Skip to content

feat(programs): B3 plumbing and tests — runProgram, adapter wiring, detection via runAgent - #1308

Merged
gewenyu99 merged 67 commits into
posthog/functional-b-integrationfrom
posthog/functional-b3-parity
Sep 25, 2026
Merged

gewenyu99 merged 67 commits into
posthog/functional-b-integrationfrom
posthog/functional-b3-parity

Conversation

@gewenyu99

@gewenyu99 gewenyu99 commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Scope: Implements the #1307 surface, plus its tests. Review behavior.

Related: #1320

This fills in runProgram. It resolves credentials, waits on approval and post-auth gates, loads flags, refreshes the token through @shared/oauth-session from main #1323, resolves the route and calls runAgent. The TUI and the headless runner reach it through the legacy adapter. Agentic detection now calls runAgent directly.

flowchart LR
  Runners["TUI and headless runner"] --> Adapter["Legacy adapter"]
  Adapter --> RunProgram["runProgram"]
  Workbench["Workbench"] --> RunProgram
  RunProgram --> RunAgent["runAgent"]
  Detection["Agentic detection"] --> RunAgent
Loading

Stack: #1306 moves → #1307 surface shell → #1308 plumbing → #1357 runner context → #1309 docs → #1363 stream retry.

What changed and checks
  • runProgram and ProgramStore: the body behind feat(programs): B2 surface shell — runProgram types and stub signatures #1307's types. The store holds one invocation's data and copies it out through onProgress and the outcome.
  • AI SDK stamp: it moves out of detect.ts into posthog-integration/ai-sdk-stamp.ts. It takes no session, so runProgram can call it.
  • Legacy adapter: builds run and the settings from the ProgramConfig, keeps the health and settings gates, and calls runProgram. It writes runProgram's diagnostics to the debug log. It is temporary and goes away later in the refactor.
  • Detection: calls runAgent with its own prompt and collects the transcript tail.
  • Tests: one per real risk: order, cancellation, failures and the adapter's wiring.
  • Known gap: runProgram still loads @ui indirectly, through @utils/oauth and @agent. C fixes this.
  • The jest e2e-tests/ suite stays. It moves to the workbench later.

Checks at f2e42acd: pnpm typecheck, pnpm lint (0 errors), pnpm vitest run (3,431 tests, 26 more than #1307) and pnpm test:arch (11 tests) pass. No live run at this head. The last real-TUI posthog-integration run was on the older top a083676c: exit 0, with 8 of 8 steps.

Created with PostHog Desktop

Include status history in fixed-route frame dedupe and rewrite the early outro result when the integration reaches keep-skills.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@github-actions

Copy link
Copy Markdown

🧙 Wizard CI

Run the Wizard CI and test your changes against wizard-workbench example apps by replying with a GitHub comment using one of the following commands:

Test all apps:

  • /wizard-ci all

Test all apps in a directory:

  • /wizard-ci ai-observability
  • /wizard-ci basic-integration
  • /wizard-ci mcp-analytics
  • /wizard-ci replay-vision
  • /wizard-ci revenue
  • /wizard-ci self-driving
  • /wizard-ci warehouse
  • /wizard-ci warehouse-seeded

Test an individual app:

  • /wizard-ci ai-observability/anthropic
  • /wizard-ci ai-observability/google-adk
  • /wizard-ci ai-observability/groq
Show more apps
  • /wizard-ci ai-observability/manual-capture
  • /wizard-ci ai-observability/openai
  • /wizard-ci ai-observability/openai-agents
  • /wizard-ci ai-observability/opentelemetry
  • /wizard-ci ai-observability/vercel-ai
  • /wizard-ci basic-integration/android
  • /wizard-ci basic-integration/angular
  • /wizard-ci basic-integration/astro
  • /wizard-ci basic-integration/django
  • /wizard-ci basic-integration/fastapi
  • /wizard-ci basic-integration/flask
  • /wizard-ci basic-integration/flutter
  • /wizard-ci basic-integration/javascript-node
  • /wizard-ci basic-integration/javascript-web
  • /wizard-ci basic-integration/laravel
  • /wizard-ci basic-integration/next-js
  • /wizard-ci basic-integration/nuxt
  • /wizard-ci basic-integration/python
  • /wizard-ci basic-integration/rails
  • /wizard-ci basic-integration/react-native
  • /wizard-ci basic-integration/react-router
  • /wizard-ci basic-integration/sveltekit
  • /wizard-ci basic-integration/swift
  • /wizard-ci basic-integration/tanstack-router
  • /wizard-ci basic-integration/tanstack-start
  • /wizard-ci basic-integration/vue
  • /wizard-ci mcp-analytics/custom-dispatcher
  • /wizard-ci mcp-analytics/typescript-sdk
  • /wizard-ci replay-vision/javascript-node
  • /wizard-ci replay-vision/next-js
  • /wizard-ci replay-vision/react-vite
  • /wizard-ci revenue/stripe
  • /wizard-ci self-driving/astro
  • /wizard-ci self-driving/fastapi
  • /wizard-ci self-driving/nuxt
  • /wizard-ci self-driving/react-router
  • /wizard-ci self-driving/sveltekit
  • /wizard-ci warehouse/monorepo-env
  • /wizard-ci warehouse/multi-source-next
  • /wizard-ci warehouse/stripe-node
  • /wizard-ci warehouse/zero-source
  • /wizard-ci warehouse-seeded/next-stripe
  • /wizard-ci warehouse-seeded/next-stripe-declined

Test against a Context Mill branch:

  • /wizard-ci all context-mill:my-branch

Add context-mill:<branch> to any command above to pin the Context Mill branch. It defaults to main.

Results will be posted here when complete.

Forward the self-driving connection decision from the legacy session and map the refactored source aliases in Jest.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Move Learn and Tips deck selection to the TUI, keep watcher updates behind callback and structural source contracts, and put cross-surface lifecycle enums in shared modules. Shrink the architecture allowlist by 29 edges while preserving program and TUI behavior.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@gewenyu99 gewenyu99 changed the title test(tui): WIP snapshot parity and full-flow result test(programs): WIP B3 parity and boundary cuts Sep 22, 2026
Use program-specific read shapes for predicates and detectors, and source API credentials directly from their owner. Remove the ten corresponding architecture allowlist entries.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Move family dispatch into the command surface, attach headless flags at CLI command construction, and share the PostHog CLI installer across programs and steering. Remove six resolved architecture exceptions without changing command or warning behavior.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Return detected variant labels from framework metadata and project them through program and host adapters. Remove ten framework-to-UI imports and their architecture allowances while preserving TUI and CI labels.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
The keyboard path mounts the next screen, where an unrelated asynchronous GitHub check can set githubConnected before the diff is captured. Keep that request pending in this commit-equivalence test.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Give completion hooks only the signup and emitted URL data they use. Narrow legacy program definitions to their required inputs and remove the corresponding session allowlist entries.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Keep authentication and token refresh independent of the UI singleton. The TUI, CI and detector hosts provide the same credential setters, preserving login reuse and refresh behavior while removing the program-to-UI import.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Bind each legacy completion hook to a fresh projection of signup and emitted URLs. The agent retains its credential-only hook contract, while late dashboard and notebook updates remain visible to program outros.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Keep agentic detection independent of the legacy session and UI renderer. The host supplies progress handling, and detector helpers consume only the fields they use.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
The legacy program runner continues to use the live UI but reaches progress mapping through its existing public UI entry. This removes the deep UI import without changing progress ordering or interaction behavior.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Move self-driving integration dispatch to the CLI host while preserving scoped sessions and composed-run cleanup. Cover the host boundary with a focused parity test.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
The detector and legacy adapter cuts both export the same reducer from the public UI entry; keep the combined export once.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Keep authentication state and warehouse run data at their actual program boundaries, and remove the two corresponding legacy-session allowlist edges.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
(cherry picked from commit def9b31a7638c5826baad350472b757a0d392b93)
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
(cherry picked from commit e75f208c3daeee45cf7e9aa5b143c4dad19aa8b2)
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
(cherry picked from commit 60db0ffaa1caa09442883f0af43e7e8e84d885ca)
Keep the legacy TUI and CI adapter with its host callers, pass explicit program host capabilities to run and ciPreRun callbacks, and retain live UI state reads for late picker callbacks. Record the resulting CLI-to-program edges as C1 debt while keeping ProgramStep session ownership explicit.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
(cherry picked from commit 6019b59a9588b0c5a12e09da71e9cc4bbdb0f156)
Update agent and program documentation comments after moving the session-driven adapter into the CLI runner layer.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
(cherry picked from commit 5616cee27f81b032a96d56c9259aabcf32389310)
Narrow feature run and CI inputs to the fields they use. Route project scoping, warnings, preinstall warnings, and hosting environment uploads through explicit host capabilities while preserving the original session-backed framework context.

Generated-By: PostHog Desktop

Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
(cherry picked from commit ce6414c58faca69f628a78d11b78b7768a359cb9)
@gewenyu99 gewenyu99 changed the title test(programs): WIP B3 parity and boundary cuts refactor(programs): B3 parity and legacy boundary cuts Sep 22, 2026

@gewenyu99 gewenyu99 left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥸 Reviewed by NotVincent, totally not Vincent. The real Vincent will review it separately. Probably slop, please disregard.

Comment thread src/lib/runners/run-program-agent.ts Outdated
@@ -1,31 +1,35 @@
/**
* The session-driven agent runner every existing caller uses.
* The session-driven host adapter for legacy TUI and CI runs.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: This module moved out of @programs/run-agent-legacy, but the real-TUI e2e host still imports the old path. Nothing typechecks scripts/, so no check notices.

pnpm test:e2e or wizard-ci --e2e starts the TUI host -> tsx resolves @programs/run-agent-legacy -> module not found -> every real-TUI snapshot run crashes before the intro screen

Suggested fix: Import runProgramAgent from @lib/runners/run-program-agent in the TUI host, and add the capture scripts to a typechecked tsconfig so the next move breaks the build.

Comment thread e2e-tests/run-live.ts Outdated
await new Promise<void>((resolve, reject) => {
const child = spawn('npm', args, {
cwd,
env: { ...process.env, CI: '1' },

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: Setting CI here turns on Vite's colored output, so the ready text the runner waits for never shows up as plain text.

Vite case reaches npm run preview with CI=1 -> Vite prints Local in bold escape codes -> output never includes "Local:" -> 120s timeout -> the run stops before Next.js starts

Suggested fix: Add NO_COLOR: '1' next to CI, or strip ANSI codes before matching.

Comment thread e2e-tests/run-live.ts Outdated
180_000,
);
if (build.code !== 0) throw new Error(`App build failed:\n${build.output}`);
await waitForOutput(['run', 'dev'], app, testCase.devReady);

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: The runner means to prove the integrated Next.js app builds and serves in production, but it builds before starting the dev server, and next dev clears .next when it starts.

agent run succeeds -> npm run build writes .next -> npm run dev cleans .next -> npm run start prints "Could not find a production build" -> Next.js case fails every time

Suggested fix: Run dev first, then build, then start, the order the old Jest suite used.

Comment thread e2e-tests/run-live.ts Outdated
}
const build = await runCommand(
'npm',
['run', 'build'],

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: The agent's own subprocesses never see the operator's personal key, but the fixture app's build and servers get the whole shell env.

operator exports POSTHOG_PERSONAL_API_KEY -> agent installs app deps from floating ranges -> npm run build runs that code with the key in env -> any build hook can read it

Suggested fix: Run the app commands with an env that drops the PostHog key, key file, and gateway token file.

Comment thread e2e-harness/live-e2e-checks.ts Outdated
hasReadableContent: (file: string) => boolean,
): string[] {
const failures: string[] = [];
const key = env.POSTHOG_PERSONAL_API_KEY?.trim();

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: The preflight is meant to catch a bad key before a 20-minute run, but it reads the key with different rules from the host.

POSTHOG_PERSONAL_API_KEY is set but blank, POSTHOG_KEY_FILE is readable -> preflight passes on the file -> host keeps the blank key -> run fails on auth after the wizard build

Suggested fix: Resolve the key in one shared helper that both the preflight and the host call.


it('passes actual self-driving GitHub gate state to the callable host', async () => {
const notConnected = session();
notConnected.githubConnected = false;

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: This test is meant to prove a caller without a recorded GitHub connection doesn't run, but it uses false rather than the null a fresh session starts with, and it only checks that the agent didn't start.

gate changed to treat anything but false as connected -> fresh session has githubConnected null -> self-driving runs without GitHub -> this test still passes

Suggested fix: Leave githubConnected at the session default and assert the abort message GitHub connection was not confirmed..

Comment thread src/lib/runners/run-program-agent.ts Outdated
? { githubConnected: true, handoffConfirmed: true }
? {
githubConnected: session.githubConnected === true,
handoffConfirmed: session.selfDrivingHandoffConfirmed,

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: The host only checks the handoff flag when a composed integration child is passed, and this adapter never passes one, so the value forwarded here never changes anything.

selfDrivingHandoffConfirmed false -> no integration child in composition -> handoff check skipped -> run proceeds exactly as if it were true

The new test sets it to true for the connected case, which reads as a precondition this path doesn't have.

Suggested fix: Drop handoffConfirmed here and in the test, or add a case where it's false and the run still goes ahead.

Comment thread src/lib/runners/run-program-agent.ts Outdated
programConfig.id === 'self-driving'
? { githubConnected: true, handoffConfirmed: true }
? {
githubConnected: session.githubConnected === true,

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: This turns a hardcoded pass into a real gate, which is a product behavior change, but it ships in a test(programs) commit and the PR body never mentions it.

caller reaches the legacy adapter without a recorded GitHub connection -> used to run -> now aborts with "GitHub connection was not confirmed."

Every current caller already connects first, so nothing breaks today. The risk is a reviewer who never looks here.

Suggested fix: Name the gate change in the PR body, or move it into its own fix(programs): commit.

Comment thread scripts/tui-host.no-jest.ts Outdated
const writeResult = (): void => {
if (!process.env.E2E_RESULT_JSON || resultWritten) return;
const writeResult = (final = false): void => {
if (!process.env.E2E_RESULT_JSON || (resultWritten && !final)) return;

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: Letting the final write replace the outro write is the fix this PR is about, and no test covers it.

guard simplified back to "already written, return" -> integration run writes at outro -> keep-skills result never lands -> snapshot CI reads skillsComplete false, and every check stays green

Suggested fix: Move the write-once-then-final decision into a small e2e-harness helper next to buildE2eResult, with one test that an outro write followed by a final write keeps the second.

Comment thread e2e-harness/tui-snapshot-signature.ts Outdated
@@ -0,0 +1,22 @@
import type { WizardStore } from '@ui/tui/store';

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's the potential issue: The move dropped the note explaining why ctx hashes values rather than keys, and this file and its test skip the JSDoc header every other harness module has.

someone trims ctx to keys -> audit ledger updates in place keep the same key -> audit screen snaps once, empty

Suggested fix: Add a header to both files and restore the "Values, not just keys" comment above ctx.

Set the tree to #1307's shell at a467ba9, so the commits after this add only
the plumbing the shell needs.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
runProgram runs one program from explicit inputs, with no session or UI:
credentials, identify and the AI SDK stamp, the AI approval gate, the
post-auth gates, flags, the binding and its telemetry, the token refresh, then
runAgent with the run tags. It returns the settled outcome with the
invocation's data, settled runs and diagnostics.

- ProgramStore keeps the invocation's data and run ledger, copies on write
  and read, and turns observer failures into diagnostics.
- The token refresh and the AI SDK stamp stay where they live and take plain
  data: refreshCredentialsIfNeeded returns the refreshed credentials, and
  stampAiSdkDetected takes its evidence. maybeStampAiSdkDetected delegates.
- The binding uses the agent's resolveBinding, as B1 does. The switchboard
  telemetry moves into runProgram with it.
- The runner still mints gateway auth from the credentials, as in B1.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
runProgramAgent keeps its B1 path, gates and audit-ledger watcher, and hands
the program to runProgram with the session and getUI() as its host.

- It builds input.run and input.program from the ProgramConfig, and the
  completion hooks from the session, as before.
- Credentials come from authenticate; the AI opt-in and post-auth gates park
  on the UI; flags come from analytics.
- Run progress reaches the UI reducer. Invocation data projects back onto the
  session: a refreshed token, the AI SDK stamp latch, and, once the binding
  resolves, the scan-report cleanup and the linear outro restore.
- A throwing host capability fails the run inside runProgram, so the adapter
  rethrows the original error for the CLI roots, as B1 did.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Detection drives the same runAgent every program uses, on a linear Haiku
binding with read-only tools, instead of initializeAgent and executeAgent.

- The runner supports the run definition's prompt, collectTranscript and
  requestRemark, and RunConfig.scanReport: 'defer'.
- collectTranscript keeps a 256 KiB transcript tail on the run snapshot and
  reports each agent step as an activity event (linear, Anthropic).
- Each attempt is a fresh run with its own deadline signal. A deadline abort
  retries once, then throws AgenticDetectionTimeoutError.
- The report is read from the transcript tail. Activity lines reach onEvent;
  the UI sees the progress it saw before, without the run lifecycle,
  spinner, outro or setup logs.
- The scan defers its scan report to the program run's.
- The agent entry drops initializeAgent, executeAgent and AgentErrorType,
  which only detection used.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
One test per real risk of the new plumbing.

- runProgram: the order from credentials to runAgent, the route and run
  tags, host cancellation during each park, the decided results before the
  agent (including a rejecting credential provider), the failure outcomes, the
  input snapshot, and the identify, stamp and refresh.
- ProgramStore: attributed copies, late events and observer failures as
  diagnostics, and data copied on write and read.
- The adapter: a login failure rethrows for the CLI roots, and a refreshed
  token and the stamp latch project back onto the session.
- Detection: both attempts run through runAgent on the detection binding with
  their own prompt, no remark and a deferred scan report; activity lines
  reach onEvent while the run lifecycle and setup logs stay off the UI.
- The token refresh test follows refreshCredentialsIfNeeded.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@gewenyu99 gewenyu99 changed the title feat(programs): B3 plumbing and tests — runProgram host, adapter wiring, legacy cuts feat(programs): B3 plumbing and tests — runProgram, adapter wiring, detection via runAgent Sep 24, 2026
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Carries main's audit ledger removal (#1336) through the adapter.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Keeps the detection tests here, where detection runs through runAgent.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
… banner

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@gewenyu99
gewenyu99 added this pull request to stack #1362 September 25, 2026 15:16

@johncwaters johncwaters left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Automated review. Not written by a human.

Verdict: REQUEST CHANGES

See inline comments. The real John is already reading with physical eyes.

Comment thread src/programs/run-program.ts Outdated
Comment thread src/programs/run-program.ts Outdated
Comment thread src/programs/run-program.ts
Comment thread src/programs/run-agent-legacy.ts
Comment thread src/programs/run-agent-legacy.ts
Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Main's OAuth session now owns when to refresh. runProgram configures it
with the invocation's login and the refresh-token grant, now in
credentials.ts, and every rotation lands in data through onRefreshed.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
…agnostics

- The AI SDK stamp moves to posthog-integration/ai-sdk-stamp.ts, and detect.ts
  re-exports it. runProgram no longer loads detection or the registry.
- A cancel during the pre-run refresh keeps the rotated token in data and in
  the shared OAuth session.
- runSessionProgram logs each runProgram diagnostic.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@johncwaters

Copy link
Copy Markdown
Contributor

FYI for the next round (not blocking, already approved). runProgram still pulls in @ui at import time, just a hop further out than the two imports you fixed:

run-program.ts > credentials.ts > @utils/oauth > @ui

oauth.ts:7 imports getUI, and loading @ui runs setDebugSink (ui/index.ts:14), so a headless caller gets debug() routed to LoggingUI just by importing runProgram. Same deal with analytics.ts:12 > @lib/wizard-session.

Both are pre-existing and allowlisted (known-violations.json:124-125), and Ink / the TUI store never load, so the stack goal holds. Proooobably worth pulling refreshAccessToken out of oauth.ts into something UI-free when you do the strict pass tho

@gewenyu99

Copy link
Copy Markdown
Collaborator Author

@johncwaters Yeah good shoute

FYI for the next round (not blocking, already approved). runProgram still pulls in @ui
This is true. We will be doing actual hard ts compile level boundaries. But all at once is ahrder t oreview/test. Will pinky promise to handle

@gewenyu99
gewenyu99 merged commit 527ef21 into main Sep 25, 2026
19 checks passed
@gewenyu99
gewenyu99 deleted the posthog/functional-b3-parity branch September 25, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants