fix: restore org-wide read access to agent threads (#1474)

The viewed-marker feature (#1441) reintroduced an owner-only gate on
thread reads, regressing #1425 which made all threads readable by any
org user. Reads no longer assert ownership; viewed markers are only
written for the thread owner.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
This commit is contained in:
Johannes du Plessis 2026-06-09 16:41:07 -07:00 • committed by GitHub
parent da8f003933
commit 722279e277
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 20 additions and 2 deletions

View file

@ -428,7 +428,7 @@ async def get_dashboard_thread(
raise HTTPException(404, "thread not found") from exc
metadata = thread.get("metadata") if isinstance(thread.get("metadata"), dict) else {}
_assert_thread_owner(metadata, login, email)
is_owner = _user_owns_thread(metadata, login, email)
messages: list[dict[str, Any]] = []
try:
@ -454,7 +454,7 @@ async def get_dashboard_thread(
else None
),
)
if mark_viewed and status != "running":
if mark_viewed and is_owner and status != "running":
metadata = await _mark_thread_viewed(
client,
thread_id,

View file

@ -83,6 +83,24 @@ async def test_get_dashboard_thread_marks_finished_thread_viewed(monkeypatch) ->
assert client.threads.thread["metadata"]["last_viewed_run_id"] == "run-1"
async def test_get_dashboard_thread_readable_by_non_owner(monkeypatch) -> None:
client = FakeClient(
{
"source": "slack",
"github_login": "octocat",
"latest_run_id": "run-1",
"latest_run_status": "success",
},
"success",
)
monkeypatch.setattr(thread_api, "langgraph_client", lambda: client)
result = await thread_api.get_dashboard_thread("tid", "someone-else")
assert result["status"] == "finished"
assert "last_viewed_run_id" not in client.threads.thread["metadata"]
async def test_get_dashboard_thread_skips_mark_viewed_when_disabled(monkeypatch) -> None:
client = FakeClient(
{