Add Link wallets and migrate to Eve 0.69 - #148
Merged
Merged
Conversation
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OpenInstinct users can connect their own Link wallet and use Stripe's official Eve tools and skills. The extension uses the existing Better Auth phone account for wallet ownership, with interactive OAuth that resumes the original agent request after connection. This branch also migrates the application from Eve 0.67.2 to 0.69.0.
The wallet page supports connection and revocation. Grants are encrypted, refresh and disconnection share an account lock, and a database constraint permits one Link wallet per user. Reconnecting the same wallet updates its grant; changing wallets requires disconnecting first. Stripe's bundled tools, skills, and approval policy remain unchanged. Scheduled workers and result delivery cannot acquire wallet access.
Eve migration
serveworkflow. Calls continue bytaskId, retain the child session, and support cancelling current work before assigning another task.agent.started,task.started, andtask.settledevents. Scheduled tasks finish within the open turn instead of waiting for a later background-result turn.no_replyreplaces the removed empty-delivery marker for silent scheduled reports.task_canceldeclaration and its framework patch; Eve now owns cancellation. Retain the independently tested native Linq reply patch.Setup and compatibility
LINK_CLIENT_ID,LINK_CLIENT_SECRET, andSTRIPE_PUBLISHABLE_KEY, set the canonicalBETTER_AUTH_URL, and register the exact/api/auth/callback/linkredirect URI with Stripe.0014_chief_tigra.sqlwithpnpm db:migratebefore enabling Link.1.7.5, the official Link plugin's minimum version.0.2.3was compiled against an older Eve contract. The documented package patch rebuilds Stripe's exact release source with Eve0.69.0. Runtime JavaScript and skills remain byte-for-byte unchanged; only generated compatibility metadata and declaration ordering differ.The Link extension upgrade also moves its SDK dependency to
0.11.0. The two exact releases have a temporary exception to the repository's 24-hour release-age gate; future versions remain subject to the gate.Validation
pnpm check— passed: 724 tests, types, lint, formatting, and Knip.pnpm test:runtime— passed: 2 real Eve runtime evaluations with 8 gates, covering browser continuation, cancellation, abort observation, and reuse of the same child session.pnpm build— passed with build-only environment values.pnpm exec eve build --skip-sandbox-prewarm— passed; all 13 Link tools compile into the agent.pnpm install --frozen-lockfile— passed. Focused Taze audit reports Eve up to date; the broader audit encountered adrizzle-ormregistry timeout.Link integration tests use real Better Auth and PGlite with mocked Stripe responses for OAuth/PKCE, callback ownership, encrypted grants, refresh, revocation, and rejection of a second wallet. Live Stripe OAuth and payments remain unverified. Full local sandbox preparation requires the optional
microsandboxpackage, which is absent from this checkout.