fix refresh extension not working#2170
Conversation
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
Here's a visual recap of what changed: Open the full interactive recap |
There was a problem hiding this comment.
Builder reviewed your changes — looks good ✅
Review Details
Incremental Code Review Summary
The latest head changes the ordering in extension-data-set so tools.updated_at is bumped before the tool_data upsert, while retaining the previously added changeset and documentation. The explicitly open comments remain applicable and were not reposted: non-atomic write/refresh behavior, missing readOnly on extension-data-get, and loading full extension bodies during authorization. One agent re-identified the changed ordering as a variation of the already-open atomicity issue; it is intentionally excluded as a duplicate. The second independent review found no additional actionable issue.
Risk level: High, due to access-controlled persistent data mutation and live extension refresh signaling.
No new confirmed findings were identified in this incremental review. The dev server is healthy.
🧪 Browser testing: Will run after this review (PR changes extension refresh behavior).

Summary
Adds two new agent actions,
extension-data-setandextension-data-get, that let the agent directly read and write an extension'stool_datastore without going through the iframe bridge or raw SQL.Problem
Agents had no reliable way to refresh data used by an extension (e.g. a dashboard) from the agent side. The only path was routing through the sandboxed iframe bridge or raw SQL, which is not accessible/safe for agent-driven updates, making it impossible for the agent to seed or refresh data that an extension reads via
extensionData.get()at render time.Solution
Introduce two dedicated actions that wrap access-controlled reads/writes to the
tool_datatable, allowing an agent to fetch fresh data from providers and persist it directly for an extension to pick up on next load.Key Changes
extension-data-setaction: upserts an item into an extension's data store (tool_data), enforcing editor access, a 1MB payload size limit, and scope (userororg) handling with Postgres/SQLite-compatible upsert conflict clauses.extension-data-getaction: reads a single item or lists items from an extension's data store, enforcing viewer access, with support foruser,org, orallscope filtering and a configurable result limit.ensureExtensionsTables()before executing and useresolveAccessto enforce permission checks tied to the extension.SKILL.mddocumentation to describe the new agent-side extension data access pattern, including guidance that this is the correct path for agent-driven dashboard refreshes.To clone this PR locally use the Github CLI with command
gh pr checkout 2170You can tag me at @BuilderIO for anything you want me to fix or change