Skip to content

fix(markdown): restore document creation and updates - #2940

Closed
George Ng (GeorgeNgMsft) wants to merge 7 commits into
mainfrom
georgengmsft-bind-markdown-loopback
Closed

fix(markdown): restore document creation and updates#2940
George Ng (GeorgeNgMsft) wants to merge 7 commits into
mainfrom
georgengmsft-bind-markdown-loopback

Conversation

@GeorgeNgMsft

@GeorgeNgMsft George Ng (GeorgeNgMsft) commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Summary

  • restore Markdown document creation and updates without requiring a connected browser
  • preserve initial content for compound create-and-fill requests and avoid overwriting existing non-empty files
  • save documents under the host-authorized workspace root, with safe relative subdirectories and traversal/symlink/junction protections
  • propagate the request working directory through CLI, dispatcher ActionContext, and out-of-process agent RPC
  • return the real filesystem path and a loopback editor link for every created/opened document
  • unify browser and headless Markdown operation semantics, including formatting, serializer-based persistence, revisions, binding identities, restart recovery, and multi-tab primary handoff
  • remove the unsafe unused /file/load rebinding path and evict stale collaboration rooms
  • preserve typed Azure model configuration while deferring LLM initialization until an update actually needs it

Validation

  • affected Markdown, RPC, dispatcher, CLI, and server builds pass
  • 103 Markdown tests pass across 9 suites
  • 38 agent RPC tests pass across 3 suites
  • focused dispatcher ActionContext tests pass
  • complexity and lint ratchets pass; changed files are Prettier-clean
  • real CLI compound request executed markdown.createDocument, wrote exact content at the repository root, appeared in git status, and returned an editor URL that responded successfully
  • completed two principal-engineer adversarial review rounds plus a narrow closure review; all high-confidence findings were addressed

Restrict the unauthenticated Markdown HTTP and WebSocket service to 127.0.0.1 and advertise the same address to collaboration clients.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 824e625d-be4c-48f5-91c7-88675b55c6e6
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 02e51644-28c8-4b3f-98da-61c5fe172346
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 02e51644-28c8-4b3f-98da-61c5fe172346
@GeorgeNgMsft George Ng (GeorgeNgMsft) changed the title fix(markdown): avoid model setup for document creation fix(markdown): restore typed model configuration Aug 28, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 02e51644-28c8-4b3f-98da-61c5fe172346
@GeorgeNgMsft George Ng (GeorgeNgMsft) changed the title fix(markdown): restore typed model configuration fix(markdown): restore document creation and updates Aug 28, 2026
message.operations,
);
if (writableFilePath) {
fs.writeFileSync(writableFilePath, content, "utf-8");
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 02e51644-28c8-4b3f-98da-61c5fe172346
@GeorgeNgMsft
George Ng (GeorgeNgMsft) marked this pull request as draft August 28, 2026 01:58
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 02e51644-28c8-4b3f-98da-61c5fe172346
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@GeorgeNgMsft

Copy link
Copy Markdown
Contributor Author

Separating this out into multiple smaller PRs

@GeorgeNgMsft

Copy link
Copy Markdown
Contributor Author

Superseded by native stack #2970, split bottom-to-top for reviewability:

  1. [Markdown] create documents in workspace #2966 - workspace-safe document creation
  2. [Markdown Agent] Apply document edits deterministically #2967 - deterministic document edit operations
  3. fix(markdown): persist conflict-safe updates #2968 - conflict-safe durable/headless persistence
  4. fix(markdown): secure browser document bindings #2969 - secure browser binding and synchronization server
  5. fix(markdown): persist browser editor changes #2971 - browser editor persistence and reconciliation

The final stack was validated with the Markdown build, all 8 Markdown test suites (64 tests), Prettier, lint/complexity/circular/debt gates, and exact branch ancestry checks.

jebrans pushed a commit to jebrans/TypeAgent that referenced this pull request Sep 6, 2026
## Summary

This PR fixes document creation and separates open/create semantics

Layer 1 (bottom) of the replacement stack for microsoft#2940.

This layer adds only core workspace-safe Markdown document creation:

- propagates the host-authorized working directory through action
context and agent RPC
- creates Markdown files under that workspace, including nested relative
paths
- preserves requested initial content
- rejects traversal, absolute/drive-qualified, out-of-workspace, and
symlink-escape paths
- avoids constructing the Markdown model for create/open actions
- passes the CLI request working directory into dispatch

## Deferred to upper layers

- document update/edit semantics
- revision and binding-token conflict checks
- streaming update persistence
- browser-view persistence and synchronization
- reopening editor bindings
- loopback view-server changes
- the unrelated `aiclient` runtimeConfig/OpenAI change

## Validation

- `pnpm run prettier:changed:fix` / `pnpm run prettier:changed` (pass)
- lint ratchet (pass)
- complexity ratchet (pass)
- circular-dependency ratchet (pass)
- debt/skipped-test gate (pass)
- direct path-policy smoke covering nested creation, traversal
rejection, canonical root resolution, and junction escape rejection
(pass)
- affected TypeScript build and Jest suites were attempted but
environment-blocked: worktree setup could not fetch locked public
packages `baseline-browser-mapping@2.11.19` and `uuid@14.0.2` because
Azure Artifacts returned 401, leaving workspace package links
incomplete; the resulting compiler errors were missing-module
diagnostics

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Hillary Mutisya (hillary-mutisya) pushed a commit to hillary-mutisya/TypeAgent that referenced this pull request Sep 10, 2026
## Stack

Layer 3 of the replacement stack for microsoft#2940.

- Base: `main` (microsoft#2966 and microsoft#2967 are merged)
- Parent layer: microsoft#2967 (merged)

## Included

- Persists headless Markdown updates directly to the authorized
workspace file.
- Makes streaming completion idempotent by recognizing the
already-produced revision instead of applying operations twice.
- Carries immutable binding identity and SHA-256 revision checks across
read/apply.
- Rejects stale tokens, rebound root/path/file identities, revision
conflicts, and roots replaced by symlinks or junctions.
- Adds request IDs to concurrent document read/apply IPC and correlates
responses.
- Keeps the view service server-authoritative for update persistence
even when no browser/SSE client is connected.

## Deferred to browser layer

- Browser `document-manager.ts` rewrite and serializer/autosave
behavior.
- Primary/secondary SSE lifecycle, browser synchronization/promotion UX,
and reopening the same file while preserving browser binding state.
- Broader browser snapshot adoption and loopback binding behavior.

## Validation

Historical results from before the rebase (not rerun as full build/Jest
validation):

- `@typeagent/markdown-agent` TypeScript and frontend build
- Focused Jest suites: 44 tests passed across Markdown persistence,
operation engine, path policy, creation path policy, and action handler
coverage
- Prettier changed-file check
- Git diff check
- Repo lint ratchet

After rebasing onto `f3e4308ea2cd722a2905eceac3f2a1e61d19a420`: 23
focused Node integration smoke checks passed using the actual handler,
persistence module, and operation engine with simulated translator/view
IPC; TypeScript 5.4.5 syntax parsing and Git diff checks passed. Full
build/Jest, semantic typechecking, and repository ratchets were not
rerun: this worktree has no installed dependencies (`fluid-build`
missing). Pinned Prettier 3.5.3 was unavailable offline.

Complete layer diff against the new main base: 992 insertions, 532
deletions (1,524 changed lines), across 6 files.

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants