Skip to content

fix: clarify hosted automation publishing - #669

Draft
an1va wants to merge 1 commit into
mainfrom
agent/hosted-execution-dogfood-polish
Draft

fix: clarify hosted automation publishing#669
an1va wants to merge 1 commit into
mainfrom
agent/hosted-execution-dogfood-polish

Conversation

@an1va

@an1va an1va commented Aug 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • explain when workspace policy holds a requested live automation write for review
  • make the automation list say “Requests live publishing” while the review gate is on
  • replace Codex auth.json tail hints with a semantic subscription label

Root cause

The UI stored a live-publish intent but did not render the workspace-level autonomy gate that the executor applies at claim time. Codex subscription login treats an auth.json document as an opaque token and used its trailing JSON punctuation as the display hint.

Validation

  • focused API and web tests
  • API and web typechecks
  • web production build
  • full repository verification under Node 24: CI checks, typechecks, and coverage suite

The verification hook completed successfully.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown

Preview

https://derive-pr-669.derive-to.workers.dev

Deployed from bc1fddb as derive-pr-669.

It shares production's database — sign in with your real account, and treat anything you change here as changed for real. It has no routes, no cron, no queue consumer and no OG renderer, so it cannot serve derive.to, run scheduled work, or write images onto real artifacts.

Unlike production it serves artifact HTML on its own origin (that is what makes frame-side changes visible here). Storage is still sandboxed away, but untrusted HTML and the sign-in form share a hostname — treat this URL as you would any link: don't type a password into it because a page asked you to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant