Skip to content

fix(ai): enforce enabledTools allowlist for page agents - #1316

Merged
2witstudios merged 1 commit into
masterfrom
pu/page-ai-regression
May 12, 2026
Merged

2witstudios merged 1 commit into
masterfrom
pu/page-ai-regression

Conversation

@2witstudios

@2witstudios 2witstudios commented May 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Bug: enabledTools = [] was silently skipped due to a .length > 0 guard, leaving page agents with unrestricted tool access when zero tools were configured
  • Fix: Changed the guard to != null so an empty array correctly blocks all PageSpace tools
  • Improvement: web_search is now extracted before the allowlist runs and re-added after if the runtime webSearchEnabled toggle is on — the per-conversation toggle correctly overrides the agent's configured allowlist

What changed

apps/web/src/app/api/ai/chat/route.ts — replaced buildPageAITools + the broken early allowlist block with a 4-step sequence:

  1. Apply isReadOnly filter to the PageSpace baseline
  2. Extract web_search separately (handled as a toggle override, not via allowlist)
  3. Apply enabledTools allowlist (!= null handles [] as zero-tool restriction)
  4. Add web_search back if webSearchEnabled is on in the request

Integration tools, MCP tools, and the finish tool continue to merge after this block — they have their own access-control plane and are not subject to enabledTools.

Test plan

  • Set enabledTools = [] on an AI Chat page — agent should have no tool calls
  • Same config with web search toggled on — agent should have only web_search
  • Set enabledTools = ['list_pages'] — agent should only call list_pages
  • Leave enabledTools unset (null) — agent has full tool set (filtered by toggles as before)
  • Verify integration tools (calendar, GitHub) still work when enabledTools is null

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved AI chat tool-selection logic to more accurately filter and enable tools based on page settings and user preferences.
  • Refactor

    • Reorganized tool-filtering pipeline for clearer, more explicit handling of tool availability in AI conversations.

Review Change Stack

- treat empty enabledTools array as zero-tool restriction
  (was skipped due to .length > 0 guard)
- extract web_search before allowlist so the runtime
  webSearchEnabled toggle can override it independently
- replace buildPageAITools with filterToolsForReadOnly
  + explicit web_search step

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 8dabe92e-4eec-4d50-9ba2-174751e3b435

📥 Commits

Reviewing files that changed from the base of the PR and between 1faa1a9 and 361bd7e.

📒 Files selected for processing (1)
  • apps/web/src/app/api/ai/chat/route.ts

📝 Walkthrough

Walkthrough

The AI chat route refactors its tool-filtering pipeline to use explicit stepwise logic instead of a single tool-builder call, reorganizing how read-only state, web_search extraction, enabledTools allowlist enforcement, and web search runtime toggles are applied to available tools.

Changes

AI Chat Tool-Filtering Pipeline

Layer / File(s) Summary
Import and documentation updates
apps/web/src/app/api/ai/chat/route.ts
Import changes from buildPageAITools to filterToolsForReadOnly; documentation updated to describe how tool allowlisting and runtime toggles (isReadOnly, webSearchEnabled) apply relative to the server-side enforcement boundary.
Tool-filtering implementation
apps/web/src/app/api/ai/chat/route.ts
Tool-filtering logic reorganized into stepwise phases: apply read-only filtering, extract web_search for independent override, enforce enabledTools allowlist unconditionally (including empty arrays), and conditionally re-add web_search when webSearchEnabled is true.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 Tools are sorted, row by row,
Read-only filters steal the show,
Web search steps in and steps back out,
Allowlists now leave no doubt!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically describes the main fix: enforcing the enabledTools allowlist for page agents, which is the core bug being addressed.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch pu/page-ai-regression

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@2witstudios
2witstudios merged commit d73d341 into master May 12, 2026
10 checks passed
@2witstudios
2witstudios deleted the pu/page-ai-regression branch May 12, 2026 21:32
2witstudios added a commit that referenced this pull request May 15, 2026
- treat empty enabledTools array as zero-tool restriction
  (was skipped due to .length > 0 guard)
- extract web_search before allowlist so the runtime
  webSearchEnabled toggle can override it independently
- replace buildPageAITools with filterToolsForReadOnly
  + explicit web_search step

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant