Skip to content

feat(files): integrate Project files with the browser and Mothership - #8781

Draft
mzxchandra wants to merge 27 commits into
codex/project-filesfrom
codex/project-files-product
Draft

mzxchandra wants to merge 27 commits into
codex/project-filesfrom
codex/project-files-product

Conversation

@mzxchandra

Copy link
Copy Markdown
Contributor

Summary

  • Add Project Files browser/editor integration on the shared file backend: owner-qualified navigation, folders, history, sharing, copy destinations, previews and collaborative Markdown editing.
  • Put Projects at the root of organization resource pickers; show environments and shared files beneath each Project. Preserve canonical ownership for search, mentions, clipboard context, embedded panels and chat reloads.
  • Gate Project roots behind the existing Project release flag and shared-file discovery behind the Project-files gate. With the release flag off, users retain workspace pickers. These surfaces remain unreleased until the Project UI rollout.
  • Add Sim-side Mothership Project discovery, explicit file-owner context and native CLI dispatch, with current delegated authorization, consumer capability negotiation, recovery and secret provenance. Keep chat ownership and workflow execution files unchanged.
  • Reconcile live list changes in embedded panels, and keep Project inventories in the query cache instead of duplicated component state.

Stacked on #8610, above #8609 and #8590, with #8762 as the lifecycle prerequisite. Pairs with Mothership #594. Keep the feature disabled until compatible app/realtime/background consumers and the companion worker are deployed. No migrations are added here.

Type of Change

  • New feature

Testing

  • Integrated product acceptance: 305 real-Postgres checks and 23 two-browser realtime checks across workspace/Project edits, concurrency, reload/reconnect, navigation, read-only enforcement and live permission changes.
  • Project picker: canonical root/file selection, nested hierarchy, search deduplication, keyboard/chip behavior, seven database context/authorization checks and six release-on/off browser checks.
  • Embedded panel: selected-text Add to Chat and archive invalidation without reloading; persisted organization chat restores its owner-qualified file panel.
  • Actual model run: Project discovery/read/write/copy, explicit-owner denials, clarification-based restricted-source handling, provenance preservation, worker restart/continuation and settled billing. A warm read/set-content/read updated the open browser editor immediately. A separate cold dev-route timeout recovered through the existing durable outbox retry, invoked explicitly because the local harness has no recurring outbox worker.
  • Final delta: 58 focused tests, app-only type check, formatting, generated artifacts and all 58 audits pass. Earlier handoff regressions have independent negative controls. Full-repository validation runs in exact-head CI.

The worker currently supports full-content replacement for Project files; targeted files edit remains unsupported. Local model verification exercised the supported operation. Remote Python/XLSX generation is not claimed as tested here.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Relevant tests updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 8, 2026 11:55pm UTC

Request Review

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 209 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/api/contracts/mothership-resource-tools.ts
Comment thread apps/sim/lib/mothership/resources/presentation.ts Outdated
Comment thread apps/sim/hooks/queries/utils/file-browser-owner-adapters.ts Outdated
Comment thread apps/sim/app/workspace/[workspaceId]/home/hooks/stream/handle-resource-event.ts Outdated
Comment thread apps/sim/app/projects/[projectId]/files/[fileId]/page.tsx Outdated
Comment thread apps/sim/hooks/use-invalidation-room.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High impact] The latest changes appear safe to merge; the loading check now matches which Project mentions users can select.

Summary

Adds Project files to the browser and Mothership while keeping each file’s owner explicit.

  • Supports Project file navigation, editing, previews, history, sharing, and copying.
  • Adds Project discovery and file commands with current access checks and protected-value tracking.
  • The latest change stops waiting for Project mentions when they cannot be selected. No new behavioral issue was found.
  • mzxchandra accepted the retained denial-before-dispatch, realtime subscriber, and single-dispatch test assertions because they catch unauthorized work, duplicate delivery, and repeated writes.
  • Previous threads were unnumbered, so previousFindings has no numbered entries.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Browser[File browser and chat panels] --> Owner[Explicit file owner]
  Mothership[Mothership file commands] --> Owner
  Owner --> Workspace[Workspace file operations]
  Owner --> Project[Project file operations]
  Workspace --> Access[Current access checks]
  Project --> Access
  Access --> Files[Shared file backend]
  Files --> Realtime[Live cache and editor updates]
  Realtime --> Browser
Loading

Reviews (17) · Last reviewed commit: "fix(project-files): gate pending mention..." · Reviewed by Greptile

Comment thread apps/sim/app/workspace/[workspaceId]/files/hooks/use-project-file-upload.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 209 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/app/workspace/[workspaceId]/files/hooks/use-file-upload-drop.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 209 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Turn on auto-fix | Re-trigger cubic

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/app/workspace/[workspaceId]/home/components/mothership-view/mothership-view.tsx">

<violation number="1" location="apps/sim/app/workspace/[workspaceId]/home/components/mothership-view/mothership-view.tsx:142">
P2: This lookup runs for persisted Project tabs even when `projects` or `project-files` is disabled, bypassing the separate release gates. Gate Project lookups and rendering on both flags.

(Based on your team's feedback about gating Project lookups.)</violation>
</file>

Comment thread apps/sim/lib/mothership/agent-cli/project-file-upload-transport.ts
Comment thread apps/sim/hooks/queries/workspace-files.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

Validation for the new review fixes:

  • 29 focused UI/query tests passed; mention rollout regressions failed before the fix, and each Project-tagging guard was independently checked.
  • 29 PostgreSQL provenance/upload integration tests passed on a freshly migrated disposable database. Secret-bearing upload metadata was rejected before session creation; safe uploads and callback leases remained valid. The corrected callback destination fixture also passed.
  • Lint, all 58 audits, committed-artifact generators, docs manifest, and actual-base block registry checks passed.
  • Live browser acceptance on 1ae209e passed: archiving a Project document removed its cached embedded editor, disabled delivery actions, returned 404 for metadata, and retained its archived database row. The owned app/relay/database services were cleaned up.

Physical provider-backed worker/CLI/model/callback acceptance remains open pending authorized provider credentials, a compatible template/snapshot, and a sandbox-reachable callback. The live browser result does not claim that provider coverage. This PR remains draft.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 227 files

Confidence score: 5/5

  • The Redis-enabled scenario in project-file-write-transport.integration.ts leaves stale upload_session rows because deleting the fixture file and user does not cascade. Delete the session during teardown.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/mothership/agent-cli/project-file-write-transport.integration.ts">

<violation number="1" location="apps/sim/lib/mothership/agent-cli/project-file-write-transport.integration.ts:691">
P3: The Redis-enabled scenario leaves its completed `upload_session` behind while deleting the fixture file and user; these columns have no cascading foreign keys, so every run leaves stale test data. Delete sessions for `f.userId` during teardown.</violation>
</file>

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/mothership/agent-cli/project-file-upload-transport.ts
@mzxchandra

Copy link
Copy Markdown
Contributor Author

Merged the updated backend parent, preserving the Project file fixes. The incoming change is confined to 12 table files; there is no database schema or migration delta.

Validation: nine affected table tests, two Project-tag state regressions (with independent failing guard-removal controls), and the Redis-enabled callback integration test on a fresh database passed. Worker contract sync and the complete 344-command CLI inventory pass against this combined tree. Lint, 58 audits, generators, docs manifest and actual-base block registry checks pass.

For the upload-transport review, the installed embedded Project CLI successfully transferred exact bytes to real same-origin and different-origin HTTP receivers while its identity transport accepted only Project control requests. Byte transfer uses global fetch and does not pass through the Project control scope check. Fixture upload-session cleanup was fixed.

The earlier live archive browser proof remains valid for the unchanged Project file implementation. Physical provider-backed acceptance remains open pending authorized credentials, a compatible template/snapshot and a sandbox-reachable callback. Fresh exact-head CI and both reviews are requested; this PR remains draft.

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 227 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/mothership/chat/project-file-context.integration.ts
Comment thread apps/sim/app/workspace/[workspaceId]/files/components/file-detail/navigation.tsx Outdated
Comment thread apps/sim/lib/uploads/client/download.ts
Comment thread apps/sim/lib/mothership/agent-cli/project-file-grep.ts
Comment thread apps/sim/app/workspace/[workspaceId]/home/home.tsx
Comment thread apps/sim/app/o/[organizationId]/home/organization-home.test.tsx Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 229 files

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

View guided diff | Re-trigger cubic

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 229 files

Confidence score: 3/5

  • resource-content.tsx can apply workspace preview text to the wrong collaborative Project document when file IDs overlap. Keep preview state off Project files unless ownership is verified.
  • mothership-assistant-tools.ts rejects valid non-UUID project IDs as nextCursor, so callers can’t fetch the next page. Accept a nonempty string to match the project-list contract.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/api/contracts/mothership-assistant-tools.ts">

<violation number="1" location="apps/sim/lib/api/contracts/mothership-assistant-tools.ts:352">
P2: `listProjects` returns a project ID as `nextCursor`, but this UUID constraint rejects valid non-UUID IDs and prevents following that page. Accept a nonempty string, matching the project-list contract.</violation>
</file>

<file name="apps/sim/app/workspace/[workspaceId]/home/components/mothership-view/components/resource-content/resource-content.tsx">

<violation number="1" location="apps/sim/app/workspace/[workspaceId]/home/components/mothership-view/components/resource-content/resource-content.tsx:317">
P1: This sends owner-unqualified preview text to a Project file based only on a matching file ID; a workspace preview can therefore update the wrong collaborative document when IDs overlap. Keep preview state off Project files until the session carries and matches its owner.

(Based on your team's feedback about Project preview ownership.)</violation>
</file>

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

fileId={resource.id}
downloadSourceRef={downloadSourceRef}
previewMode={previewMode}
streamingContent={previewSession?.fileId === resource.id ? textStreamingContent : undefined}

@cubic-dev-ai cubic-dev-ai Bot Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: This sends owner-unqualified preview text to a Project file based only on a matching file ID; a workspace preview can therefore update the wrong collaborative document when IDs overlap. Keep preview state off Project files until the session carries and matches its owner.

(Based on your team's feedback about Project preview ownership.)

View Feedback

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At apps/sim/app/workspace/[workspaceId]/home/components/mothership-view/components/resource-content/resource-content.tsx, line 317:

<comment>This sends owner-unqualified preview text to a Project file based only on a matching file ID; a workspace preview can therefore update the wrong collaborative document when IDs overlap. Keep preview state off Project files until the session carries and matches its owner.

(Based on your team's feedback about Project preview ownership.) </comment>

<file context>
@@ -291,6 +297,34 @@ export const ResourceContent = memo(function ResourceContent({
+        fileId={resource.id}
+        downloadSourceRef={downloadSourceRef}
+        previewMode={previewMode}
+        streamingContent={previewSession?.fileId === resource.id ? textStreamingContent : undefined}
+        isAgentEditing={isAgentEditing}
+        streamIsIncremental={streamIsIncremental}
</file context>
Fix with cubic


/** Project discovery accepts pagination only; the conversation determines the accessible scope. */
export const listUserProjectsInputSchema = z.object({
cursor: z.string().uuid().optional(),

@cubic-dev-ai cubic-dev-ai Bot Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: listProjects returns a project ID as nextCursor, but this UUID constraint rejects valid non-UUID IDs and prevents following that page. Accept a nonempty string, matching the project-list contract.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At apps/sim/lib/api/contracts/mothership-assistant-tools.ts, line 352:

<comment>`listProjects` returns a project ID as `nextCursor`, but this UUID constraint rejects valid non-UUID IDs and prevents following that page. Accept a nonempty string, matching the project-list contract.</comment>

<file context>
@@ -347,8 +347,22 @@ export const listWorkspacesInputSchema = z.object({
 
+/** Project discovery accepts pagination only; the conversation determines the accessible scope. */
+export const listUserProjectsInputSchema = z.object({
+  cursor: z.string().uuid().optional(),
+  limit: z.number().int().min(1).max(100).default(50),
+})
</file context>
Suggested change
cursor: z.string().uuid().optional(),
cursor: z.string().min(1).optional(),
Fix with cubic

This branch was previously deployed

1 inactive deployment
Preview — 64a46520 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant