Skip to content

SMOODEV-3412: Add the changeset #577 needed to release - #578

Merged
brentrager merged 1 commit into
mainfrom
SMOODEV-3412-require-owned-changeset
Oct 1, 2026
Merged

brentrager merged 1 commit into
mainfrom
SMOODEV-3412-require-owned-changeset

Conversation

@brentrager

Copy link
Copy Markdown
Contributor

Problem

#577 merged without a changeset, so the release workflow has nothing to bump. No version, no version:sync stamping the crates, no crates.io publish — and therefore nothing for smooai to consume. with_require_owned_conversations is on main and unreachable from the consumer that needs it.

Confirmed: .changeset/ on main holds only README.md and config.json.

Solution

Adds the changeset. minor — a new public builder on AppState, additive and off by default.

Sequencing (unchanged, and it matters)

The flag fails closed by design: it is checked before the scope match, so a UserScope::Denied principal — one whose token carries no email claim — reaches nothing at all.

  1. ✅ smooai#5206 — the email claim on the minted operator token. Already merged.
  2. This PR → release → crates.io.
  3. Bump smooai-smooth-operator-server in smooai.
  4. Then set the flag on copilot-ws.

Enabling the flag before step 1 had deployed would have refused every conversation read rather than leaking through — the right direction, but it would have broken the drawer.

🤖 Generated with Claude Code

#577 merged without one, so `changeset version` had nothing to bump — no
version, no `version:sync` onto the crates, no crates.io publish, and therefore
nothing for smooai to consume. The flag was on main and unreachable.

`minor`: a new public builder on `AppState`, additive and off by default.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b4802de

The changes in this PR will be included in the next version bump.

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@brentrager
brentrager merged commit 714b7bb into main Oct 1, 2026
1 check passed
brentrager added a commit that referenced this pull request Oct 1, 2026
…oot (#579)

My changeset named `@smooai/smooth-operator-js`, which is the PRIVATE root
package.json — not a package changesets manages. `changeset version` then threw
"Found changeset require-owned-conversations for package
@smooai/smooth-operator-js which is not in the workspace" and the release failed,
which means my fix has been breaking the release on every push to main since
#578 landed, not just failing to publish itself.

The published one is `@smooai/smooth-operator` (typescript/package.json, the only
non-private member); `version:sync` stamps its version onto the crates, which is
the number smooai needs.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant