Skip to content

FEAT: Add custom params to new targets in CoPYRIT - #2846

Merged
jbolor21 merged 19 commits into
microsoft:mainfrom
jbolor21:bjagdagdorj/gui_target_params
Oct 7, 2026
Merged

jbolor21 merged 19 commits into
microsoft:mainfrom
jbolor21:bjagdagdorj/gui_target_params

Conversation

@jbolor21

@jbolor21 jbolor21 commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description

Make CopyRIT target creation metadata-driven so users can configure the same JSON-expressible target parameters available through the Python framework.

Previously,  CreateTargetDialog ignored the constructor parameters returned by GET /targets/types and rendered a hardcoded set of fields. This meant parameters such as temperature, seed , reasoning_effort, and extra_body_parameters were unavailable for most targets, and new target types required frontend changes

Screenshot:
(example OpenAI Target - shows "advanced settings")
image

image

Changes:

  • Generatees target parameter controls from /targets/types metadata
  • Supports: strings, numbers, booleans, constrained choices, scalar lists,
  • Keep common connection and authentication fields prominent.
  • Group optional target-specific parameters under Advanced settings.
  • Display constructor defaults as light placeholder and hint text without explicitly submitting them.
  • Omit untouched optional values so target constructors and providers retain ownership of defaults.
  • Validate dictionary parameters as JSON objects and submit parsed objects rather than JSON strings.
  • Use registry metadata to determine which target types can be configured through the UI instead of maintaining a hardcoded target allowlist.
  • Preserve specialized handling for api_key through the authentication UI and for the RoundRobin Target and weights through the inner-target picker
  • Explicitly explain that  custom_functions  cannot be configured in CopyRIT because it requires Python callables.
  • Exclude targets whose required parameters need unsupported live Python objects.

Tests and Documentation

reran existing tests

  • Added frontend policy tests covering supported parameter types: scalars, constrained choices, lists, JSON dictionaries, references, structured values, and unsupported Python objects.
  • Added integration tests verifying that explicit  0 ,  false , and empty-list values are submitted while untouched optional parameters are omitted.
  • Added backend catalog synchronization tests that fail when a target introduces a required parameter that the UI cannot render, specially handle, or explicitly mark as unsupported.
  • Added regression coverage for authentication fields, Round Robin targets and weights, advanced settings, and constructor-default placeholders.
  • Updated E2E coverage to reflect metadata-driven optional endpoints and parameter fields.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 275c7ae2-b8ef-4f2e-990a-f2e9e276deb1
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 275c7ae2-b8ef-4f2e-990a-f2e9e276deb1
@richlundeen

Copy link
Copy Markdown
Contributor

Can you include a screenshot?

Comment thread frontend/src/components/Config/CreateTargetDialog.tsx Outdated
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx Outdated
@hannahwestra25 hannahwestra25 self-assigned this Sep 28, 2026
@jbolor21 jbolor21 changed the title [DRAFT] FEAT: Add custom params to new targets in CoPYRIT FEAT: Add custom params to new targets in CoPYRIT Sep 28, 2026
Comment thread tests/unit/backend/test_target_service.py Outdated
Comment thread tests/unit/backend/test_target_service.py
Comment thread frontend/src/components/Config/targetParameterPolicy.ts Outdated
Comment thread frontend/src/components/Parameters/parameterForm.ts Outdated
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a minor followup comment, and I think Hannah's are valid. But looks good to me once addressed

…sts into

serialized Parameter metadata derived from component identifiers. Mark target
credential fields as sensitive and raw HTTP requests as multiline
Comment thread pyrit/models/identifiers/target_identifier.py Outdated
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx
Comment thread frontend/src/components/Config/targetParameterPolicy.ts Outdated
Comment thread tests/unit/registry/test_target_registry.py Outdated
Comment thread frontend/src/components/Config/targetParameterPolicy.ts Outdated
Comment thread frontend/src/components/Config/CreateTargetDialog.tsx Outdated
Comment thread pyrit/models/identifiers/target_identifier.py Outdated

@hannahwestra25 hannahwestra25 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

overall looks good ! could you update doc/gui/0_gui.md:343 as well ?

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f1b528a9-31d3-4c35-9010-608feb7d0b68
@jbolor21
jbolor21 added this pull request to the merge queue Oct 7, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 7, 2026
@jbolor21
jbolor21 added this pull request to the merge queue Oct 7, 2026
Merged via the queue into microsoft:main with commit 799ea49 Oct 7, 2026
50 checks passed
@jbolor21
jbolor21 deleted the bjagdagdorj/gui_target_params branch October 7, 2026 19:52
hannahwestra25 pushed a commit to hannahwestra25/PyRIT that referenced this pull request Oct 7, 2026
PR microsoft#2846 landed the AzureBlobStorageTarget half of this bug using a
get_auth_mode_parameters classmethod. Adopt that hook as the single
mechanism for carrying auth intent into target construction and drop the
_accepts_auth_mode signature introspection, which only existed because
AzureBlobStorageTarget lacked the parameter.

Every target advertising identity support now overrides the hook, guarded
by a registry-wide contract test so a future identity target cannot
silently fall back to inferring auth from a missing key.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants