Boss Agent Integration Audit Report

Scope Reviewed

Architecture Summary

Boss Agent Core API

The primary Boss Agent service exposes:

These routes are implemented in boss_agent_core.py and represent the contract used by client integrations.

VS Code Extension

The extension is designed around a dedicated API client (src/client.ts) and panel/providers for:

Chrome Extension

The extension background script contains the runtime API client and message router for:

Front-end Login

The login page uses useTenantAuth context hooks and expects to be wrapped by TenantAuthProvider in the global provider tree.

Findings (Before Fixes)

  1. Front-end login provider missing - useTenantAuth() was used on /login, but TenantAuthProvider was not included in app-level providers. - Impact: Runtime crash (useTenantAuth must be used within a TenantAuthProvider).

  2. Chrome extension tool invoke endpoint mismatch - Client called legacy POST /api/v1/mcp/invoke. - Core service exposes POST /api/v1/mcp/tools/{tool_name}/invoke. - Impact: tool invocation failures against current API.

  3. Chrome extension cell health endpoint mismatch - Client called /api/v1/cells/status while core contract uses /api/v1/cells/health/all. - Impact: status panel data failure/inconsistency.

  4. Chrome extension streaming payload/event mismatch - Sent mode instead of orchestration_mode and lacked stream flags. - Parsing expected token; server emits typed SSE events (type: token, content, done). - Impact: broken or partial streaming UX.

  5. Chrome options save message not applied by background worker - Options sent SETTINGS_UPDATED, but background script ignored it. - Impact: updated API URL not guaranteed to apply until extension reload.

  6. VS Code extension tool invoke endpoint mismatch - Used legacy /api/v1/mcp/invoke only. - Impact: tool invoke may fail against new deployments.

  7. VS Code extension non-stream chat response shape variability - Some backends may return response + conversation_id instead of message + conversationId. - Impact: empty responses in UI depending on deployment variant.

Fixes Implemented

  1. Added TenantAuthProvider to global provider composition so login and auth hooks are valid.
  2. Updated Chrome extension to use canonical tool invoke path /api/v1/mcp/tools/{tool}/invoke.
  3. Updated Chrome extension to use /api/v1/cells/health/all.
  4. Updated Chrome chat/stream payloads and SSE parsing to the current Boss Agent schema.
  5. Added background handling for SETTINGS_UPDATED so API URL and runtime config update immediately.
  6. Updated VS Code extension tool invoke to use canonical endpoint, with fallback to legacy endpoint when 404.
  7. Updated VS Code non-stream chat parsing to normalize both old/new response field names.

Validation Run

  1. Add automated contract tests for extension clients against a mocked Boss Agent API schema.
  2. Add CI checks for Chrome extension (lint + unit test harness).
  3. Add VS Code extension integration tests around stream and tool invoke fallback paths.
  4. Add an environment bootstrap script for miz-oki-command-center-ui to ensure next lint is runnable in CI/dev containers.
  5. Standardize on one canonical chat response schema across all Boss Agent deployments to reduce client normalization logic.
← All docsView source on GitHub →