Skip to content

feat(eve): authorize workflow tool steps - #3073

Open
ruiconti wants to merge 24 commits into
mainfrom
ruiconti/workflow-step-authorization
Open

feat(eve): authorize workflow tool steps#3073
ruiconti wants to merge 24 commits into
mainfrom
ruiconti/workflow-step-authorization

Conversation

@ruiconti

@ruiconti ruiconti commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Summary

No Connect-backed tool could be a workflow: ctx.getToken and ctx.requireAuth threw in workflow bodies, and steps only saw process.env. Both now work inside a "use step" helper that receives ctx as a direct argument. Sign-in ends the step attempt, the workflow parks on its own callback hook, and after the callback eve retries that step and continues the body. Tokens never enter durable history. Related to #47 and #2997.

What

  • Workflow steps, ordinary tools, approval responses, and connection_search now share one authorization implementation (createAuthorizationExecution): requester identity, token cache, callback completion, and the rejected-after-sign-in guard. About 400 lines of duplicated park/loop-guard code are gone.
  • The compiler registers an authorization twin for each authored step and routes context-bearing calls to it. Native calls and SDK built-ins keep the plain proxy. Only modules that can define workflow tools get the twin; eve's own steps are untouched.
  • Older session drivers can't display auth events raised by a workflow task itself, so a step would wait on a callback no channel renders. The driver now advertises support in its command hook metadata (next to sessionInboxWireVersion); background dispatch reads it and fails fast with "start a new session" when absent. Blocking workflows are unaffected.
  • The busy-worker steering eval waits for an approval gate instead of a five-second timer. It's here because the standalone PR (test(eve): hold busy-worker until steering begins #3139) was closed in favor of one change.

Data flow

flow before after
step needs a token ctx.getToken throws; step reads process.env step calls ctx.getToken(provider); auth capability rebuilt inside the step under the launcher's identity
sign-in required n/a step returns a signal → workflow reports authorization.required to its owner, task goes input_required, waits on a step-owned hook → callback retries the step
callback completion on retry n/a completion marker under eve.authorization.<stepId>.<attemptId>; a later retry reads the token from the provider store instead of re-exchanging the code
old-driver detection n/a producer reads workflowTaskAuthorization from the driver's command hook metadata

Why this shape

The twin step id is the discriminator because a symbol-marked envelope wouldn't survive the durable log; authored arguments can never select the auth context. Hook metadata over a SessionCapabilities field: the field needed a buildRunContext override so clients couldn't grant it and a workflowEntry mutation to set it, and the metadata path already exists for the wire version. Cost is one hook read per background dispatch.

Step input is recorded in the run log and, after sign-in, includes the provider's callback parameters (one-time code), same as an agent turn today. Docs say so.

Validation

  • pnpm exec vitest run --config vitest.unit.config.ts: 8232 passed, 1 skipped, 2 failed — the two macOS telemetry XDG-path assertions that also fail on main locally.
  • Focused unit: workflow-bundle, structural file-length, session-command-inbox, tools/workflow, harness, runtime-context, workflow-entry, tasks → 72 files, 1116 passed.
  • pnpm exec vitest run --config vitest.integration.config.ts for workflow-tool-run, connection-search-authorization, tool-execution → 49 passed. Covers owner routing, callback retry via the completion marker, cancellation, the missing-driver-support boundary, and the real driver's metadata on the positive path. Not a two-deployment reproduction.
  • pnpm fmt, pnpm lint, tsc -p tsconfig.json --noEmit (packages/eve), pnpm docs:check, pnpm guard:invariants pass.
  • E2E in CI: agent-workflow-tools fixture runs the real ctx.getToken/requireAuth against a fixture HTTP service (implicit, explicit after 401, and rejected-after-sign-in), plus connection_search authorization boundaries.
  • Not run locally: scenario tier, pnpm build, pnpm update:extension-contracts (contracts were regenerated in an earlier commit on this branch).

Checklist

  • This change was requested or approved by a maintainer
  • I ran the relevant checks from CONTRIBUTING.md
  • I added tests and documentation where relevant
  • I added a changeset if this touches the published eve package
  • DCO sign-off passes for every commit (git commit --signoff)

Signed-off-by: Rui Conti <ruiconti@gmail.com>
@vercel

vercel Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
eve-docs Ready Ready Preview, v0 Sep 8, 2026 4:38pm UTC
eve-docs-4759 Ready Ready Preview, v0 Sep 8, 2026 4:38pm UTC
eve-pkg Ready Ready Preview, v0 Sep 8, 2026 4:38pm UTC

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Bundle + Package Summary: apps/fixtures/weather-agent

Key takeaways

  • No notable deltas vs main (9cb899d).

Delta vs main (9cb899d)

Area Metric Baseline Current Delta
Package Packed tarball 8.66 MB 8.67 MB +4.8 kB ⚠️
Package Unpacked publish size 32.63 MB 32.65 MB +17.4 kB ⚠️
Package Installed footprint 77.71 MB 77.73 MB +17.4 kB ⚠️
Package Published files 3853 3863 +10
Package Installed files 7751 7761 +10
Package Installed package instances 33 33 0
Package Distinct installed package names 32 32 0
Package Installed dependency edges 51 51 0
Package Installed optional peer edges 7 7 0
Runtime Unique function payloads 2 2 0
Runtime Total function bytes 20.74 MB 20.75 MB +12.9 kB ⚠️
Runtime Public routes 18 18 0
Changed function payloads vs main (9cb899d) (2)
Function Status Baseline Current Delta Route changes
functions/__server.func changed 10.37 MB 10.37 MB +6.5 kB ⚠️ none
functions/.well-known/workflow/v1/flow.func changed 10.37 MB 10.38 MB +6.5 kB ⚠️ none

eve init install

Metric Baseline Current Delta
Installed footprint 116.15 MB 116.17 MB +17.4 kB ⚠️
Installed packages 113 113 0
dependencies 4 4 0
devDependencies 2 2 0
Dependency package bytes 48.76 MB 48.78 MB +17.4 kB ⚠️
devDependency package bytes 5.04 MB 5.04 MB 0 B ➖
Build Metadata
  • Preset: vercel
  • Nitro: nitro@3.0.260903-beta
  • Output directory: apps/fixtures/weather-agent/.vercel/output
  • Build metadata timestamp: 2026-09-08T16:39:35.647Z
  • Route aliases: 18 public, 1 internal (19 total aliases)
  • Vercel routes in config: 21
  • Severity legend: 🔴 dominant/large, 🟠 notable, 🟡 watch, ⚪ small
Package Drill-Down

Package Details

  • Package: eve@0.52.2
  • Package directory: packages/eve
  • Tarball: 8.67 MB (eve-0.52.2.tgz)
  • Unpacked payload: 32.65 MB across 3863 published files
  • Installed footprint: 77.73 MB across 7761 installed files
  • Installed root package: 31.22 MB
  • Installed dependencies: 46.51 MB
  • Installed package instances: 33
  • Distinct installed package names: 32
  • Installed dependency edges: 51
  • Installed optional peer edges: 7
  • Runtime dependencies: 2
  • Peer dependencies: 5 (4 optional)

Installed footprint is measured from an isolated temporary npm install of the packed tarball.
Graph metrics read only package.json files in package directories directly beneath a node_modules boundary, including nested boundaries. Each directory is one package instance; distinct names come from those manifests. Dependency edges count each unique name in dependencies or optionalDependencies per instance; optional peer edges count peerDependencies marked optional.

Heavy installed dependencies

  • eve: 31.22 MB (40.2%)
  • @rolldown/binding-linux-x64-gnu: 19.31 MB (24.8%)
  • ai: 7.01 MB (9.0%)
  • zod: 6.41 MB (8.3%)
  • undici: 3.51 MB (4.5%)
Publish payload breakdown
Published file size
🔴 dist/src/compiled/shadcn-registry/index.js       [#############...........] 9.76 MB 29.9%
🟠 dist/src/compiled/@photon-ai/chat-adapter-ime... [###.....................] 2.27 MB 7.0%
🟠 dist/src/compiled/@ai-sdk/code-mode/index.js     [#.......................] 1.03 MB 3.1%
🟡 dist/src/compiled/@vercel/blob/index.js          [#.......................] 901.4 kB 2.8%
🟡 dist/src/compiled/_chunks/workflow/signal-exi... [#.......................] 514.6 kB 1.6%
🔴 Other published files                            [########################] 18.18 MB 55.7%
Installed footprint breakdown
Installed package size
🔴 eve                             [########################] 31.22 MB 40.2%
🔴 @rolldown/binding-linux-x64-gnu [###############.........] 19.31 MB 24.8%
🔴 ai                              [#####...................] 7.01 MB 9.0%
🔴 zod                             [#####...................] 6.41 MB 8.3%
🟠 undici                          [###.....................] 3.51 MB 4.5%
🟠 nitro                           [#.......................] 1.89 MB 2.4%
🔴 Other installed packages        [######..................] 8.36 MB 10.8%
Runtime dependencies (2)
Package Range Notes
nitro 3.0.260903-beta
undici 8.9.0
Peer dependencies (5)
Package Range Notes
@opentelemetry/api ^1.0.0 optional peer
ai catalog:
braintrust ^3.0.0 optional peer
just-bash ^3.1.0 optional peer
microsandbox ^0.5.0 optional peer
eve init install drill-down

eve init install details

  • Command: eve init my-agent
  • Package manager: npm
  • Installed footprint: 116.17 MB across 9657 installed files
  • Installed packages: 113 total (107 transitive-only)
  • dependencies: 4 direct packages totaling 48.78 MB
  • devDependencies: 2 direct packages totaling 5.04 MB
  • Other transitive package files: 62.35 MB

Installed footprint is measured from an isolated temporary eve init my-agent using the current packed eve tarball.

Heavy installed dependencies

  • eve: 31.22 MB (26.9%)
  • @typescript/typescript-linux-x64: 27.95 MB (24.1%)
  • @rolldown/binding-linux-x64-gnu: 19.31 MB (16.6%)
  • zod: 10.37 MB (8.9%)
  • ai: 7.01 MB (6.0%)
Installed footprint breakdown
Installed package size
🔴 eve                              [########################] 31.22 MB 26.9%
🔴 @typescript/typescript-linux-x64 [#####################...] 27.95 MB 24.1%
🔴 @rolldown/binding-linux-x64-gnu  [###############.........] 19.31 MB 16.6%
🔴 zod                              [########................] 10.37 MB 8.9%
🔴 ai                               [#####...................] 7.01 MB 6.0%
🟠 undici                           [###.....................] 3.51 MB 3.0%
🔴 Other installed packages         [#############...........] 16.79 MB 14.5%
dependencies (4)
Package Range Installed size Share
@vercel/connect 1.0.0 167.9 kB 0.1%
ai ^7.0.82 7.01 MB 6.0%
eve file:eve-0.52.2.tgz 31.22 MB 26.9%
zod 4.5.4 10.37 MB 8.9%
devDependencies (2)
Package Range Installed size Share
@types/node 24.x 2.54 MB 2.2%
typescript 7.0.2 2.50 MB 2.1%
Function Drill-Down

Payload Size Graph

Unique function payload size and share of total
🔴 functions/.well-known/workflow/v1/flow.func     [########################] 10.38 MB 50.0%
🔴 functions/__server.func                         [########################] 10.37 MB 50.0%

Top Function Payloads

🟠 functions/.well-known/workflow/v1/flow.func • 1 public route • 10.38 MB
Metric Value
Public routes /.well-known/workflow/v1/flow
Runtime nodejs24.x
Handler index.mjs
Payload 10.38 MB
Function files 10.38 MB across 112 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.33 MB (22.4%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                        [###########.............] 2.33 MB 22.4%
🟡 _libs/undici.mjs                 [#####...................] 980.8 kB 9.5%
🟡 _chunks/esm-Fqlolk7e.mjs         [###.....................] 723.3 kB 7.0%
🟡 _chunks/chatgpt-model.mjs        [###.....................] 698.3 kB 6.7%
🟡 _chunks/signal-exit-Dsy-TT0V.mjs [###.....................] 616.2 kB 5.9%
🔴 Other bundled files              [########################] 5.03 MB 48.5%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x",
  "maxDuration": "max",
  "experimentalTriggers": [
    {
      "type": "queue/v2beta",
      "topic": "__eve776561746865722d6167656e74_wkf_workflow_*",
      "consumer": "default",
      "retryAfterSeconds": 5,
      "initialDelaySeconds": 0
    }
  ],
  "environment": {
    "WORKFLOW_PRECONDITION_GUARD": "1"
  }
}

🟠 functions/__server.func • 17 public routes, 1 internal alias • 10.37 MB
Metric Value
Public routes /
/.well-known/workflow/v1/webhook/[token]
/eve/v1/activity/[token]
/eve/v1/callback/[token]
/eve/v1/connections/[name]/callback/[attemptId]/[token]
/eve/v1/connections/[name]/callback/[token]
/eve/v1/health
/eve/v1/info
/eve/v1/session
/eve/v1/session/[parentSessionId]/subagents/[callId]/[childSessionId]/stream
/eve/v1/session/[sessionId]
/eve/v1/session/[sessionId]/cancel
/eve/v1/session/[sessionId]/clear
/eve/v1/session/[sessionId]/compact
/eve/v1/session/[sessionId]/reset
/eve/v1/session/[sessionId]/stream
/eve/v1/task-input/[token]
Internal aliases /__server
Runtime nodejs24.x
Handler index.mjs
Payload 10.37 MB
Function files 10.37 MB across 112 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.33 MB (22.4%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                        [###########.............] 2.33 MB 22.4%
🟡 _libs/undici.mjs                 [#####...................] 980.8 kB 9.5%
🟡 _chunks/esm-Fqlolk7e.mjs         [###.....................] 723.3 kB 7.0%
🟡 _chunks/chatgpt-model.mjs        [###.....................] 698.3 kB 6.7%
🟡 _chunks/signal-exit-Dsy-TT0V.mjs [###.....................] 616.2 kB 5.9%
🔴 Other bundled files              [########################] 5.03 MB 48.5%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x"
}

Build Timing: e2e/fixtures/agent-tools-sandbox

This is an informational timing measurement inside eve build, from preflight through publication. Output-size measurement and profile writing are excluded.

Build mode: deployable Vercel build with sandbox template prewarm included.

  • Build pipeline: 6.44 s -> 6.12 s (-322.6 ms) vs main (9cb899d).
  • Timing is informational: shared GitHub runners are too variable for a hard timing budget.
Detailed phase timings vs `main (9cb899d)`
Phase Baseline Current Delta
extension.check 0.8 ms 18.7 ms +17.9 ms
project.resolve 0.4 ms 3.6 ms +3.2 ms
workspace.create 0.6 ms 1.3 ms +0.7 ms
host.prepare 743.1 ms 520.9 ms -222.2 ms
vercel.service-prefix.resolve 2.2 ms 2.5 ms +0.3 ms
nitro.create 601.7 ms 596.8 ms -4.9 ms
sandbox.prewarm 472.8 ms 396.3 ms -76.5 ms
nitro.cache.prepare 0.3 ms 0.3 ms 0.0 ms
nitro.prepare 1.0 ms 0.8 ms -0.2 ms
nitro.public-assets 0.8 ms 0.8 ms 0.0 ms
nitro.prerender 0.5 ms 0.6 ms +0.1 ms
nitro.bundle 4.56 s 4.52 s -43.4 ms
nitro.cache.write 0.4 ms 0.4 ms 0.0 ms
vercel.workflow-function.materialize 51.7 ms 53.6 ms +1.9 ms
agent-summary.emit 0.8 ms 0.8 ms 0.0 ms
nitro.close 0.2 ms 0.1 ms -0.1 ms
output.publish 3.6 ms 3.8 ms +0.2 ms
workspace.remove 2.3 ms 2.4 ms +0.1 ms

Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
…p-authorization

Signed-off-by: Rui Conti <ruiconti@gmail.com>

# Conflicts:
#	packages/eve/extension-contracts/compatibility/tool/v29.ts
#	packages/eve/extension-contracts/reports/tool/v30.json
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
@ruiconti ruiconti changed the title feat(eve): share authorization with workflow tool steps feat(eve): authorize workflow tool steps Sep 8, 2026
@ruiconti
ruiconti changed the base branch from main to ruiconti/shared-authorization-runtime September 8, 2026 12:58
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Comment thread packages/eve/src/execution/tools/connection-search.ts
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Signed-off-by: Rui Conti <ruiconti@gmail.com>
Only authored modules and the package test fixtures register an authorization twin and route context-bearing calls to it; eve's own steps keep the plain Workflow proxy. The session driver advertises workflow-task authorization through its command hook metadata, next to the inbox wire version, instead of a SessionCapabilities field. Each challenge mints its own attempt id rather than reusing the hook token. Docs state that step input records the provider callback parameters.

Signed-off-by: Rui Conti <ruiconti@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants