Skip to content

feat(control-plane): let a webchat conversation change its own host agent - #2585

Merged
zfy0701 merged 1 commit into
mainfrom
claude/agent-webchat-decision-config-860fa1
Sep 27, 2026
Merged

zfy0701 merged 1 commit into
mainfrom
claude/agent-webchat-decision-config-860fa1

Conversation

@zfy0701

@zfy0701 zfy0701 commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Summary

In a private webchat conversation, the AgentConnect admin tools refused to update the conversation's own host agent or replace its workspace. An owner chatting with their own agent could ask it to change any other agent, but had to leave the conversation to change the one they were talking to. The refusal also came late: the write was queued, the owner approved it, and only then did it fail with 403.

Every delegated write already executes only after the owner approves its exact arguments in the browser, which is the same change the owner could make in the console. This removes the self-check from updateAgent and setAgentWorkspace.

deleteAgent still refuses the host agent, because deleting it would end the conversation that carries the approval.

  • packages/control-plane/src/http/mcp/tools.ts: drop the self-check from updateAgent and setAgentWorkspace, and narrow the remaining guard and its message to deletion.
  • docs/designs/webchat-preset-agentconnect-mcp.md invariant 7 and docs/designs/agent-assistant.md §6.3: record the new rule and why.

Test plan

  • pnpm --filter @agentconnect.md/control-plane exec vitest run src/http/mcp/tools.test.ts (56 passed), including a new case: a delegated call sends the PATCH and the workspace PUT for its own host agent, and deleteAgent on it returns 403 with no request sent
  • pnpm --filter @agentconnect.md/control-plane typecheck
  • eslint and prettier on the changed files

🤖 Generated with Claude Code · Claude Opus 5.5

…gent

A delegated webchat call could not update its host agent or replace its
workspace, so an owner chatting with their own agent had to leave the
conversation to change it. Every delegated write already waits for the
owner to approve its exact arguments in the browser, so the refusal
protected nothing the approval did not. Deleting the host agent stays
refused: it would end the conversation carrying the approval.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@zfy0701
zfy0701 enabled auto-merge (squash) September 27, 2026 07:44

@agentconnect-md-test agentconnect-md-test Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. The self-target guard is removed only for updateAgent and setAgentWorkspace; deleteAgent remains blocked before REST dispatch. I traced delegated writes through browser approval and the existing agent update and workspace drain paths and found no blocking regression. git diff --check passes. I could not rerun the focused Vitest suite in this checkout because its dependencies are not installed; the pinned package manager began fetching the workspace, so I stopped that optional run.

sent by review-bot (Codex · gpt-6-sol) · open in session

@zfy0701
zfy0701 merged commit 153fd4c into main Sep 27, 2026
13 of 14 checks passed
@zfy0701
zfy0701 deleted the claude/agent-webchat-decision-config-860fa1 branch September 27, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant