mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 08:03:15 +00:00
The thread detail endpoint already returned metadata for non-owners, but the transcript hydration endpoints (state, stream/events, history, pr-diff) all asserted ownership and 404-ed. This caused the UI to redirect non-owners back to /agents when they clicked an "Open in Web" link shared in Slack. Dashboard login is already gated by ALLOWED_GITHUB_ORGS, so any logged-in user is a trusted org member. This commit: - Adds _thread_is_readable / _assert_thread_readable helpers that grant read access to any surfaced-source thread for authenticated users - Relaxes read endpoints (state, stream/events, history, pr-diff, SSE stream) to use readable checks instead of ownership checks - Keeps write endpoints (send message, cancel, delete, resolve, run commands) owner-only - Adds an isOwner field to the thread summary so the frontend can render a read-only mode (hides the prompt bar, resolve/delete buttons) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| dashboard | ||
| integrations | ||
| middleware | ||
| skills | ||
| tools | ||
| utils | ||
| analyzer.py | ||
| chat.py | ||
| ci_autofix.py | ||
| ci_monitor.py | ||
| encryption.py | ||
| prompt.py | ||
| review_style_collector.py | ||
| review_style_guidance.py | ||
| reviewer.py | ||
| reviewer_diff.py | ||
| reviewer_eval_store.py | ||
| reviewer_findings.py | ||
| reviewer_groups.py | ||
| reviewer_publish.py | ||
| reviewer_reconcile.py | ||
| scheduler.py | ||
| server.py | ||
| webapp.py | ||