{"record":{"id":"522d910be26af01d","repo":"paperclipai/paperclip","slug":"paperclip-runner-attachment-staging-not-authorized","errorCode":"paperclip_runner_attachment_staging_not_authorized","errorMessage":"paperclip_runner_attachment_staging_not_authorized","messagePattern":"paperclip_runner_attachment_staging_not_authorized","errorType":"error_code","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"server/src/services/native-runtime/native-runner-file-handoff.ts","lineNumber":859,"sourceCode":"        eq(heartbeatRuns.agentId, input.binding.agentId),\n        eq(heartbeatRuns.nativeIssueId, input.binding.issueId),\n        eq(heartbeatRuns.runtimeMode, \"native\"),\n        inArray(heartbeatRuns.status, [\"queued\", \"running\"]),\n        eq(issues.id, input.binding.issueId),\n        eq(issues.companyId, input.binding.companyId),\n        eq(issues.executionRunId, input.binding.runId),\n        eq(agents.id, input.binding.agentId),\n        eq(agents.companyId, input.binding.companyId),\n      ),\n    )\n    .limit(1);\n  if (\n    !run ||\n    [\"paused\", \"terminated\", \"pending_approval\", \"error\"].includes(\n      run.agentStatus,\n    )\n  ) {\n    throw new Error(\"paperclip_runner_attachment_staging_not_authorized\");\n  }\n  const reviewContext = readNativeReviewAssignmentContext(run.contextSnapshot);\n  const nativeReview = reviewContext\n    ? await getNativeReviewAssignment(input.db, {\n        companyId: input.binding.companyId,\n        issueId: input.binding.issueId,\n        agentId: input.binding.agentId,\n        contextSnapshot: reviewContext,\n      })\n    : null;\n  if (run.assigneeAgentId !== input.binding.agentId && !nativeReview) {\n    throw new Error(\"paperclip_runner_attachment_staging_not_authorized\");\n  }\n  const selections = wakeAttachmentSelections(run.contextSnapshot);\n  if (selections.length > MAX_NATIVE_STAGED_ATTACHMENTS) {\n    throw new Error(\"paperclip_runner_attachment_staging_count_denied\");\n  }\n  const workspaceRoot =","sourceCodeStart":841,"sourceCodeEnd":877,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/server/src/services/native-runtime/native-runner-file-handoff.ts#L841-L877","documentation":"Authorization gate for staging runner attachment bytes: the run must exist and its agentStatus must not be paused, terminated, pending_approval, or error. Staging is only permitted for actively running agents; a missing run row or a halted lifecycle state rejects the handoff so paused/failed runs cannot inject files.","triggerScenarios":"Calling the attachment staging entrypoint when the run row is absent (unknown/expired runId), or run.agentStatus is 'paused', 'terminated', 'pending_approval', or 'error'.","commonSituations":"Runner keeps streaming attachments after the task hit a budget hard-stop (paused); staging attempted during an approval gate (pending_approval); stale runner retries after the run errored or was terminated; wrong runId passed by the caller.","solutions":["Check the run's current agentStatus before staging and only stage while the run is active","Resume/restart the run (resolve pause or approval) and then retry the attachment handoff","Verify the runId/binding is correct — a missing run row also produces this error"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"const run = await getRun(runId);\nif (!run || [\"paused\",\"terminated\",\"pending_approval\",\"error\"].includes(run.agentStatus)) {\n  throw new Error(`run ${runId} not stageable (status=${run?.agentStatus ?? \"missing\"})`);\n}","typeGuard":"const isStageableRun = (run) => !!run && ![\"paused\",\"terminated\",\"pending_approval\",\"error\"].includes(run.agentStatus);","tryCatchPattern":"try { await stageAttachmentForRun(input); } catch (e) { if (e.message === \"paperclip_runner_attachment_staging_not_authorized\") { /* stop streaming, wait for resume, or abort the handoff */ } else throw e; }","preventionTips":["Poll run status before and during attachment handoffs; stop staging on any halt state","Handle budget hard-stops and approval gates by suspending file handoff, not forcing it","Validate runId/binding correctness to avoid staging against an expired or wrong run"],"tags":["authorization","lifecycle","agents"],"backgroundTag":"permission-denied","analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-09-18T08:03:59.046Z","contentChangedAt":"2026-09-18T08:03:59.046Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}