Document the two mandatory API access conventions that are enforced by
the CI test src/api/no-direct-agent-server-calls.test.ts:
1. All agent-server calls must use typed @openhands/typescript-client
classes (ConversationClient, FileClient, VSCodeClient, ServerClient,
RemoteWorkspace, RemoteEventsList) instantiated via
getAgentServerClientOptions() -- never raw axios/fetch.
2. All cloud SaaS and runtime-sandbox calls must go through
callCloudProxy() in src/api/cloud/proxy.ts to avoid CORS, using
hostOverride for runtime-sandbox URLs and authMode='session-api-key'
for those endpoints.
AGENTS.md gets a full '## API Access Rules' section with client
listings, option helper references, CORRECT/WRONG code examples, and
the allowed-exceptions list.
The custom-codereview-guide.md skill gets a '## Frontend API Access
Conventions' section with DO NOT APPROVE triggers, forbidden pattern
lists, correct examples, and a note about the silent hostOverride bug.
Co-authored-by: openhands <openhands@all-hands.dev>
Adds the Azure DevOps @openhands resolver (PR + work-item mentions, run-as-mentioner with content-marker loop prevention) and an org-level one-click webhook setup. Includes a write-permission gate (permissionevaluationbatch, fails closed), deterministic/fail-closed work-item repo derivation, async webhook processing via BackgroundTasks, type-specific PR/work-item context loaders, and a stable dedup key. Validated live on a Replicated test install.