Skip to content

fix(usage): enforce spend caps for room turns - #1059

Open
casquijo wants to merge 1 commit into
milind-soni:mainfrom
casquijo:codex/security-room-spend-accounting
Open

casquijo wants to merge 1 commit into
milind-soni:mainfrom
casquijo:codex/security-room-spend-accounting

Conversation

@casquijo

Copy link
Copy Markdown
Contributor

What changed

  • Capture immutable usage attribution when each room member is dispatched and record it when the provider turn completes.
  • Recheck the workspace spend cap immediately before room and calendar provider dispatches.
  • Preserve attribution across queued messages and identify routine-driven room goals correctly.
  • Treat capped room goals as blocked instead of retrying them as provider failures.
  • Add regression coverage for rooms, goals, queued users, and calendar calls.

Why

Direct turns were accounted for and capped, but provider-backed room and calendar turns could proceed without equivalent ledger entries or dispatch-time enforcement.

This ensures settled room usage is visible before the next member dispatch and that all affected paths observe the same monthly cap.

How it was verified

  • pnpm typecheck
  • pnpm lint
  • Targeted spend-cap tests: 6 passed
  • Affected and review suites: 147 passed, 1 todo
  • pnpm test
    • Vitest: 461 files passed, 2 skipped; 5,731 tests passed, 40 skipped, 1 todo
    • Broker tests: 8 passed
    • Electron tests: 164 passed
    • Packaged-server smoke passed

Screenshots (UI changes)

Not applicable — no UI changes.

Checklist

  • pnpm typecheck and pnpm test pass locally
  • Server behavior changes come with tests
  • No dist-server/ edits
  • No macOS-only code or shell command construction added
  • No secrets in logs, responses, events, or argv

@vercel

vercel Bot commented Sep 10, 2026

Copy link
Copy Markdown

@casquijo is attempting to deploy a commit to the SupaMaus Team on Vercel.

A member of the Team first needs to authorize it.

@milind-soni

Copy link
Copy Markdown
Owner

Triage update: #1135 is now merged, so the room spend-cap guard, room ledger entries, blocked-goal outcome, and live budget fields already exist on main. This PR is not wholly redundant: capturing the initiating user on each operation/queued item still matters. Current main reads turnTriggers at settlement, which a later queued sender can overwrite. Please rebase this as the narrower immutable-attribution follow-up, preserving the queued-user, calendar-owner, and routine-goal regressions, without adding a second spend/ledger path. Holding the current overlapping version rather than closing it as a duplicate.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants