Skip to content

feat(ai): set_home_page tool — agents can set/clear a drive's landing page - #1644

Merged
2witstudios merged 6 commits into
masterfrom
pu/set-home-tool
Jun 13, 2026
Merged

2witstudios merged 6 commits into
masterfrom
pu/set-home-tool

Conversation

@2witstudios

@2witstudios 2witstudios commented Jun 13, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Adds set_home_page to driveTools in apps/web/src/lib/ai/tools/drive-tools.ts
  • Registers it in WRITE_TOOLS in apps/web/src/lib/ai/core/tool-filtering.ts

What the tool does

Agents can now call set_home_page to designate any non-trashed page within a drive as its landing page. Passing null for pageId clears the home page (restoring the default page tree view).

Authorization: owner or admin only (via getDriveAccessWithDrive); scoped MCP tokens gated via driveDeniedByAppToken.

Validation: isValidDriveHomePage confirms the target page exists, belongs to the drive, and is not trashed — same check used by PATCH /api/drives/[driveId].

Side effects: broadcasts drive:updated to all drive members + logs activity with before/after homePageId values.

Test plan

  • Agent sets a page as home page — drive redirects to that page on navigation
  • Agent clears home page (pageId: null) — drive reverts to default tree
  • Rejects if page belongs to a different drive (400)
  • Rejects if caller is not owner/admin (403)
  • Rejects if scoped MCP token lacks manage access (403)
  • Read-only mode excludes set_home_page (it's in WRITE_TOOLS)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added the ability to set or clear a drive's home/landing page with AI tools (requires owner or admin permissions)

… page

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 13, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@2witstudios, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 23 minutes and 20 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 928ef035-5821-4a88-babf-149b61fc5728

📥 Commits

Reviewing files that changed from the base of the PR and between b70f397 and cb1dde0.

📒 Files selected for processing (5)
  • apps/web/src/components/ai/shared/chat/tool-calls/ToolCallRenderer.tsx
  • apps/web/src/components/ai/shared/chat/tool-calls/registry.tsx
  • apps/web/src/lib/ai/core/__tests__/tool-filtering.test.ts
  • apps/web/src/lib/ai/tools/__tests__/drive-tools.test.ts
  • apps/web/src/lib/ai/tools/drive-tools.ts
📝 Walkthrough

Walkthrough

Adds a new AI tool set_home_page that allows authenticated, authorized users (drive owners/admins) to set or clear a drive's home page. The tool implementation includes access validation, page verification, drive updates, event broadcasting, and activity logging. The tool is then registered as a write operation to enforce read-only access restrictions.

Changes

Drive Home Page Tool Implementation

Layer / File(s) Summary
set_home_page tool implementation
apps/web/src/lib/ai/tools/drive-tools.ts
Extends drive-service imports with updateDrive, then implements the set_home_page tool that authenticates the caller, verifies owner/admin access, validates that the provided pageId (if any) is a non-trashed page in the drive, updates the drive's homePageId, broadcasts an updated event to drive recipients, logs AI activity with before/after metadata, and returns a success response with the updated homePageId or null and user-facing messaging.
Write-tools permission registration
apps/web/src/lib/ai/core/tool-filtering.ts
Adds set_home_page to the WRITE_TOOLS constant so it is classified as a write operation and will be excluded from allowed tools when read-only mode is enabled.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

  • 2witstudios/PageSpace#1316: Both PRs involve AI tool-permission filtering: this PR adds set_home_page to WRITE_TOOLS for read-only access control, while the retrieved PR refactors the chat route to apply filterToolsForReadOnly and enabledTools allowlists to page agents.

Poem

🐰 A tool to set homes with care,
Permissions checked with flair,
Write it once, read-only beware,
Drive's landing page awaits there! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main feature: adding a new AI tool that allows agents to set or clear a drive's landing page.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch pu/set-home-tool

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b70f397fe2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

}

try {
const result = await getDriveAccessWithDrive(driveId, userId);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Gate page agents by their own drive membership

When this tool is invoked by a page agent, userId identifies the triggering user, so this check authorizes using that user's owner/admin status and ignores the agent's drive membership. An enabled agent with no membership can therefore change the home page of any drive administered by its caller if given the drive ID, while a valid member agent invoked by a non-admin is incorrectly denied. Use the actor-aware canActorManageDrive gate in actor-permissions.ts, which explicitly applies agent membership and MCP ceilings.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in cb1dde0: replaced the manual driveDeniedByAppToken + getDriveAccessWithDrive + owner/admin check with canActorManageDrive, which properly gates page-agent callers by their drive membership (via hasAgentDriveMembership) rather than the triggering user's role.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/web/src/lib/ai/core/tool-filtering.ts (1)

21-21: ⚡ Quick win

Add a direct read-only filter assertion for set_home_page.

This classification is correct; add an explicit unit assertion in apps/web/src/lib/ai/core/__tests__/tool-filtering.test.ts to prevent regressions for this tool specifically.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/web/src/lib/ai/core/tool-filtering.ts` at line 21, Add an explicit unit
assertion in apps/web/src/lib/ai/core/__tests__/tool-filtering.test.ts that
verifies the tool 'set_home_page' is classified as read-only by the filtering
logic: locate the test for tool filtering (e.g., the test that calls the
filterTools/filterToolList or similar helper) and add an assertion like
expect(filteredTools).toContainEqual(expect.objectContaining({name:
'set_home_page', access: 'read'})) or the project's equivalent matcher to assert
read-only classification for 'set_home_page' so this specific tool cannot
regress.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@apps/web/src/lib/ai/core/tool-filtering.ts`:
- Line 21: Add an explicit unit assertion in
apps/web/src/lib/ai/core/__tests__/tool-filtering.test.ts that verifies the tool
'set_home_page' is classified as read-only by the filtering logic: locate the
test for tool filtering (e.g., the test that calls the
filterTools/filterToolList or similar helper) and add an assertion like
expect(filteredTools).toContainEqual(expect.objectContaining({name:
'set_home_page', access: 'read'})) or the project's equivalent matcher to assert
read-only classification for 'set_home_page' so this specific tool cannot
regress.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 72931d44-64f2-4742-9959-e1f4de25bb4a

📥 Commits

Reviewing files that changed from the base of the PR and between b231db3 and b70f397.

📒 Files selected for processing (2)
  • apps/web/src/lib/ai/core/tool-filtering.ts
  • apps/web/src/lib/ai/tools/drive-tools.ts

Comment thread apps/web/src/lib/ai/tools/drive-tools.ts
Pins the read-only filtering regression guard requested in code review.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

@2witstudios 2witstudios left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added in a471308: new test in tool-filtering.test.ts asserts isWriteTool('set_home_page') is true and that set_home_page is excluded from read-only mode via filterToolsForReadOnly.

2witstudios and others added 4 commits June 13, 2026 09:17
Required by the registry-coverage test which asserts every AI tool has
a rich renderer. Adds ActionResultRenderer entry + display label.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Covers tool definition shape and auth guard, matching the pattern
for list_drives / create_drive / rename_drive.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…test

The describe was inserted after the outer describe's closing }), creating
a syntax error. Move it inside the outer describe('drive-tools') block.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…home_page

- Replace manual driveDeniedByAppToken + getDriveAccessWithDrive + owner/admin
  check with canActorManageDrive, which correctly gates page-agent callers by
  their drive membership rather than the triggering user's role.
- Wrap broadcast and activity logging in try/catch so a side-effect failure
  does not return a false-negative on a successful state change.
- Guard updateDrive null return with an explicit error.

Fixes: Codex P1 (agent membership), CodeRabbit major (side-effect isolation).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@2witstudios
2witstudios merged commit 13d5872 into master Jun 13, 2026
3 checks passed
@2witstudios
2witstudios deleted the pu/set-home-tool branch June 13, 2026 21:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant