Skip to content

feat(eve): share authorization with workflow tool steps - #3073

Open
ruiconti wants to merge 14 commits into
mainfrom
ruiconti/workflow-step-authorization
Open

feat(eve): share authorization with workflow tool steps#3073
ruiconti wants to merge 14 commits into
mainfrom
ruiconti/workflow-step-authorization

Conversation

@ruiconti

@ruiconti ruiconti commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Summary

Workflow tools cannot currently use ctx.getToken and ctx.requireAuth across a step boundary. This shares authorization handling across connection search, ordinary tools, and workflow steps, reconstructing step capabilities under the launching requester. Root-agent authorization returns control to the model; workflow authorization waits on its own callback and invokes the interrupted step again. Background-task owners apply auth state through the existing task transitions, forward the event, and acknowledge it through one handler for queued and newly received requests.

  • Pass ctx directly to a step helper. Token resolution and authenticated I/O stay inside the step; its API result enters workflow history. Direct workflow-body token calls remain unsupported, and the existing exception-based auth contract is unchanged.
  • Step invocations require authorization context. Only execution fields cross into the step; the owner address and full run reference remain in the workflow body.
  • Successful callback completion survives a later step retry; bearer tokens remain in the provider store and step-local cache. Native step references retain SDK serialization and calling conventions.
  • Background tasks enter input_required while awaiting sign-in. Cancellation withdraws their callback; discarded owner events release acknowledgment waiters without reopening a terminal task.
  • Capability epoch 31 retains epoch 30 and earlier supported epochs. Native Devbox migration and general webhook-wait cancellation remain separate work. Related to feat(eve): support inline tool auth providers #47, feat(eve): yield progress and messages from background tools #2997, and research/tool-suspendability-and-lifetime.md.

Upgrading existing conversations

A conversation started before this feature was deployed retains its old session driver, even when a later message starts a turn on the new deployment. If that turn launches a background workflow tool, its sign-in event would reach the old driver, whose sender validation only recognizes child agents. The event would be dropped and the task could wait without displaying its sign-in link.

The new turn now reads workflowTaskAuthorization from the receiving driver's persisted inbox-hook metadata. Without that capability, the background workflow may still run, but its first ctx.getToken or ctx.requireAuth call fails without retrying or calling the auth provider, telling the user to start a new session. Checking at API use avoids blocking existing background workflows that never use auth. Blocking workflow tools use their owning turn's handler; root-agent authorization keeps its existing path.

The old handler's rejection was reproduced in a focused test. Integration coverage removes the driver's capability advertisement and exercises the real launch and step paths, verifying the actionable error and absence of a sign-in challenge. This is not a two-deployment production reproduction.

Validation

  • Producer capability guard at f004de6f1: 40 focused unit tests and 45 integration tests passed across workflow execution, authorization, task ownership, and parent dispatch. Typecheck (43 tasks), build (4 tasks), formatting, lint, docs, and invariant checks passed. CI for this head is pending.

  • Context simplification at 46425eb13: 7 focused unit tests and 27 workflow-tool integration tests passed. Workspace typecheck (43 tasks), build (4 tasks), formatting, lint, and invariant checks passed.

  • After merging current main, 27 unit tests passed across task-owner handling, parent dispatch/execution, and the subagent registry. The 15 task-owner cases include state/forward/acknowledgment ordering, rejected dispatch, cancellation, and persistence/delivery failure.

  • After merging current main, 38 integration tests passed across workflow-tool execution and parent task execution, covering authorization, cancellation, background execution, step references, and busy-agent steering.

  • pnpm typecheck (43 tasks), pnpm build, pnpm fmt, pnpm lint, pnpm docs:check, and pnpm guard:invariants passed on the merged tree. The fixture's 19 transition declarations validated.

  • Before the main merge, pnpm test: 8,154 eve unit tests passed; the same two existing macOS telemetry-path assertions failed in src/cli/telemetry/preference.test.ts, preventing the command from reaching integration. The focused integration suite above ran separately.

  • Earlier focused auth/compiler validation: 24 unit and 67 integration tests passed; the compiled authored-workflow development-server scenario passed.

  • The E2E fixture uses real context methods and a fixture HTTP service, including requireAuth after 401.

  • The preceding Vercel run exposed a timing race in task.agent.continue.rejected-agent-busy: the child completed before the later continuation arrived (trace artifact). Current main (test(eve): add background subagent steering evals #3016) changes later continuation into steering and renames this eval to task.agent.steer.accepted-busy. The merged eval waits for the child to reach an approval gate, then checks that steering cancels that nonterminal task and completes a replacement on the same agent. Its correctness no longer depends on completing the check within five seconds.

  • The step-reference regression round-trips references, then binds arguments/receivers at invocation. Binding a receiver before the round trip also fails in a direct SDK control; that separate SDK behavior is unchanged.

  • E2Es run only in CI. Owner simplification is isolated in 4f192c5b3; the deterministic busy-worker gate is in 45ca4bd4d, adapted to current-main steering semantics in a5a71dd99.

Checklist

  • This change was requested or approved by a maintainer
  • I ran the relevant checks from CONTRIBUTING.md
  • I added tests and documentation where relevant
  • I added a changeset if this touches the published eve package
  • DCO sign-off passes for every commit (git commit --signoff)

Signed-off-by: Rui Conti <ruiconti@gmail.com>
@vercel

vercel Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
eve-docs Ready Ready Preview, v0 Sep 6, 2026 11:21pm UTC
eve-docs-4759 Ready Ready Preview, v0 Sep 6, 2026 11:21pm UTC
eve-pkg Ready Ready Preview, v0 Sep 6, 2026 11:21pm UTC

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Bundle + Package Summary: apps/fixtures/weather-agent

Key takeaways

  • Runtime delta: function payloads 20.72 MB -> 21.13 MB (+407.6 kB ⚠️).

Delta vs main (4b5fad4)

Area Metric Baseline Current Delta
Package Packed tarball 8.65 MB 8.65 MB +4.4 kB ⚠️
Package Unpacked publish size 32.59 MB 32.61 MB +15.1 kB ⚠️
Package Installed footprint 77.67 MB 77.69 MB +15.1 kB ⚠️
Package Published files 3847 3857 +10
Package Installed files 7745 7755 +10
Package Installed package instances 33 33 0
Package Distinct installed package names 32 32 0
Package Installed dependency edges 51 51 0
Package Installed optional peer edges 7 7 0
Runtime Unique function payloads 2 2 0
Runtime Total function bytes 20.72 MB 21.13 MB +407.6 kB ⚠️
Runtime Public routes 18 18 0
Changed function payloads vs main (4b5fad4) (2)
Function Status Baseline Current Delta Route changes
functions/__server.func changed 10.36 MB 10.56 MB +203.8 kB ⚠️ none
functions/.well-known/workflow/v1/flow.func changed 10.36 MB 10.56 MB +203.8 kB ⚠️ none

eve init install

Metric Baseline Current Delta
Installed footprint 116.11 MB 116.13 MB +15.1 kB ⚠️
Installed packages 113 113 0
dependencies 4 4 0
devDependencies 2 2 0
Dependency package bytes 48.72 MB 48.73 MB +15.1 kB ⚠️
devDependency package bytes 5.04 MB 5.04 MB 0 B ➖
Build Metadata
  • Preset: vercel
  • Nitro: nitro@3.0.260903-beta
  • Output directory: apps/fixtures/weather-agent/.vercel/output
  • Build metadata timestamp: 2026-09-06T23:21:55.152Z
  • Route aliases: 18 public, 1 internal (19 total aliases)
  • Vercel routes in config: 21
  • Severity legend: 🔴 dominant/large, 🟠 notable, 🟡 watch, ⚪ small
Package Drill-Down

Package Details

  • Package: eve@0.52.2
  • Package directory: packages/eve
  • Tarball: 8.65 MB (eve-0.52.2.tgz)
  • Unpacked payload: 32.61 MB across 3857 published files
  • Installed footprint: 77.69 MB across 7755 installed files
  • Installed root package: 31.18 MB
  • Installed dependencies: 46.51 MB
  • Installed package instances: 33
  • Distinct installed package names: 32
  • Installed dependency edges: 51
  • Installed optional peer edges: 7
  • Runtime dependencies: 2
  • Peer dependencies: 5 (4 optional)

Installed footprint is measured from an isolated temporary npm install of the packed tarball.
Graph metrics read only package.json files in package directories directly beneath a node_modules boundary, including nested boundaries. Each directory is one package instance; distinct names come from those manifests. Dependency edges count each unique name in dependencies or optionalDependencies per instance; optional peer edges count peerDependencies marked optional.

Heavy installed dependencies

  • eve: 31.18 MB (40.1%)
  • @rolldown/binding-linux-x64-gnu: 19.31 MB (24.9%)
  • ai: 7.01 MB (9.0%)
  • zod: 6.41 MB (8.3%)
  • undici: 3.51 MB (4.5%)
Publish payload breakdown
Published file size
🔴 dist/src/compiled/shadcn-registry/index.js       [#############...........] 9.76 MB 29.9%
🟠 dist/src/compiled/@photon-ai/chat-adapter-ime... [###.....................] 2.27 MB 7.0%
🟠 dist/src/compiled/@ai-sdk/code-mode/index.js     [#.......................] 1.03 MB 3.1%
🟡 dist/src/compiled/@vercel/blob/index.js          [#.......................] 901.4 kB 2.8%
🟡 dist/src/compiled/_chunks/workflow/signal-exi... [#.......................] 514.6 kB 1.6%
🔴 Other published files                            [########################] 18.14 MB 55.6%
Installed footprint breakdown
Installed package size
🔴 eve                             [########################] 31.18 MB 40.1%
🔴 @rolldown/binding-linux-x64-gnu [###############.........] 19.31 MB 24.9%
🔴 ai                              [#####...................] 7.01 MB 9.0%
🔴 zod                             [#####...................] 6.41 MB 8.3%
🟠 undici                          [###.....................] 3.51 MB 4.5%
🟠 nitro                           [#.......................] 1.89 MB 2.4%
🔴 Other installed packages        [######..................] 8.36 MB 10.8%
Runtime dependencies (2)
Package Range Notes
nitro 3.0.260903-beta
undici 8.9.0
Peer dependencies (5)
Package Range Notes
@opentelemetry/api ^1.0.0 optional peer
ai catalog:
braintrust ^3.0.0 optional peer
just-bash ^3.1.0 optional peer
microsandbox ^0.5.0 optional peer
eve init install drill-down

eve init install details

  • Command: eve init my-agent
  • Package manager: npm
  • Installed footprint: 116.13 MB across 9651 installed files
  • Installed packages: 113 total (107 transitive-only)
  • dependencies: 4 direct packages totaling 48.73 MB
  • devDependencies: 2 direct packages totaling 5.04 MB
  • Other transitive package files: 62.35 MB

Installed footprint is measured from an isolated temporary eve init my-agent using the current packed eve tarball.

Heavy installed dependencies

  • eve: 31.18 MB (26.8%)
  • @typescript/typescript-linux-x64: 27.95 MB (24.1%)
  • @rolldown/binding-linux-x64-gnu: 19.31 MB (16.6%)
  • zod: 10.37 MB (8.9%)
  • ai: 7.01 MB (6.0%)
Installed footprint breakdown
Installed package size
🔴 eve                              [########################] 31.18 MB 26.8%
🔴 @typescript/typescript-linux-x64 [######################..] 27.95 MB 24.1%
🔴 @rolldown/binding-linux-x64-gnu  [###############.........] 19.31 MB 16.6%
🔴 zod                              [########................] 10.37 MB 8.9%
🔴 ai                               [#####...................] 7.01 MB 6.0%
🟠 undici                           [###.....................] 3.51 MB 3.0%
🔴 Other installed packages         [#############...........] 16.79 MB 14.5%
dependencies (4)
Package Range Installed size Share
@vercel/connect 1.0.0 167.9 kB 0.1%
ai ^7.0.82 7.01 MB 6.0%
eve file:eve-0.52.2.tgz 31.18 MB 26.8%
zod 4.5.4 10.37 MB 8.9%
devDependencies (2)
Package Range Installed size Share
@types/node 24.x 2.54 MB 2.2%
typescript 7.0.2 2.50 MB 2.2%
Function Drill-Down

Payload Size Graph

Unique function payload size and share of total
🔴 functions/.well-known/workflow/v1/flow.func     [########################] 10.56 MB 50.0%
🔴 functions/__server.func                         [########################] 10.56 MB 50.0%

Top Function Payloads

🟠 functions/.well-known/workflow/v1/flow.func • 1 public route • 10.56 MB
Metric Value
Public routes /.well-known/workflow/v1/flow
Runtime nodejs24.x
Handler index.mjs
Payload 10.56 MB
Function files 10.56 MB across 112 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.51 MB (23.8%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                        [############............] 2.51 MB 23.8%
🟡 _libs/undici.mjs                 [#####...................] 980.8 kB 9.3%
🟡 _chunks/esm-Fqlolk7e.mjs         [###.....................] 723.3 kB 6.8%
🟡 _chunks/chatgpt-model.mjs        [###.....................] 697.1 kB 6.6%
🟡 _chunks/signal-exit-Dsy-TT0V.mjs [###.....................] 616.2 kB 5.8%
🔴 Other bundled files              [########################] 5.03 MB 47.7%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x",
  "maxDuration": "max",
  "experimentalTriggers": [
    {
      "type": "queue/v2beta",
      "topic": "__eve776561746865722d6167656e74_wkf_workflow_*",
      "consumer": "default",
      "retryAfterSeconds": 5,
      "initialDelaySeconds": 0
    }
  ],
  "environment": {
    "WORKFLOW_PRECONDITION_GUARD": "1"
  }
}

🟠 functions/__server.func • 17 public routes, 1 internal alias • 10.56 MB
Metric Value
Public routes /
/.well-known/workflow/v1/webhook/[token]
/eve/v1/activity/[token]
/eve/v1/callback/[token]
/eve/v1/connections/[name]/callback/[attemptId]/[token]
/eve/v1/connections/[name]/callback/[token]
/eve/v1/health
/eve/v1/info
/eve/v1/session
/eve/v1/session/[parentSessionId]/subagents/[callId]/[childSessionId]/stream
/eve/v1/session/[sessionId]
/eve/v1/session/[sessionId]/cancel
/eve/v1/session/[sessionId]/clear
/eve/v1/session/[sessionId]/compact
/eve/v1/session/[sessionId]/reset
/eve/v1/session/[sessionId]/stream
/eve/v1/task-input/[token]
Internal aliases /__server
Runtime nodejs24.x
Handler index.mjs
Payload 10.56 MB
Function files 10.56 MB across 112 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.51 MB (23.8%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                        [############............] 2.51 MB 23.8%
🟡 _libs/undici.mjs                 [#####...................] 980.8 kB 9.3%
🟡 _chunks/esm-Fqlolk7e.mjs         [###.....................] 723.3 kB 6.8%
🟡 _chunks/chatgpt-model.mjs        [###.....................] 697.1 kB 6.6%
🟡 _chunks/signal-exit-Dsy-TT0V.mjs [###.....................] 616.2 kB 5.8%
🔴 Other bundled files              [########################] 5.03 MB 47.7%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x"
}

Build Timing: e2e/fixtures/agent-tools-sandbox

This is an informational timing measurement inside eve build, from preflight through publication. Output-size measurement and profile writing are excluded.

Build mode: deployable Vercel build with sandbox template prewarm included.

  • Build pipeline: 5.99 s -> 6.04 s (+47.8 ms) vs main (4b5fad4).
  • Timing is informational: shared GitHub runners are too variable for a hard timing budget.
Detailed phase timings vs `main (4b5fad4)`
Phase Baseline Current Delta
extension.check 15.2 ms 15.5 ms +0.3 ms
project.resolve 0.4 ms 0.4 ms 0.0 ms
workspace.create 0.6 ms 0.6 ms 0.0 ms
host.prepare 548.9 ms 512.5 ms -36.4 ms
vercel.service-prefix.resolve 1.9 ms 2.2 ms +0.3 ms
nitro.create 557.9 ms 591.5 ms +33.6 ms
sandbox.prewarm 288.2 ms 265.1 ms -23.1 ms
nitro.cache.prepare 0.2 ms 0.3 ms +0.1 ms
nitro.prepare 0.7 ms 0.8 ms +0.1 ms
nitro.public-assets 0.8 ms 0.7 ms -0.1 ms
nitro.prerender 0.5 ms 0.5 ms 0.0 ms
nitro.bundle 4.52 s 4.60 s +70.5 ms
nitro.cache.write 0.3 ms 0.3 ms 0.0 ms
vercel.workflow-function.materialize 42.5 ms 44.7 ms +2.2 ms
agent-summary.emit 0.7 ms 0.8 ms +0.1 ms
nitro.close 0.1 ms 0.2 ms +0.1 ms
output.publish 3.2 ms 3.6 ms +0.4 ms
workspace.remove 2.0 ms 1.8 ms -0.2 ms

Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
…p-authorization

Signed-off-by: Rui Conti <ruiconti@gmail.com>

# Conflicts:
#	packages/eve/extension-contracts/compatibility/tool/v29.ts
#	packages/eve/extension-contracts/reports/tool/v30.json
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
@vercel
vercel Bot temporarily deployed to Preview – eve-pkg September 6, 2026 21:39 Inactive
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants