paperclip/scripts
Dotta 13bae6fa21
fix: reject unsupported REST tool connections without stdio validation (#13346)
## Thinking Path

> - Paperclip manages AI agents and their connections.
> - Connection checks must use the configured transport.
> - The tool service treated every remaining transport as local stdio.
> - Anthropic's old REST method therefore failed with a templateId
error. A REST connection with a valid stdio template could incorrectly
pass.
> - Anthropic now has a supported AI-account flow. This pull request
removes its obsolete REST setup option and limits stdio checks to stdio
connections.
> - Users can connect an AI account, and existing unsupported
connections receive an accurate error.

## Linked Issues or Issue Description

Related: #13248 added the supported AI-account flow. Searches for
related REST health and templateId bugs found no duplicate fix.

**What happened?**

The Anthropic REST API-key connection showed `Local stdio MCP
connections must use an approved templateId`. Health checks and catalog
discovery both fell through to the local stdio path. A REST connection
with an approved template could report success and expose the template's
catalog without a REST integration.

**Expected behavior**

Only local stdio connections use command templates. Unsupported
transports return an accurate HTTP 422 error. New Anthropic accounts use
the supported runtime authentication flow.

**Steps to reproduce**

1. Check out the test-only commit `924e6e85a` in a separate worktree and
install dependencies.
2. Run `pnpm exec vitest run packages/shared/src/app-definitions.test.ts
server/src/__tests__/tool-access-service.test.ts -t 'unsupported
REST|obsolete Anthropic'`.
3. The tests exercise saved Anthropic REST configuration and an
unsupported REST connection containing an approved stdio template. They
cover health checks and catalog discovery separately.
4. Run the same tests on the fix commit. They pass. The full affected
files also pass.

**Paperclip version or commit**

Reproduced against master `6cef9743c`.

**Deployment mode**

Server transport handling. Reproduced with an isolated embedded
PostgreSQL test database. No provider account or live credentials are
required.

## What Changed

- Restrict stdio health checks and tool discovery to `local_stdio`.
- Return and audit `tool_connection_transport_unsupported` with HTTP 422
for unsupported tool transports.
- Remove Anthropic's obsolete REST method from the generated catalog and
its durable ingestion source. Keep its subscription and API-key AI
methods.
- Cover the reported error, false-success case, rejected obsolete setup,
connection removal, and the UI's AI-account submission path.
- Replace impossible reconnect forms for removed methods with supported
setup, while preserving connection removal.
- Preserve AI-versus-tool intent isolation for legacy requests and
reject new unsupported Anthropic tool requests.
- Document recovery for existing unsupported connections.

## Verification

- Clean-worktree red/green: the same command failed all six regression
cases at `924e6e85a` and passed all six at `4d3de9de0`. The failing run
includes the reported templateId error.
- Green: all 555 tests across the six affected test files passed.
- Recovery UI red/green: three added cases failed before the recovery
fix and passed afterward; all 200 tests across setup, detail, and
advanced controls passed.
- After the recovery UI update, UI typecheck/build and token gates
passed again.
- `pnpm -r typecheck` — passed.
- `pnpm build` — passed.
- `pnpm check:token-gates` — passed.
- Catalog regeneration — passed with the documented
`PAPERCLIP_CONTENT_TEMPLATES` override for the local capture corpus.
- Full CI on `69fb31fd4` — passed all general and serialized test
shards, browser shards, typecheck, build, runner verification, and
canary dry run:
https://github.com/paperclipai/paperclip/actions/runs/34726975425.
- The local serial `pnpm test:run` was stopped after the fixture
correction superseded that run; full-suite verification above comes from
CI. All 555 affected tests passed locally, including all 17
connection-intent tests after the correction.
- Greptile — 5/5, successful check on final commit `69fb31fd4`, no
unresolved findings.
- No live Anthropic validation was performed. The UI regression uses a
fake key and a mocked AI-account response.

## Risks

Existing obsolete REST connections remain in needs-attention state.
Users must add an account through the supported flow and remove the old
connection. Credentials and grants are not transferred automatically.
Removal remains covered. The specialized AgentMail and Composio paths
keep their existing behavior. There are no schema or permission changes.

## Model Used

OpenAI GPT-6 through Codex. The exact serving model ID and
context-window capacity are not exposed in this session. Used reasoning,
code editing, shell tools, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-12 19:26:58 -05:00
..
__tests__ ci: run release Runner protocol and Rust checks in parallel (#13326) 2026-09-12 11:33:20 -07:00
install-sh-fixtures
lib feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
mcp-fixtures fix: continue interrupted task conversations with bounded retries (#13237) 2026-09-11 12:16:04 -05:00
smoke feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
tests feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
acpx-patch-packaging.test.mjs fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162) 2026-09-10 11:35:33 -07:00
assert-cloud-image-sentry.mjs Install the declared Sentry server package into the hosted image (#12330) 2026-08-27 19:10:49 -07:00
assert-orphan-reaping.sh fix(docker): make tini PID 1 in the server image so adopted orphans are reaped (#12137) 2026-08-25 09:52:39 -07:00
backfill-issue-reference-mentions.ts
backup-db.sh
benchmark-skill-preparation.ts fix(skills): reuse validated runtime revisions during preparation (#13042) 2026-09-08 09:35:32 -05:00
bootstrap-npm-package.mjs
bootstrap-npm-package.test.mjs
build-npm.sh
build-standalone-public-packages.mjs
capture-pap-2351-binding-picker.mjs
chat-adapter-patch-packaging.test.mjs feat: add opt-in chat provider and data foundation (#13100) 2026-09-09 13:49:12 -05:00
check-docker-deps-stage.mjs
check-docker-runner-cache.sh fix(ci): reuse one available Cloud registry cache (#13334) 2026-09-12 13:20:18 -07:00
check-forbidden-tokens.mjs
check-module-boundaries.mjs refactor(server): move the admission half of the deferred wake state machine into the wake-queue module (#13136) 2026-09-10 00:55:48 -07:00
check-module-boundaries.test.mjs refactor(server): move the admission half of the deferred wake state machine into the wake-queue module (#13136) 2026-09-10 00:55:48 -07:00
check-no-git-push.mjs
check-no-git-push.test.mjs
check-node-version-policy.mjs
check-release-package-bootstrap.mjs
check-release-package-bootstrap.test.mjs
check-task-chat-motion.mjs
check-token-gates.mjs
clean-install-git.sh
clean-install-npm.sh
clean-onboard-git.sh
clean-onboard-npm.sh
clean-onboard-ref.sh
cli-bundled-npm-dependencies.mjs
cloud-readiness.mjs fix(ci): verify deployable cloud artifacts independently (#13192) 2026-09-10 21:08:29 -07:00
cloud-source-verification.mjs fix(ci): reuse cloud source verification for npm canaries (#13233) 2026-09-11 09:26:26 -07:00
cloud-source-verification.test.mjs fix(ci): reuse cloud source verification for npm canaries (#13233) 2026-09-11 09:26:26 -07:00
codemod-extract-colors.mjs
codemod-extract-misc.mjs
codemod-extract-sizes.mjs
codemod-extract-type.mjs
codemod-type-ladder.mjs
codex-acp-network-policy.test.mjs fix(adapters): prevent engine fallback and preserve usable runtime defaults (#13105) 2026-09-09 13:27:24 -05:00
create-github-release.sh
dev-both.mjs
dev-runner-native-binary.mjs feat(runner): integrate Codex native execution (#12616) 2026-08-31 22:51:17 -05:00
dev-runner-options.ts fix(dev): honor --data-dir isolation (#12193) 2026-08-26 09:08:31 -05:00
dev-runner-output.mjs
dev-runner-output.ts
dev-runner-paths.mjs
dev-runner-snapshot.mjs
dev-runner.mjs
dev-runner.ts fix(runner): recover native sessions across restarts (#12845) 2026-09-04 15:03:53 -05:00
dev-service-profile.ts
dev-service.ts fix(dev): honor --data-dir isolation (#12193) 2026-08-26 09:08:31 -05:00
discord-daily-digest.sh
docker-build-test.sh fix(docker): make tini PID 1 in the server image so adopted orphans are reaped (#12137) 2026-08-25 09:52:39 -07:00
docker-entrypoint.sh
docker-onboard-smoke.sh Follow the current onboarding arc in the release smoke (#12423) 2026-08-28 07:21:08 -07:00
docker-onboard-smoke.test.mjs Follow the current onboarding arc in the release smoke (#12423) 2026-08-28 07:21:08 -07:00
draft-stable-notes.sh feat(release): thorough notes skeletons — nest each PR's summary at creation (#12124) 2026-08-24 20:51:33 -07:00
draft-stable-notes.test.mjs feat(release): thorough notes skeletons — nest each PR's summary at creation (#12124) 2026-08-24 20:51:33 -07:00
e2e-install-lifecycle.sh
e2e-mcp-user-stories.mjs
e2e-shard-durations.json test(e2e): shorten and split Smoke Lab coverage (#12506) 2026-08-31 10:15:39 -05:00
e2e-shard.mjs feat(connections): connect services from native task feeds (#13058) 2026-09-08 15:55:26 -05:00
e2e-update-migrations.sh
ensure-plugin-build-deps.mjs fix(cli): recover abandoned workspace build locks (#13288) 2026-09-11 18:25:42 -05:00
ensure-workspace-package-links.ts
extract-proposed-events.mjs
extract-proposed-events.test.mjs
general-server-shard-durations.json refactor: remove automatic productivity reviews (#13263) 2026-09-11 15:46:35 -05:00
general-server-shard.mjs
generate-company-assets.ts
generate-feature-catalog.ts
generate-npm-package-json.mjs
generate-org-chart-images.ts
generate-org-chart-satori-comparison.ts
generate-plugin-package-json.mjs
generate-runner-api-reference.mjs fix(onboarding): make chief-of-staff hiring reliable (#13317) 2026-09-12 12:59:42 -05:00
generate-runner-experimental-api-metadata.mjs feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
generate-ui-package-json.mjs
ingest-app-definitions.mjs fix: reject unsupported REST tool connections without stdio validation (#13346) 2026-09-12 19:26:58 -05:00
install.sh
kill-agent-browsers.sh
kill-dev.sh
kill-vitest.sh
kill-workspaces.sh
link-plugin-dev-sdk.mjs
link-plugin-dev-sdk.test.js
measure-issue-chat-long-thread.mjs
migrate-inline-env-secrets.ts
paperclip-commit-metrics.ts
paperclip-issue-update.sh
prepare-bundled-package.mjs Build isolated preview artifacts for exact-source deployments (#13041) 2026-09-08 09:21:58 -05:00
prepare-server-ui-dist.sh
preview-artifacts.mjs fix(release): publish exact-source cloud migrators on merge (#13188) 2026-09-10 21:07:38 -07:00
preview-artifacts.test.mjs fix(ci): reuse one available Cloud registry cache (#13334) 2026-09-12 13:20:18 -07:00
provision-worktree-runtime.sh fix(scripts): silence pnpm DEP0169 at provisioning install call sites (#12228) 2026-08-26 10:42:13 -07:00
provision-worktree.sh fix(workspaces): preserve dependency provisioning failures (#13093) 2026-09-09 10:14:58 -05:00
release-lib.sh fix(release): skip lifecycle scripts for bundle staging (#12585) 2026-08-31 09:14:08 -05:00
release-lib.test.mjs fix(release): skip lifecycle scripts for bundle staging (#12585) 2026-08-31 09:14:08 -05:00
release-package-manifest.json
release-package-map.mjs
release-package-map.test.mjs
release-registry-versions.mjs
release-registry-versions.test.mjs
release.sh
repair-pr-prep-workspace-attachment.mjs
request-hot-restart.ts
rollback-latest.sh
run-typecheck-build-gaps.mjs
run-vitest-stable.mjs fix(ci): split release chat verification into test shards (#13198) 2026-09-10 20:30:30 -07:00
runner-api-eval-worker.ts feat: add experimental persistent agent chat (#13284) 2026-09-12 08:56:04 -05:00
screenshot-blocked-inbox.mjs
screenshot-file-viewer.mjs
screenshot-fork-flow.mjs
screenshot-notion-connect-flow.mjs
screenshot-one.mjs
screenshot-pap2373.mjs
screenshot-recovery-card.cjs
screenshot-subissues.mjs
screenshot-verdicts.mjs
screenshot.cjs
select-cloud-cache.mjs fix(ci): reuse one available Cloud registry cache (#13334) 2026-09-12 13:20:18 -07:00
select-cloud-cache.test.mjs fix(ci): reuse one available Cloud registry cache (#13334) 2026-09-12 13:20:18 -07:00
serialized-shard-durations.json ci: rebalance serialized tests with current suite durations (#13328) 2026-09-12 11:36:20 -07:00
serve-storybook-static.mjs
service-onboard-smoke.sh test(release-smoke): cover the background-service leg of onboarding (#12151) 2026-08-25 01:05:27 -07:00
service-onboard-smoke.test.mjs test(release-smoke): cover the background-service leg of onboarding (#12151) 2026-08-25 01:05:27 -07:00
storybook-visual-baseline.mjs
test-install-sh-docker.sh
test-line-shard.mjs fix(ci): split release chat verification into test shards (#13198) 2026-09-10 20:30:30 -07:00
verify-release-registry-state.mjs
verify-release-registry-state.test.mjs