Files
buzz/desktop/tests/e2e/agent-access-warning.spec.ts
f716eef437 fix(desktop): enforce shared agent access across devices (#6086)
## Summary

- discover shared managed agents from authenticated relay directory
records instead of treating channel membership as sufficient proof
- publish and refresh access-policy changes immediately so running
clients converge across machines without a restart or five-minute poll
- route profile edits through the exact managed instance and
stop/restart runtimes around access changes so unrelated edits cannot
silently widen access
- keep mention send-time revalidation and Block owner-only build
enforcement fail closed
- explain invalid custom provider/model configuration instead of leaving
Save silently disabled

### Related issue

Fixes #3204

### Known residuals

- a brand-new remote agent's first policy record can wait for the
bounded directory poll when no authenticated directory coordinate exists
yet; send-time mention revalidation remains fail closed
- a failed remote-provider policy redeploy is recorded but cannot
undeploy the older provider instance until the provider protocol gains
the destructor tracked by #5570

### Testing

- full Desktop unit suite: 4,961 tests passed
- focused profile editor Playwright workflow passed, including Customize
access edits and prompt-only edits after tightening an instance
- Desktop TypeScript, Biome formatting, file-size ratchet, Tauri checks,
and pre-push suites passed
- independently reviewed for authenticated directory trust, live
subscription teardown, runtime revocation ordering, fail-open edit
paths, and per-agent provider deployment serialization

---------

Signed-off-by: Wes <wesbillman@users.noreply.github.com>
Signed-off-by: Brain <21994759fc7a6fa6b965551d35cfd7897d262f2495467f2d78694ddcfa6a5c7e@buzz.block.builderlab.xyz>
Co-authored-by: diegorumo <diegorumo@gmail.com>
Co-authored-by: Carl <c7ebe626f000404285d3686e1dc74cc07cc60a9754a150041ba132e14bd3e2ec@buzz.block.builderlab.xyz>
Co-authored-by: Brain <21994759fc7a6fa6b965551d35cfd7897d262f2495467f2d78694ddcfa6a5c7e@buzz.block.builderlab.xyz>
2026-08-17 09:51:00 -07:00

338 lines
11 KiB
TypeScript

import { expect, test } from "@playwright/test";
import { waitForAnimations } from "../helpers/animations";
import { installMockBridge, TEST_IDENTITIES } from "../helpers/bridge";
const SHOTS = "test-results/agent-access-warning";
async function choosePersonaAccess(
page: import("@playwright/test").Page,
optionName: string,
) {
await page.locator("#agent-respond-to").click();
await page.getByRole("menuitemradio", { name: optionName }).click();
}
async function openAgentAccessDialog(
page: import("@playwright/test").Page,
agentPubkey: string,
) {
if (!(await page.getByTestId("members-sidebar").isVisible())) {
await page.getByTestId("channel-general").click();
await page.getByTestId("channel-members-trigger").click();
await expect(page.getByTestId("members-sidebar")).toBeVisible();
}
const row = page.getByTestId(`sidebar-member-${agentPubkey}`);
const menu = page.getByTestId(`sidebar-member-menu-${agentPubkey}`);
await row.hover();
await menu.focus();
await menu.press("Enter");
await page.getByTestId(`sidebar-edit-respond-to-${agentPubkey}`).click();
await expect(
page.getByRole("dialog", { name: "Manage agent access" }),
).toBeVisible();
}
test("open agent access explains the available access before save", async ({
page,
}) => {
const agent = TEST_IDENTITIES.charlie;
await installMockBridge(page, {
managedAgents: [
{
pubkey: agent.pubkey,
name: "Hack Day Helper",
status: "running",
channelNames: ["general"],
respondTo: "anyone",
},
],
});
await page.goto("/");
await page.getByTestId("channel-general").click();
await page.getByTestId("channel-members-trigger").click();
const accessBadge = page.getByTestId(
`sidebar-managed-agent-respond-to-${agent.pubkey}`,
);
await expect(accessBadge).toBeVisible();
await expect(accessBadge).toHaveText("Anyone");
await openAgentAccessDialog(page, agent.pubkey);
const accessSelect = page.getByTestId("agent-respond-to-select");
await expect(accessSelect).toHaveValue("anyone");
const saveAccess = page.getByRole("button", { name: "Save access" });
await expect(saveAccess).toBeVisible();
const commandsBeforeSave = await page.evaluate(
() => window.__BUZZ_E2E_COMMAND_LOG__?.length ?? 0,
);
await accessSelect.selectOption("owner-only");
await expect(page.getByTestId("agent-access-warning")).toHaveCount(0);
await waitForAnimations(page);
await page
.getByRole("dialog", { name: "Manage agent access" })
.screenshot({ path: `${SHOTS}/open-access-warning.png` });
await saveAccess.click();
await expect(
page.getByRole("dialog", { name: "Manage agent access" }),
).not.toBeVisible();
await expect
.poll(async () =>
page.evaluate((start) => {
const commands = window.__BUZZ_E2E_COMMAND_LOG__ ?? [];
return commands
.slice(start)
.some(
(entry) =>
entry.command === "update_managed_agent" &&
(entry.payload as { input?: { respondTo?: string } })?.input
?.respondTo === "owner-only",
);
}, commandsBeforeSave),
)
.toBe(true);
await expect(accessBadge).toHaveText("Only me");
await openAgentAccessDialog(page, agent.pubkey);
await expect(accessSelect).toHaveValue("owner-only");
// Selected people narrows the audience but not the access, so the warning
// persists with its own audience phrase.
await accessSelect.selectOption("allowlist");
const warning = page.getByTestId("agent-access-warning");
await expect(warning).toBeVisible();
await expect(warning).toContainText(
"Selected people can use this agent to access your computer, including files, accounts, and connected tools.",
);
const picker = page.getByTestId("agent-respond-to-allowlist");
await expect(
picker.getByText("Selected people", { exact: true }),
).toBeVisible();
// The warning sits below the picker so it never blocks the selection the
// user came here to make.
await waitForAnimations(page);
const pickerBox = await picker.boundingBox();
const warningBox = await warning.boundingBox();
expect(pickerBox?.y).toBeDefined();
expect(warningBox?.y).toBeGreaterThan(pickerBox?.y ?? 0);
await page
.getByRole("dialog", { name: "Manage agent access" })
.screenshot({ path: `${SHOTS}/selected-people-warning.png` });
// Only me shares nothing, so the warning goes away entirely.
await accessSelect.selectOption("owner-only");
await expect(warning).toHaveCount(0);
});
test("full agent editor tightens the exact sidebar agent instance", async ({
page,
}) => {
const agent = TEST_IDENTITIES.tyler;
const preferredSiblingPubkey = "d".repeat(64);
const personaId = "shared-sidebar-agent";
await installMockBridge(page, {
acpRuntimesCatalog: [
{
availability: "available",
command: "goose",
default_args: [],
id: "goose",
install_hint: "",
label: "Goose",
mcp_command: "",
},
],
globalAgentConfig: {
env_vars: { ANTHROPIC_API_KEY: "sk-ant-test-key" },
model: "claude-opus-4-5",
preferred_runtime: "goose",
provider: "anthropic",
},
managedAgents: [
{
pubkey: agent.pubkey,
name: "Tyler Agent",
personaId,
status: "running",
channelNames: ["general"],
respondTo: "anyone",
},
{
pubkey: preferredSiblingPubkey,
name: "Preferred Sibling",
personaId,
status: "running",
channelNames: [],
respondTo: "anyone",
},
],
personas: [
{
displayName: "Shared Sidebar Agent",
id: personaId,
isActive: true,
respondTo: "anyone",
runtime: "goose",
systemPrompt: "Test exact instance editing.",
},
],
});
await page.goto("/");
await page.getByTestId("channel-general").click();
await page.getByTestId("channel-members-trigger").click();
const accessBadge = page.getByTestId(
`sidebar-managed-agent-respond-to-${agent.pubkey}`,
);
await expect(accessBadge).toHaveText("Anyone");
await page.getByTestId(`sidebar-member-${agent.pubkey}`).click();
await expect(page.getByTestId("user-profile-panel")).toBeVisible();
await page.getByTestId("user-profile-edit-agent").click();
const dialog = page.getByRole("dialog", { name: "Edit agent" });
await expect(dialog).toBeVisible();
await dialog.getByRole("button", { name: "Advanced" }).click();
await choosePersonaAccess(page, "Only me (default)");
await dialog.getByRole("tab", { name: "Customize for this agent" }).click();
const saveChanges = dialog.getByRole("button", { name: "Save changes" });
await expect(saveChanges).toBeEnabled();
await saveChanges.click();
await expect(dialog).not.toBeVisible();
const updateCommand = await page.evaluate(
(pubkey) =>
window.__BUZZ_E2E_COMMAND_LOG__?.findLast(
(entry) =>
entry.command === "update_managed_agent" &&
(entry.payload as { input?: { pubkey?: string } })?.input?.pubkey ===
pubkey,
),
agent.pubkey,
);
expect(updateCommand?.payload).toMatchObject({
input: { pubkey: agent.pubkey, respondTo: "owner-only" },
});
expect(updateCommand?.payload).not.toMatchObject({
input: { pubkey: preferredSiblingPubkey },
});
await page.getByTestId("channel-members-trigger").click();
await expect(accessBadge).toHaveText("Only me");
// The definition still says "anyone" after the instance-only save above.
// Reopening the same linked agent for an unrelated prompt edit must seed
// access from the exact instance, or the submit silently widens it again.
await page.getByTestId(`sidebar-member-${agent.pubkey}`).click();
await page.getByTestId("user-profile-edit-agent").click();
await expect(dialog).toBeVisible();
await dialog.getByRole("button", { name: "Advanced" }).click();
await expect(page.locator("#agent-respond-to")).toHaveText(
"Only me (default)",
);
await page
.locator("#persona-system-prompt")
.fill("Test unrelated prompt editing after tightening access.");
await dialog.getByRole("button", { name: "Save changes" }).click();
await expect(dialog).not.toBeVisible();
const unrelatedEditCommand = await page.evaluate(
(pubkey) =>
window.__BUZZ_E2E_COMMAND_LOG__?.findLast(
(entry) =>
entry.command === "update_managed_agent" &&
(entry.payload as { input?: { pubkey?: string } })?.input?.pubkey ===
pubkey,
),
agent.pubkey,
);
expect(unrelatedEditCommand?.payload).toMatchObject({
input: { pubkey: agent.pubkey },
});
expect(unrelatedEditCommand?.payload).not.toMatchObject({
input: { respondTo: "anyone" },
});
});
test("a provider-backed agent's warning names the server, not this computer", async ({
page,
}) => {
const agent = TEST_IDENTITIES.charlie;
await installMockBridge(page, {
managedAgents: [
{
pubkey: agent.pubkey,
name: "Remote Helper",
status: "running",
channelNames: ["general"],
respondTo: "owner-only",
backend: { type: "provider", id: "blox", config: {} },
},
],
});
await page.goto("/");
await openAgentAccessDialog(page, agent.pubkey);
await page.getByTestId("agent-respond-to-select").selectOption("anyone");
const warning = page.getByTestId("agent-access-warning");
await expect(warning).toContainText(
"Anyone can use this agent to access the server it runs on, including any accounts and tools available there.",
);
// The local wording must not leak into a remote-backed agent.
await expect(warning).not.toContainText("your computer");
});
test("persona-backed edit warns before saving open access", async ({
page,
}) => {
const agent = TEST_IDENTITIES.tyler;
await installMockBridge(page, {
managedAgents: [
{
pubkey: agent.pubkey,
name: "Tyler Agent",
status: "stopped",
channelNames: ["agents"],
respondTo: "owner-only",
},
],
});
await page.goto("/");
await page.getByTestId("open-agents-view").click();
await page.getByRole("button", { name: "Tyler Agent agent profile" }).click();
await page.getByTestId("user-profile-edit-agent").click();
const dialog = page.getByTestId("edit-agent-dialog");
await expect(dialog).toBeVisible();
await expect(page.locator("#agent-respond-to")).toHaveText(
"Only me (default)",
);
await choosePersonaAccess(page, "Anyone");
await expect(dialog.getByTestId("agent-access-warning")).toContainText(
"Anyone can use this agent to access your computer, including files, accounts, and connected tools.",
);
const commandsBeforeSave = await page.evaluate(
() => window.__BUZZ_E2E_COMMAND_LOG__?.length ?? 0,
);
await page.getByTestId("edit-agent-dialog-submit").click();
await expect(dialog).not.toBeVisible();
await expect
.poll(async () =>
page.evaluate((start) => {
const commands = window.__BUZZ_E2E_COMMAND_LOG__ ?? [];
return commands
.slice(start)
.some(
(entry) =>
entry.command === "update_managed_agent" &&
(entry.payload as { input?: { respondTo?: string } })?.input
?.respondTo === "anyone",
);
}, commandsBeforeSave),
)
.toBe(true);
});