Skip to content

[Promotion] Add Org Announcements authoring support - #359

Open
SophieS0ng wants to merge 49 commits into
mainfrom
users/rebova/org-announcements-prerelease
Open

SophieS0ng wants to merge 49 commits into
mainfrom
users/rebova/org-announcements-prerelease

Conversation

@SophieS0ng

Copy link
Copy Markdown

Summary

Promote the reviewed Org Announcements authoring stack from
users/rebova/org-announcements-prerelease to main.

This PR consolidates the previously reviewed and merged implementation slices
into the final repository promotion boundary. It also removes the temporary CI
branch filters that were added only to support the stacked review process.

Included work

Together, these changes provide:

  • shared deployed-agent discovery and account-bound authentication
  • Org Announcements create, read, update, delete, publish, schedule, archive,
    duplicate, and audience-selection contracts
  • WeveNova OData request/response adaptation
  • Microsoft Graph user and group audience discovery
  • MCP tools and hosted-widget protocol support
  • Maker skill instructions and setup/package integration
  • privacy-safe diagnostics and credential-recovery guidance

CI cleanup

The following temporary pull-request target filters were required while the
stacked PRs targeted user branches:

  • users/rebova/org-announcements-prerelease
  • users/rebova/org-announcements-review-*

Now that the complete stack is merged into the prerelease branch, this PR
removes both filters and updates
tests/mcp/agentconfig_core/test_ci_contract.py accordingly.

Normal CI coverage for main and release/** is preserved.

Validation

Local validation on September 28, 2026:

  • Org Announcements configuration tests
  • Foundation setup router tests
  • 742 tests passed
  • CI contract cleanup test: 1 passed
  • git diff --check passed

The promotion PR targets main, so the repository's normal main-target CI
should run without the temporary user-branch filters.

Release validation

This PR is the consolidated code-review and CI boundary. The individual stack
merges established the reviewed implementation on the prerelease branch; they
did not independently approve production rollout.

The following live validation remains separate from the offline test coverage:

  • authorized Microsoft Graph integration
  • deployed WeveNova Authoring service integration
  • hosted Vorpal widget integration
  • end-to-end Admin authoring validation
  • final rollout and release approval

Review request

Please review the complete prerelease-to-main integration and confirm:

  • the stacked implementation is ready to enter main
  • the temporary CI review-branch configuration has been fully removed
  • the remaining live integration work is recorded accurately
  • no additional release-branch promotion step is required

This PR should remain a draft until the final promotion target and required
release gates are confirmed.

Extract read-only deployed-agent discovery and reuse tenant-local account matching. Preserve account-bound token refresh and safe authentication failures. Add isolated regression coverage and narrowly scoped review-stack CI targets.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Normalize token-file I/O failures without exposing the configured path or falling back to another credential source. Preserve the original exception as the cause. Limit MCP test-loader warning suppression to the known Pydantic category and cover caller warning policies and module cleanup.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Keep known credential failures actionable through MCP responses without exposing private details. Distinguish local sign-in timeout and cover plain/widget error serialization while preserving account binding and replay behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
* feat(agentconfig): share authoring identity and agent discovery

Extract read-only deployed-agent discovery and reuse tenant-local account matching. Preserve account-bound token refresh and safe authentication failures. Add isolated regression coverage and narrowly scoped review-stack CI targets.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27

* fix(agentconfig): sanitize token reads and narrow test warnings

Normalize token-file I/O failures without exposing the configured path or falling back to another credential source. Preserve the original exception as the cause. Limit MCP test-loader warning suppression to the known Pydantic category and cover caller warning policies and module cleanup.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27

* fix(agentconfig): preserve actionable credential failures

Keep known credential failures actionable through MCP responses without exposing private details. Distinguish local sign-in timeout and cover plain/widget error serialization while preserving account binding and replay behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27

---------

Co-authored-by: Reilly Bova <rebova@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Add typed announcement drafts and the tenant-and-agent-scoped authoring client. Preserve canonical save results, ownership checks, lifecycle semantics, and indeterminate-write recovery. Keep contract tests independent of the future MCP runtime.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Retain typed primary actions and incomplete targets in editable copies without relaxing structural, scope, or write constraints. Explain Standard priority labels in the model-facing schema and distinguish parsing from backend action validity.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 15e9d51c-c328-48e6-9948-8819f9e57f90
…-review-contracts

[2/5] Add agent-scoped announcement models and authoring client
Search eligible directory groups by name or email with one combined bounded Graph query. Bind independent Graph credentials and metadata caches to the intended authoring tenant and account, preserving safe invalidation and diagnostic handling.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Follow Graph next links during audience resolution, report exact search exhaustion correctly, and cover cached token reuse with regression tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
…-review-audience

[3/5] Add account-bound Graph audience discovery
Expose separate announcement manager and editor entry points with validated flat arguments, scoped retry context, captured directory leases, and widget-owned mutations. Preserve indeterminate and committed-refresh recovery, safe telemetry, and independent provider discovery.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Describe read-only repairable copies and cover zero-write opening, priority preservation, unresolved audiences, backend action errors, and non-repeating committed-refresh failures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 15e9d51c-c328-48e6-9948-8819f9e57f90
Sanitize model-visible backend failures and hide validation input values while preserving structured app-only mutation errors.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Add the announcements skill, prompt, setup materialization, and Maker Profile entry point. Keep discovery on the announcements provider, require deployed-agent context, and document recovery and credential limits. Preserve the reviewed 0.4.25 package and existing upstream setup behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Map Important and Informational explicitly, continue review-only creation after unresolved audience lookup, and distinguish repairable copies from backend-valid saved actions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 15e9d51c-c328-48e6-9948-8819f9e57f90
Publish the announcement-enabled VSIX as 0.4.26 and add cross-platform checks that keep the packaged extension aligned with its source and manifest.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Adapt the authoring client to the WeveNova EssBulletins OData contract while preserving the existing MCP and widget-facing lower-camel contract. Reload canonical saved resources, keep delete tombstones non-readable, and prevent committed writes from being retried after refresh failures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Preserve OData canonical reload semantics and validate keyed response identity.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Make authoring construction and cleanup cancellation-safe, sanitize model-visible discovery failures, and cover every registered tool with privacy-safe telemetry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Align repo and solution routing, refresh feature dependencies for completed workspaces, and strengthen cross-entry-point and server cache regression coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
SophieS0ng and others added 16 commits September 25, 2026 16:13
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Validate provider enums at the OData boundary, retry only committed keyed GET 404s, preserve closed DTO projections, and add provider-derived contract coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Distinguish renewable cached MSAL sign-ins from explicit environment tokens, token files, and malformed identity credentials before advising a retry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
…-review-runtime

[4/5] Expose the scoped announcement MCP runtime
Add the announcements skill, prompt, setup materialization, and Maker Profile entry point. Keep discovery on the announcements provider, require deployed-agent context, and document recovery and credential limits. Preserve the reviewed 0.4.25 package and existing upstream setup behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eddd3818-bb74-42d3-bcf3-7e0670a57f27
Map Important and Informational explicitly, continue review-only creation after unresolved audience lookup, and distinguish repairable copies from backend-valid saved actions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 15e9d51c-c328-48e6-9948-8819f9e57f90
Publish the announcement-enabled VSIX as 0.4.26 and add cross-platform checks that keep the packaged extension aligned with its source and manifest.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Align repo and solution routing, refresh feature dependencies for completed workspaces, and strengthen cross-entry-point and server cache regression coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
Distinguish renewable cached MSAL sign-ins from explicit environment tokens, token files, and malformed identity credentials before advising a retry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19335911-b012-4b7f-b179-e4caeae7ea69
…-review-maker

[5/5] Wire announcement maker entry points and setup
…ents-review-odata

[6/6] Migrate announcement authoring to the OData contract
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4276d4a0-2a35-4f07-a7fd-e7d86188d388
@SophieS0ng SophieS0ng changed the title [7/6] Promote Org Announcements authoring support [Promotion] Add Org Announcements authoring support Sep 28, 2026
Adapt the reviewed announcement stack to the current DA-GA setup flow, preserve main-ca CI coverage, and rebuild the Maker Profile as 0.4.29.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4276d4a0-2a35-4f07-a7fd-e7d86188d388
Force telemetry on and stub event delivery so the legacy lite identity regression does not depend on runner network or persisted consent state.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4276d4a0-2a35-4f07-a7fd-e7d86188d388
@SophieS0ng
SophieS0ng marked this pull request as ready for review September 28, 2026 19:23
@apurvabanka

Copy link
Copy Markdown
Contributor

Reviewed the full diff and ran the suites locally: tests/mcp + tests/setup/test_org_announcements_integration.py + tests/scripts/test_maker_profile_vsix.py → 1186 passed, 22 skipped, and ruff check is clean. The lifecycle handling here is genuinely careful — the committed-vs-failed write distinction, the compare-and-swap client/token invalidation, and the content-free telemetry allowlist are all well done. A few gaps worth addressing before merge:

1. Interactive sign-in failures surface as InvalidRequest (high)

_construct_and_publish_client (server.py ~L314) catches (LocalCredentialError, LockException, OSError). But acquire_token_msal_interactive raises a plain ValueError in two cases — MSAL failure (base_client.py ~L205) and the 300-second browser-callback timeout (~L275) — and since LocalCredentialError is a ValueError subclass, the plain case isn't caught. It escapes to _to_failure, which falls through to _FailureResult("InvalidRequest", str(error)).

That routes a sign-in timeout to the wrong maker guidance. Per org-announcements/SKILL.md L400, InvalidRequest means "Explain what to change; do not retry the same call" — but a browser-callback timeout is precisely a retryable AuthenticationRequired. The existing coverage (test_mcp_app_protocol.py:2501) only exercises the LocalCredentialError path, so the gap isn't caught.

Suggested fix: widen the catch to (ValueError, LockException, OSError) — it already maps to AuthenticationRequired.

2. tests/setup/test_da_setup_router.py runs in no CI job (medium)

The new org-announcements job lists only tests/setup/test_org_announcements_integration.py. test_da_setup_router.py is modified by this PR but isn't executed by any job in ci.yml. Either run tests/setup wholesale or add the file explicitly.

3. Discovery tools don't catch ValueError (medium)

list_agent_configs and search_agents catch (_FailureResult, AgentConfigApiError, httpx.RequestError). A ValueError — from search_agents input validation, from _validate_https_base_url on a bad ORG_ANNOUNCEMENTS_BASE_URL, or from issue 1 above — escapes as an unstructured FastMCP error with no telemetry event emitted. Every other tool in the file includes ValueError in its handler; these two look like an oversight.

Minor / non-blocking

  • search_audience_groups returns {status, code, retryable} on failure, while the mutation tools return {...scope, status, errors[]}. If that asymmetry is deliberate it's worth a comment, since the widget has to branch on two failure shapes.

  • Neither _client nor _graph_client is closed on server shutdown. Process exit covers it in practice, but there's no lifespan hook — worth noting if the server is ever hosted in-process.

  • agent_discovery._to_api_payload is unused within its own module (it exists for the landing-page client's import). A one-line comment would save the next reader a grep.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants