feat: add memory.patch, trim memory.get, unify the memory write path
memory.get no longer returns the embedding and content_tsv ---------------------------------------------------------- It used a bare select() and returned the raw DB row, while memory.list and memory.search already projected an explicit 9-field shape. On a ~13k-char memory those two internal columns were 55% of the response and pushed it past the MCP tool-output cap, so large memories could not be fetched inline at all. memory.get now returns the same 9 fields as its siblings; user_id is still selected for the authorization check and stripped before responding. memory.patch ------------ memory.update only accepts full replacement, so adding one line to a large document meant resending the whole document — expensive enough that edits were being skipped rather than risk silently truncating shared team documents. memory.patch replaces one exact occurrence of old_string. An absent or ambiguous match is an error, never a silent no-op and never an arbitrary pick; that refusal is what makes the operation safe to hand to an agent. The semantics live in lib/memory-patch.ts as a pure function, free of DB and auth, so both surfaces share them. Shared mutation layer --------------------- The MCP tools and the Web UI Server Actions each reimplemented authorize -> mutate -> re-embed -> CAS -> audit, and had drifted. Both now route through lib/memory-mutations.ts. BEHAVIOUR CHANGE: memory.delete over MCP skipped the project ACL whenever the caller authored the row, so a memory written while a share was rw stayed deletable by its author after an owner downgraded that share to ro. memory.update and the whole Web UI always checked. Authoring a row now grants no standing write privilege on any path. The one deliberate difference between the surfaces is injected as a ProjectResolver: MCP refuses an unknown project key so an agent cannot spawn near-miss projects off a typo, while the Web UI creates one because a person typing a name into a form means to. Tests and lint -------------- Adds vitest. The integration tests run against a real Postgres rather than a mocked DB. The embedder sidecar is the only stub and it is deterministic per-text, so re-embedding is verified by asserting the stored vector actually changed rather than that a mock was called. One test pins that content_tsv is a generated column and therefore cannot rot after a patch — only the embedding needs an explicit recompute. pnpm lint previously dropped into an interactive `next lint` setup prompt and exited 1; ESLint had never been configured here. Replaced with the ESLint CLI and a flat config bridging eslint-config-next through FlatCompat. Clean at --max-warnings=0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,76 @@
|
||||
import { MEMORY_CONTENT_MAX } from "@shared-memory/schemas";
|
||||
|
||||
/**
|
||||
* Pure string-level semantics for `memory.patch`.
|
||||
*
|
||||
* Kept free of any DB or auth dependency so both the MCP tool handler and
|
||||
* the Web UI can share it, and so the refuse-rather-than-clobber rules
|
||||
* below are directly testable.
|
||||
*
|
||||
* The contract mirrors the file-editing primitive coding agents already
|
||||
* use: an `old_string` that is absent or ambiguous is an ERROR, never a
|
||||
* silent no-op and never an arbitrary pick. That refusal is the property
|
||||
* that makes the operation safe to hand to an agent editing a shared
|
||||
* document it cannot afford to corrupt.
|
||||
*/
|
||||
export type PatchOutcome =
|
||||
| { ok: true; content: string }
|
||||
| { ok: false; error: string };
|
||||
|
||||
function countOccurrences(haystack: string, needle: string): number {
|
||||
let count = 0;
|
||||
let from = 0;
|
||||
for (;;) {
|
||||
const at = haystack.indexOf(needle, from);
|
||||
if (at === -1) return count;
|
||||
count += 1;
|
||||
// Advance past this match so overlapping matches aren't double-counted.
|
||||
from = at + needle.length;
|
||||
}
|
||||
}
|
||||
|
||||
export function applyPatch(
|
||||
content: string,
|
||||
oldString: string,
|
||||
newString: string,
|
||||
): PatchOutcome {
|
||||
if (oldString === newString) {
|
||||
return {
|
||||
ok: false,
|
||||
error: "old_string and new_string are identical; the patch would change nothing",
|
||||
};
|
||||
}
|
||||
|
||||
const first = content.indexOf(oldString);
|
||||
if (first === -1) {
|
||||
return {
|
||||
ok: false,
|
||||
error:
|
||||
"old_string not found in the memory content; nothing was changed. Fetch the memory with memory.get and copy the exact text you mean to replace.",
|
||||
};
|
||||
}
|
||||
|
||||
// Only pay for a full count once we know there's more than one match.
|
||||
if (content.indexOf(oldString, first + oldString.length) !== -1) {
|
||||
const count = countOccurrences(content, oldString);
|
||||
return {
|
||||
ok: false,
|
||||
error: `old_string matches ${count} times; it must match exactly once. Nothing was changed — include more surrounding context to identify the one you mean.`,
|
||||
};
|
||||
}
|
||||
|
||||
const patched =
|
||||
content.slice(0, first) + newString + content.slice(first + oldString.length);
|
||||
|
||||
if (patched.length === 0) {
|
||||
return { ok: false, error: "the patch would leave the memory empty" };
|
||||
}
|
||||
if (patched.length > MEMORY_CONTENT_MAX) {
|
||||
return {
|
||||
ok: false,
|
||||
error: `the patched content would be ${patched.length.toLocaleString("en-US")} characters, over the ${MEMORY_CONTENT_MAX.toLocaleString("en-US")}-character limit`,
|
||||
};
|
||||
}
|
||||
|
||||
return { ok: true, content: patched };
|
||||
}
|
||||
Reference in New Issue
Block a user