mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
The thread detail endpoint already returned metadata for non-owners, but the transcript hydration endpoints (state, stream/events, history, pr-diff) all asserted ownership and 404-ed. This caused the UI to redirect non-owners back to /agents when they clicked an "Open in Web" link shared in Slack. Dashboard login is already gated by ALLOWED_GITHUB_ORGS, so any logged-in user is a trusted org member. This commit: - Adds _thread_is_readable / _assert_thread_readable helpers that grant read access to any surfaced-source thread for authenticated users - Relaxes read endpoints (state, stream/events, history, pr-diff, SSE stream) to use readable checks instead of ownership checks - Keeps write endpoints (send message, cancel, delete, resolve, run commands) owner-only - Adds an isOwner field to the thread summary so the frontend can render a read-only mode (hides the prompt bar, resolve/delete buttons) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| admin.py | ||
| agent_instructions.py | ||
| agent_overrides.py | ||
| agent_usage.py | ||
| analyzer_cron.py | ||
| autofix_state.py | ||
| enabled_repos.py | ||
| eval_jobs.py | ||
| oauth.py | ||
| options.py | ||
| pr_diff.py | ||
| profiles.py | ||
| repo_access.py | ||
| review_api.py | ||
| review_chat_api.py | ||
| review_style_jobs.py | ||
| review_styles.py | ||
| routes.py | ||
| schedules.py | ||
| slack_oauth.py | ||
| team_credentials.py | ||
| team_settings.py | ||
| thread_api.py | ||
| user_credentials.py | ||
| user_mappings.py | ||