Repository navigation
fix(ai): enforce enabledTools allowlist for page agents - #1316
Conversation
- treat empty enabledTools array as zero-tool restriction (was skipped due to .length > 0 guard) - extract web_search before allowlist so the runtime webSearchEnabled toggle can override it independently - replace buildPageAITools with filterToolsForReadOnly + explicit web_search step Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe AI chat route refactors its tool-filtering pipeline to use explicit stepwise logic instead of a single tool-builder call, reorganizing how read-only state, ChangesAI Chat Tool-Filtering Pipeline
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
- treat empty enabledTools array as zero-tool restriction (was skipped due to .length > 0 guard) - extract web_search before allowlist so the runtime webSearchEnabled toggle can override it independently - replace buildPageAITools with filterToolsForReadOnly + explicit web_search step Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Summary
enabledTools = []was silently skipped due to a.length > 0guard, leaving page agents with unrestricted tool access when zero tools were configured!= nullso an empty array correctly blocks all PageSpace toolsweb_searchis now extracted before the allowlist runs and re-added after if the runtimewebSearchEnabledtoggle is on — the per-conversation toggle correctly overrides the agent's configured allowlistWhat changed
apps/web/src/app/api/ai/chat/route.ts— replacedbuildPageAITools+ the broken early allowlist block with a 4-step sequence:isReadOnlyfilter to the PageSpace baselineweb_searchseparately (handled as a toggle override, not via allowlist)enabledToolsallowlist (!= nullhandles[]as zero-tool restriction)web_searchback ifwebSearchEnabledis on in the requestIntegration tools, MCP tools, and the finish tool continue to merge after this block — they have their own access-control plane and are not subject to
enabledTools.Test plan
enabledTools = []on an AI Chat page — agent should have no tool callsweb_searchenabledTools = ['list_pages']— agent should only calllist_pagesenabledToolsunset (null) — agent has full tool set (filtered by toggles as before)enabledToolsisnull🤖 Generated with Claude Code
Summary by CodeRabbit
Bug Fixes
Refactor