fix(agents): honor signed execution environment bindings - #4564
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughBranch agent requests now resolve the authorized project preview environment and inject its variables. The handler validates the signed target environment ID. Tests cover preview-only loading and authorization failure before project discovery. ChangesBranch preview environment resolution
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant AgentStreamHandler
participant EnvironmentIdentityResolver
participant AgentEnvVarCache
participant EnvironmentAPI
AgentStreamHandler->>EnvironmentIdentityResolver: Resolve signed preview environment
EnvironmentIdentityResolver-->>AgentStreamHandler: Authorized preview environment
AgentStreamHandler->>AgentEnvVarCache: Load preview variables
AgentEnvVarCache->>EnvironmentAPI: Request environment variables
EnvironmentAPI-->>AgentEnvVarCache: Variables or 403
AgentEnvVarCache-->>AgentStreamHandler: Runtime variables or authorization error
Merge Risk: ⚪ Minimal · up to No verified merge-blocking issue remains in the reviewed change. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
f2256dc to
6706d07
Compare
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
Review score: 15/100 — do not merge as-is (branch is not rebased; carries 16 unrelated/superseded commits)The one commit that matches this PR's description is solid, but the PR as opened is not mergeable and is not reviewable in its current form. Blocking issue — stale branch carrying duplicate/superseded history:
Review of the actual intended change (commit
Once rebased so the diff is just the environment-resolution fix, this looks close to mergeable — the logic and tests are in good shape. Please fix the branch base first. Generated by Claude Code |
|
@codex review |
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
|
Review score: 96/100 Status: ready to merge after the required merge-queue checks. Findings:
Validation:
No blocking findings. |
|
You have reached your Codex usage limits for security reviews. Please try again later. |
1 similar comment
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
@codex review |
|
@codex review |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
|
|
Updated review score: 98/100 Status: ready to merge after the merge-group checks for the current head. Update reviewed at exact head
Validation:
No blocking findings. |



Studio branch-agent runs receive an empty environment even when their project's runtime environment has configured server-side credentials. This change lets the control plane bind an execution environment explicitly in the signed invocation.
Add optional
run.project.executionEnvironmentIdto the internal invocation contract. For branch sources, load only that environment through the existing project-scoped authorization and credential-scoped cache. Without a binding, a branch still receives no project secrets. The runtime does not discover an environment or choose a preview fallback. Named release-bound environments and bare releases keep their existing behavior.No provider-specific logic or credential values are added to the protocol, browser, or model messages. Tests use a synthetic generic service key. Paired API PR: https://github.com/veryfront/veryfront-api/pull/5066. It resolves the managed environment from project metadata without loading secret values; the framework change must be deployed first.
Validation: 285 focused runtime/contract/environment checks pass, including an explicitly bound tool environment, unbound branches, and authorization denial. Full framework typecheck, targeted lint, formatting and diff checks pass. Production Studio verification is pending the paired release.