Skip to content

[AIGTWY-4880] Add account auth for CUJ5 with shared credentials - #913

Closed
andy-xu-db wants to merge 1 commit into
mainfrom
andy-xu-db/stack/andy/aigtwy-4880-account-auth
Closed

andy-xu-db wants to merge 1 commit into
mainfrom
andy-xu-db/stack/andy/aigtwy-4880-account-auth

Conversation

@andy-xu-db

@andy-xu-db andy-xu-db commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

🥞 Stacked PR

Use this link to review incremental changes.


Summary

Match PR #930's dedicated-workspace authentication shape for CUJ5. The workflow supplies UCODE_TEST_WORKSPACE plus the shared CUJ service-principal credentials; the runner uses its standard workspace OAuth path and adds one account-scoped exchange for the account budget API.

Changes

  • Keep mint_m2m_token as the existing workspace-only helper used by other integration jobs.
  • Add mint_account_m2m_token for /oidc/accounts/{account_id}/v1/token, using the same client ID and secret.
  • Accept CUJ5 workspace, account, budget, and model metadata from the workflow instead of hardcoding a target in the runner.
  • Forward non-secret UG_BUDGET_* metadata and the minted account token only to pytest, while keeping credentials and caller-supplied tokens out of native agent processes and evidence.
  • Preserve the bounded test deadline and interrupt grace period needed to restore a mutated budget.

Workflow contract

PR #911 declares the target in .github/workflows/integration.yml. It maps UG_CUJ5_WORKSPACE, UG_CUJ_SP_CLIENT_ID, and UG_CUJ_SP_CLIENT_SECRET in the same format as PR #930, then provides the account, budget, and model identifiers as CUJ5 job environment values. This PR contains no fixed CUJ5 target values.

Verification

  • 19 runner tests passed.
  • The complete stack passed 119 focused runner, contract, fixture, evidence, and Codex regression tests.
  • Ruff, formatting, and diff checks passed.
  • A previous live CUJ5 run verified workspace OAuth, account-budget mutation and restoration, and all seven journeys with the shared credentials.

@andy-xu-db
andy-xu-db force-pushed the andy-xu-db/stack/andy/aigtwy-4880-account-auth branch 4 times, most recently from e61d623 to 4fc5d70 Compare September 30, 2026 20:49
@andy-xu-db andy-xu-db changed the title [AIGTWY-4880] Add account auth support to the integration runner [AIGTWY-4880] Configure budget integration workspace and account targets Sep 30, 2026
@andy-xu-db
andy-xu-db force-pushed the andy-xu-db/stack/andy/aigtwy-4880-account-auth branch from 4fc5d70 to 3a4a526 Compare October 1, 2026 14:38
@andy-xu-db andy-xu-db changed the title [AIGTWY-4880] Configure budget integration workspace and account targets [AIGTWY-4880] Share integration credentials with budget tests Oct 1, 2026
@andy-xu-db
andy-xu-db force-pushed the andy-xu-db/stack/andy/aigtwy-4880-account-auth branch 7 times, most recently from eff75a9 to 53d70a5 Compare October 1, 2026 18:51
@andy-xu-db andy-xu-db changed the title [AIGTWY-4880] Share integration credentials with budget tests [AIGTWY-4880] Add account auth for CUJ5 with shared credentials Oct 1, 2026
@andy-xu-db
andy-xu-db force-pushed the andy-xu-db/stack/andy/aigtwy-4880-account-auth branch 7 times, most recently from bb6457e to 75792ec Compare October 2, 2026 16:49
@andy-xu-db
andy-xu-db force-pushed the andy-xu-db/stack/andy/aigtwy-4880-account-auth branch from 75792ec to f258ae5 Compare October 2, 2026 17:03
@andy-xu-db

Copy link
Copy Markdown
Collaborator Author

Consolidated into #911, which now contains the complete CUJ5 integration test change as one commit against main.

@andy-xu-db andy-xu-db closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant