalid_request on a repeated Idempotency-Key header, and 413 payload_too_large beyond the signed-body limit; a Session now records its creator so approval responses are owned without a Workspace creation record; a Session with no recorded creator answers approvals to any caller in its tenant."
"description": "Canonical contract for the public Managed Agent resources and the WebShell adapter. partial means that the route exists but generated types and full contract tests are pending; planned means that the route or field is not implemented. Workspace context and cwd operations are v1.9 target contracts, not current server capabilities. v1.10 adds planned command admission, Actions, lifecycle and actor authorization. v1.12 refines planned W0 creation discovery, actor-specific create hints and explicit default selection. Filter planned fields as well as routes from production SDKs. v1.13 moves this contract into the Qwen Code repository as its single source and records the shipped rename, archive, unarchive and delete routes as partial. v1.14 integrates W0d workspace discovery, the WebShell workspace lookup, and empty-session binding as partial; workspace_binding/workspaceBinding advertises this narrow flow without enabling workspace execution or context switching. v1.15 adds the archived, archiving and deleting Session statuses and the cancelling Turn status, requires request_id in error envelopes, declares the error responses that the server returns, and marks Session create, list and get on both surfaces implemented. v1.16 adds the planned Stage H task contract (SessionTaskView as PublicTask, task list, detail, events and cancel) and names the MCP catalog, hook catalog, automation and channel resources as planned; their shapes arrive with Stages H1 to H6. v1.17 implements event replay: events carry their schema and projection versions and a top-level Item and Part identity, JSON event pages return has_more and next_cursor and accept limits up to 1000, and a persisted replay floor answers expired cursors with 409 cursor_expired in JSON and one agent.session.resync_required frame over SSE; it marks the public event query and stream, the WebShell event stream and the WebShell transcript implemented. v1.18 implements the durable Session lifecycle (Stage D4): close, archive and delete answer 202 with a command operation on both surfaces, an archive requires a closed Session, a deleted Session leaves a tombstone whose operations stay readable, and the operation query serves them; unarchive restores a closed Session, and Session capabilities advertise session_lifecycle. v1.19 serves the task list and detail on both surfaces as partial (Stage H0c): the Session store projects them from the Stage H records the Session authority commits, a task.updated Session event announces each change of a task's view, and Session capabilities advertise tasks. Task events and cancel stay planned until a slice's tasks produce output and accept a cancel. v1.20 implements the Turn read model (Stage D5): the public Turn list and detail read a Session's Turns without their input, newest first by creation time in milliseconds and then Turn ID, with an opaque cursor; a deleted Session's Turns are not readable, and the durable admission fields of a Turn stay planned until D7. v1.21 declares on the task list, detail and event routes of both surfaces the 403 actor_scope_mismatch that the tenant filter answers on every /v1/agents/ and WebShell route, as the Session and Turn reads already do, and the shared Forbidden response names it; a caller that cannot read a task still gets 404. v1.22 adds deployment-opted-in creation with an initial Workspace file-tool Turn (G0) on the public and WebShell surfaces; the fixed server-owned profile does not enable later Workspace operations. v1.23 settles the planned task event and cancel semantics: a durable retention floor, committed-prefix publication, stable cursors, Artifact visibility before expiry, bounded backlog under archival failure, ordered idempotent cancellation and command outcomes. Clients tolerate unknown optional event fields across minor versions. Task events and cancel remain planned. v1.24 serves the read-only Session MCP catalog as partial (Stage H1), projecting display metadata and schemas from committed records without Runtime identities, credentials or production profile enablement. v1.25 implements permission Actions (Stage D6b) on both surfaces: list, get and respond, projected from the Session's action.changed records; a WebShell permission Action carries inputRevision, policyRevision, functionCallId, toolName and expiresAt, its option ids allow and deny are stable, a Turn has at most one requested approval at a time, and a response is a durable command operation carrying requestId. v1.26 declares the tenant filter's 403 actor_scope_mismatch on every covered public and WebShell route, including planned routes, and pins the refusal code in contract traffic. v1.27 adds O3 durable tool-result projection, artifact metadata, immutable range/streaming content and WebShell result reads. Artifact capability requires a configured O3 reader and a Workspace-bound Session; execution admission remains independent. v1.28 admits later Turns of a Workspace-bound Session for the Session's creator under the deployment's Workspace files opt-in, including cancel and rename; WebShell Session capabilities advertise the per-caller workspaceTurns flag. v1.29 implements the AgentDefinition routes (Stage D8a): create, get and update store tenant-scoped, immutable revisions with a content digest, and an unchanged update adds no revision. Sessions still pin qwen-code and the configured revision, and no definition field changes execution yet. v1.30 adds the qwenSignature security scheme for gateway-free deployments: in signed authentication mode the broker authenticates the X-Qwen-Tenant-Id and X-Qwen-Actor-Id header pair itself with an HMAC signature over method, path, query, tenant, actor, timestamp, body digest and Idempotency-Key, carried in X-Qwen-Signature and X-Qwen-Signature-Timestamp, and answers 401 authentication_required or invalid_signature, 400 invalid_request on a repeated Idempotency-Key header, and 413 payload_too_large beyond the signed-body limit; a Session now records its creator so approval responses are owned without a Workspace creation record; a Session with no recorded creator answers approvals to any caller in its tenant."
},
"servers": [
{
Expand Down
57 changes: 36 additions & 21 deletions packages/vscode-ide-companion/NOTICES.txt

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
You are viewing a condensed version of this merge commit. You can view the full changes here.