Brings the branch current with dev (was 18 behind) so the PR
squash-merges into dev with zero conflicts. Resolved 6 conflicts:
- backend/main.py: keep both workflows and telegram_bot SubApps
- backend/auth.py: keep the Spotify OAuth callback path exemptions
- backend/apps/agents/agent_manager.py: take the deletions of
_build_connected_tools_context, _approx_tokens, and
_summarize_message_block (confirmed dead, zero callers on dev)
- backend/apps/tools_lib/tools_lib.py: keep both dev's
google_oauth_token_proxy and the MCP credential endpoints
- electron/main.js: keep both the Instagram MCP CLI helpers and
dev's one-line waitForBackend comment
- frontend/src/app/pages/Tools/Tools.tsx: keep the credential dialogs
Also widens the Tools.tsx snackbar severity union to include
'warning', a value its own code already passes (a pre-existing type
error surfaced once dev was merged and tsc was run).
Verified: 832 backend tests pass, webpack build succeeds, tsc clean
except one pre-existing allowpopups error in dev's BrowserCard.tsx.
Removed:
- _connected_phone (L143, 6 lines) — docstring said 'backwards-compat
helper used by the user-account path' but nothing in the repo still
calls it.
Verified zero callers via:
grep -rn '_connected_phone' backend electron frontend/src
Returned only the definition line. 802 tests pass; listener module
imports clean.
Removed:
- _resolve_model (L36, 2 lines)
- MODEL_MAP module-level dict (L29) — only consumed by the deleted
function, so it became orphaned after the cut.
Verified zero callers via:
grep -rn '_resolve_model' backend electron frontend/src
grep -rn 'MODEL_MAP' backend electron frontend/src
The only other MODEL_MAP match (browser_agent.py) is a distinct
module-level dict, not this one. 802 tests pass.
Removed:
- _is_9router_available (L307, 15 lines)
- _9router_cache module-level dict (L186) — only consumed by the
deleted function, so it became orphaned after the cut.
Verified zero callers via:
grep -rn '_is_9router_available' backend electron frontend/src
grep -rn '_9router_cache' backend electron frontend/src
Both showed only intra-module references. 802 tests pass.
Workflow's new-branch fallback fell through to a full repo scan whenever
merge-base with main equaled HEAD (empty range). That re-flagged every
historical secret a prior PR had already cleared. Now: empty range means
nothing new to scan, log + exit clean. Genuine no-shared-history case
still falls through to full scan.
The agent_manager composer iterated tool_permissions._tool_descriptions
to build the per-tool allowlist passed to the claude CLI. When that map
was empty (an MCP tool added without populating it), zero tool names
were allowlisted, so the CLI rejected every sub-tool the server actually
advertised with "No such tool available". Mirror the unknown-tool
fallback: emit mcp__{name}__* and still honor explicit denies.