feat(webapp): dashboard agent — UI - #4529
Conversation
… row The hand-built row stopped satisfying every column the authenticated-environment mapper reads, so both proxy cases failed. Stubbing the lookup keeps the fixture independent of the row's columns.
Route conflicts were the tab-title work meeting the agent page-context handle: both sides kept, duplicate meta exports resolved to pageMeta, duplicate imports merged with unused bindings dropped. Lockfile regenerated from the merged manifests.
…lowlist Replaces https://*.googleusercontent.com (a host with public write access) with CSP_IMG_SRC_ALLOWLIST: exact origins only, https outside development, deduplicated, bad entries warned about instead of failing the boot.
…ts message Classify a failed tool result locally into one of seven categories and send only the label; the message is dropped with every other free-text field. Unrecognised failures are unknown rather than guessed, and a bare string error field is now withheld too.
…the message withheld Also reuse the policy's errored-output check instead of a second copy of it.
…ack to its condition A per-condition fallback identified the condition rather than the submit, so a re-watch could replay a stale terminal outcome from the retention window.
A refusal that won the race kept the reserved watch id, so the user was told nothing was created while that watch stayed active.
…batch order A tick that could read nothing now moves the group's fairness key only, so a watch with a permanently broken reader stops crowding out the rest of an over-cap group. Dueness and the streak facts still follow the last real check.
…t-wide routes The environments and runs listings are project-wide, so an environment-scoped user-actor token could read every environment its user can reach. Both routes now resolve the claim into a mandatory filter, and a conflicting request filter is refused rather than overridden.
…ntity The direct PAT authentication path returned identity only, so a user-actor token reaching it (admin routes and other direct callers) lost its environment scope. The claims now ride on the authentication result itself.
…ed token can do A user-actor token declaring no scope cap could mint an environment JWT with any scopes it asked for. The exchange now clamps the minted scopes to the actor's own ability, so a capless token is read-only, and only mints for its claimed environment.
…ad of re-deciding it replay() re-ran subscribe() for an already-recorded `created` submission. A retry that succeeded could flip the ledger to `enabled`, but the confirmation in the transcript is append-once, so the user kept being told email was unavailable while the system believed it was on. The replay now reads recordedExternalNotification() and takes no external decision. An attempt that dies before subscribing or before its outcome is recorded leaves the row `pending`, and the normal creation path subscribes on the retry.
… a colleague's The create-watch response matched any watch-alert channel in the project, so a second member was told they were subscribed while the mail went to the first. The channel's deduplication key is the only record of whose it is, so state resolution, subscribe and unsubscribe now share one owner lookup.
…n patch A recorded outcome is immutable now, so nothing calls it.
Settling the investigations row was invisible to the user. The panel builds the
winning revision from the transcript's own `tool-render_view` parts and never
reads that table, so a turn that ran out of steps left the card at
`in_progress` forever: the database believed the investigation had finished
while a refresh still showed "Working...".
`settleOpenInvestigations` now returns the revisions it committed, and
`onTurnComplete` appends each as one more card revision — after the transcript
write and id-deduped on `investigation-settlement:{id}:{revision}`, so a failed
append leaves the card visibly unclosed rather than silently lost, and a retry
can't stack a second card.
The card-building and the latest-revision reader move out of the watch lane and
into the runtime both lanes share, so there is one shape, not two. The watch
lane keeps its own message id: it dedupes on the action, not the revision.
…tles
The sweep settled the row and appended nothing, so it visibly fixed nothing: the
chat kept rendering the last card it had, which was still "Working…". The settle
now returns the state and revision it wrote, and the sweep appends that as the
closing card revision on the chat — id-deduped on
`investigation-settlement:{id}:{revision}`, so a retried run can neither stack a
second card nor open a second investigation.
The append is scoped by chat id: a sweep runs off any session and has no user in
context, unlike the turn lane.
… user-actor token Binding a delegated token to its environment claim on the project-wide routes also refused any token that carries no claim at all, which the public PAT exchange used by MCP and the CLI is allowed to issue. Line the project-wide helper up with its neighbours: a claimless dashboard-agent token is still refused, everything else stays project-wide.
…at/dashboard-agent-flows
# Conflicts: # apps/webapp/app/components/dashboard-agent/DashboardAgentMessages.tsx # apps/webapp/app/components/dashboard-agent/InvestigationCard.test.ts # apps/webapp/app/components/dashboard-agent/InvestigationCard.tsx # apps/webapp/app/components/dashboard-agent/chat-layout.tsx # apps/webapp/app/components/dashboard-agent/investigation-winners.test.ts # apps/webapp/app/components/dashboard-agent/view-catalog.tsx # apps/webapp/test/__snapshots__/reportRenderParity.test.ts.snap
FROM is optional in the ClickHouse-derived grammar, so a query without a FROM clause parses cleanly. Fix the stale expectation.
# Conflicts: # apps/webapp/test/dashboardAgentMessageCards.test.ts
## What & why This is the system behind the Dashboard Agent — an assistant that answers questions about a project's runs, errors, queues, deploys and health, and can investigate failures end to end. The agent runs as a chat.agent task in its own Trigger project. It has no access to the main database or ClickHouse; all platform data is read through the public API using a delegated, read-only user token. Everything here is behind `canAccessDashboardAgent` and inert with the flag off. The UI that mounts the panel lands in #4529. ## Stack `#4418` (this, base) ← `#4529` UI ← `#4525` Watch ← `#4516` storybook gallery. The scenario/contract reference for the whole stack is `internal-packages/dashboard-agent/GUIDEBOOK.md` (it lands on the Watch branch): it states, per feature, what makes each thing happen and where that is decided. ## What's inside **Agent runtime and tools** — `internal-packages/dashboard-agent`: prompt, tool set (API reads, TRQL query, docs, navigation, evidence/investigations, repo source), conversation compaction, a prompt-prefix token budget pinned by snapshot test, and sampled LLM-judged turn evals. The package cannot import webapp server code, which is what makes the "no DB access" claim structural rather than a convention. **Contracts** — `internal-packages/dashboard-agent-contracts`: `trigger://` URIs, intents, and the block envelope every rendered card travels in. **Conversation store** — `internal-packages/dashboard-agent-db`: drizzle over postgres-js in its own `trigger_dashboard_agent` Postgres schema, plus one additive migration. **Auth boundary** — the user-actor token gains an optional environment claim; one guard (`userActorEnvironment.server.ts`) enforces it so routes don't each re-derive the rule. Token minting, cap ceiling, and the RBAC fallback path for self-hosted. **Transport** — webapp resource routes that mint the token and proxy each turn, and SDK-side mid-turn reconnect. **Public API the agent reads through** — orgs, projects, environments, runs, queue metrics, workers, a run's commit metadata, repo snapshot, reports, and `POST /api/v1/query`. **Reports** — the health report's layout is declared once and shared by the card, the markdown surface and the JSON/MCP surface, so the same report reads the same in the dashboard, the terminal and an editor. **Block renderers** — the report and investigation cards the flows above already emit (`app/components/dashboard-agent/`). The panel that hosts them, and the rest of the chat UI, is #4529. **Query safety and CSP** — see below. ## Key decisions - **The agent is a separate Trigger project, not webapp code.** It reads platform data over the public API with a delegated user-actor token whose `cap` ceilings it to read scopes. No Prisma, no ClickHouse, no webapp imports. - **The PAT-only auth helper now refuses user-actor tokens.** This is an intentional behavioral change: its callers consume only a bare userId and do not enforce delegated-token capabilities. Actor-aware routes continue through the scoped route builders instead. - **RBAC fallback builds a delegated token's ability from its own cap**, never the blanket ability a PAT gets (read-only when the token declares none). Without this, the agent's read-only cap would buy a write JWT on self-hosted. - **Org creation checks RBAC only for user-actor tokens, and only after the env gate**, so an install with `ORG_CREATION_API_ENABLED` off returns 404 rather than 403, and an ordinary PAT never consults an ability the route has no org to scope. Both orderings are pinned by test. - **The query path is read-only in depth.** TRQL rejects write statements at the grammar level (they don't parse, rather than being filtered), ClickHouse runs with `readonly=1`, and the org/project/env filters are injected server-side from the credential — the request body cannot widen scope. An unparseable query denies instead of falling through to the permissive resource. - **Document-wide img-src CSP.** Remote images are an outbound-request/exfiltration surface, so the policy permits only own-origin/data/blob, the required SSO avatar hosts, and the favicon endpoint. Operators can add exact origins through CSP_IMG_SRC_ALLOWLIST; wildcard hosts and bare schemes are intentionally not allowed. - **The chat transport reconnects on a mid-turn EOF** (`@trigger.dev/sdk`). A body that ends without a turn-complete is terminal only when the server says `X-Session-Settled: true`; otherwise the transport resubscribes from `lastEventId` with bounded backoff, and any record re-earns the budget. Previously a closed long-poll window or a proxy restart left the reply stuck as if still generating. - **Conversations live in their own datastore**, schema-scoped and foreign-key-free (it references `organizationId`/`userId` by id, because in cloud it is a different database). It is a display read-model for the History tab and transport resume; `chat.agent`'s object-store snapshot remains the model's source of truth. - **Deterministic first.** Reports and health checks contain no LLM — they are computed from the same data the dashboard shows, and the model only narrates and links them. That is what makes a number in an answer auditable. ## Testing - 63 new test files, run with `pnpm run test --filter webapp` and per-package vitest. Heaviest coverage on the auth boundary (`userActorPatOnlyBoundary`, `userActorTokenClaimsAndScopes`, `contextlessPatRoutes`, `rbacFallbackBranch`), TRQL read-only, the report layout, and the SDK reconnect. - The agent package has a separate eval lane (`pnpm run test:evals`, `vitest.eval.config.ts`) that hits the real model, so it never runs in `pnpm test`. - Live-tested against a local stack scenario by scenario; the GUIDEBOOK lists the condition each behaviour is expected under, which is what those runs were checked against. ## Changelog `.server-changes/dashboard-agent.md`, plus changesets for `@trigger.dev/core` (report schemas), `@trigger.dev/sdk` (chat reconnect) and the CLI's `mint-token` help text.
…ft-delete idempotency (review)
…rst as a draft guard
| const loadHistory = useMemo( | ||
| () => | ||
| createCoalescedReload(async () => { | ||
| try { | ||
| const res = await fetch(actionPath); | ||
| if (!res.ok) throw new Error(`History request failed (${res.status})`); | ||
| const data = (await res.json()) as { chats?: DashboardAgentChatListItem[] }; | ||
| setChats(data.chats ?? []); | ||
| } catch (error) { | ||
| console.error("Dashboard agent: failed to load chat history", error); | ||
| toast.error("We couldn't load your previous chats. Try again in a moment."); | ||
| } | ||
| }), | ||
| [actionPath, toast] | ||
| ); |
There was a problem hiding this comment.
🔍 History reload coalescing depends on useToast() returning a stable reference
loadHistory is a useMemo over createCoalescedReload(...) keyed on [actionPath, toast]. If useToast() returns a fresh object per render (rather than a memoized context value or a useCallback-stable API), the memo is invalidated on every render, so a brand-new coalescer is constructed each time — the in-flight/queued state it carries is discarded and the coalescing described in coalesced-reload.ts never actually applies across renders. It also makes loadHistory an unstable identity, which is passed down as onTurnSettled into DashboardAgentChat and used as a dependency of the turn-settle effect (DashboardAgentChat.tsx:292) and of deleteChat. The settle effect is still guarded by prevStatus, so re-running it is harmless, but the coalescing guarantee is worth verifying against the actual useToast implementation.
Was this helpful? React with 👍 or 👎 to provide feedback.
Stacked on #4418. Merge that first.
The UI slice of the dashboard agent: the side panel, the chat transport wiring, message and card rendering, suggested prompts, and chat history. #4418 works without this — the system is simply invisible. The diff is mostly components, so the notes below cover only the three decisions you can't read off the markup. Behavior and a hands-on walkthrough live in GUIDEBOOK.md, which lands with #4525.
Decisions worth knowing
answeredstays keyed on the emission index.Notes
canAccessDashboardAgent; no behavior change with the flag off.handle.agentPageContexton 47 routes, ~20 lines each.?aiHelp=links keep working.Screenshots