Repository navigation
fix(server,web): bound image prompts, name provider on consent, render generated images - #460
leoisadev1 wants to merge 4 commits into
Conversation
…t for provider crossing Image tool calls carried the prompt and input-image references on item.started args, request.opened args, approval activities, and observational memory. Bound GenerateImage tool content so only routing fields (operation, provider, allowProvider, count, quality, aspectRatio) persist; prompts and image references never reach the event store, analytics, observational memory, or logs. Crossing providers during an edit relied on the model retrying with allowProvider after a needs-consent result, but nothing recorded the user's agreement. The retried call now opens a one-shot approval card naming the receiving provider, and the persisted approval activity keeps the bounded args so the consent record is machine-readable. Adds a server-side test that renders a finished image in a group chat and coverage for the bounded sinks and the consent card. Model: Devin (Cognition AI), #450
Assistant rows never mounted BotMessageAttachments, and visibleBotChatMessages kept only the last settled assistant record per turn, so a generated image posted mid-turn was shadowed by the final reply. Attachment posts are artifacts: they stay visible next to the answer, and the row now renders them like mobile already does. Model: Devin (Cognition AI), #450
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
|
…details imageConsentDetail preferred allowProvider over an explicit provider pin, but imageRoutePlan honors the pin first, so a retry carrying both showed a card for one provider while another received the images. The card now names the pin. Keeping an attachment post beside the final answer also repeated the turn's step meter and plugin cards on both rows. Turn details now land on the last visible assistant row of the turn in bot and group chats. Model: Devin (Cognition AI), #460
|
Fixed in d355d3c. |
|
Fixed in d355d3c — same root cause as the Devin Review thread: the card now names |
|
Fixed in d355d3c. New |
|
Covered on two levels in d355d3c and the earlier web commit: |
The source check pinned the old stepMeters.get(message.turnId) lookup. It now asserts the once-per-turn gating alongside the meter render. Model: Devin (Cognition AI), #460
What Changed
Bounds image-tool content before it reaches sinks outside the caller's chat transcript, names the provider on the consent card, and fixes generated images not rendering on web.
GenerateImagetool events and persisted activities no longer carrypromptorinputImages.boundedImageToolArgsstrips them fromitem.startedargs,request.openedargs, and persistedapproval.requestedactivities (routing fields likeoperation,provider,allowProvider,count,quality,aspectRatiostay). The event store stays clean, which covers analytics and logs; observational memory (processOutputResultand the rollback restore) scrubstool-invocationparts viaboundedImageToolMessage.allowProviderafterneeds-consent, with nothing recording the user's agreement. The retried call now opens the existing one-shot approval card with a provider-aware detail — "Send the chat images to Grok?" — so the persistedrequest.resolved(actor: "user") records real consent, and theapproval.requestedactivity keeps the bounded args so the record stays machine-readable.AssistantMessageRownever mountedBotMessageAttachmentsandvisibleBotChatMessageskept only the last settled assistant record per turn, so a generated image posted mid-turn never rendered on web/desktop. Attachment posts now stay visible next to the final reply, and the row renders them like mobile already does.visibleBotChatMessagescoverage for attachment posts.Refs #450. The one item not covered here is a real generation through each supported subscription path (ChatGPT and Grok) — it needs live provider credentials, which this environment doesn't have; the fake-adapter tests cover both routing paths.
Why
The remaining #450 acceptance items: keep prompts/images out of analytics, memory, logs, and feedback; record user confirmation before crossing providers on edit; and render a finished image in a group chat. Verification surfaced the web render gap — the feature was invisible on the main client, so fixing it is part of exposing image generation.
UI Changes
Before — assistant message rendered text only; the image attachment never appeared:
After — the image paints inline under the assistant reply, and the consent card names the provider:
Checklist
Link to Devin session: https://app.devin.ai/sessions/462eb37e238e43b69e896a94c638a5a9
Open in Devin Desktop: https://app.devin.ai/desktop/session/462eb37e238e43b69e896a94c638a5a9?variant=devin
Requested by: @leoisadev1