mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 08:03:15 +00:00
fix: restore org-wide read access to agent threads (#1474)
The viewed-marker feature (#1441) reintroduced an owner-only gate on thread reads, regressing #1425 which made all threads readable by any org user. Reads no longer assert ownership; viewed markers are only written for the thread owner. Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
This commit is contained in:
parent
da8f003933
commit
722279e277
2 changed files with 20 additions and 2 deletions
|
|
@ -428,7 +428,7 @@ async def get_dashboard_thread(
|
|||
raise HTTPException(404, "thread not found") from exc
|
||||
|
||||
metadata = thread.get("metadata") if isinstance(thread.get("metadata"), dict) else {}
|
||||
_assert_thread_owner(metadata, login, email)
|
||||
is_owner = _user_owns_thread(metadata, login, email)
|
||||
|
||||
messages: list[dict[str, Any]] = []
|
||||
try:
|
||||
|
|
@ -454,7 +454,7 @@ async def get_dashboard_thread(
|
|||
else None
|
||||
),
|
||||
)
|
||||
if mark_viewed and status != "running":
|
||||
if mark_viewed and is_owner and status != "running":
|
||||
metadata = await _mark_thread_viewed(
|
||||
client,
|
||||
thread_id,
|
||||
|
|
|
|||
|
|
@ -83,6 +83,24 @@ async def test_get_dashboard_thread_marks_finished_thread_viewed(monkeypatch) ->
|
|||
assert client.threads.thread["metadata"]["last_viewed_run_id"] == "run-1"
|
||||
|
||||
|
||||
async def test_get_dashboard_thread_readable_by_non_owner(monkeypatch) -> None:
|
||||
client = FakeClient(
|
||||
{
|
||||
"source": "slack",
|
||||
"github_login": "octocat",
|
||||
"latest_run_id": "run-1",
|
||||
"latest_run_status": "success",
|
||||
},
|
||||
"success",
|
||||
)
|
||||
monkeypatch.setattr(thread_api, "langgraph_client", lambda: client)
|
||||
|
||||
result = await thread_api.get_dashboard_thread("tid", "someone-else")
|
||||
|
||||
assert result["status"] == "finished"
|
||||
assert "last_viewed_run_id" not in client.threads.thread["metadata"]
|
||||
|
||||
|
||||
async def test_get_dashboard_thread_skips_mark_viewed_when_disabled(monkeypatch) -> None:
|
||||
client = FakeClient(
|
||||
{
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue