Skip to content

feat(access-requests): request and review permission access - #7871

Merged
waleedlatif1 merged 3 commits into
stagingfrom
codex/permission-access-requests
Sep 16, 2026
Merged

waleedlatif1 merged 3 commits into
stagingfrom
codex/permission-access-requests

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Let members request permission-group access and increases to administrator-set credit limits from restricted features and a shared request history.
  • Add an organization opt-out, administrator review with explicit group-wide impact, and durable email links to authenticated requests. Reuse existing resource empty states and keep enabled blocks first in the registry.
  • Recheck authorization and policy before applying changes, handle concurrent decisions, and gate rollout behind a global flag that defaults off.

Type of Change

  • New feature

Testing

  • 1,215 focused tests passed, including PostgreSQL migration, concurrent submission, and impact-query tests.
  • Repository lint, all workspace type checks, API boundary validation, full audits, and migration safety checks passed.
  • Reviewed requester and administrator UI states in a local fixture using production components, including mobile and dark mode. Live authentication and email delivery still need a staging smoke test before rollout.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 16, 2026 12:51am UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no outstanding correctness, security, migration, or repository-rule failures were identified.

Summary

This PR adds a feature-flagged permission access-request workflow spanning member requests, administrator review, organization settings, policy revalidation, notifications, and shared request history.

  • Adds authenticated APIs and application services for creating, discovering, listing, cancelling, previewing, and resolving requests.
  • Adds permission-boundary and request-management UI across restricted workspace resources.
  • Persists request state and organization preferences through a matching schema migration.
  • Revalidates global rollout and organization policy before mutations and excludes runtime-discovered private model names from request catalogs.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Member[Workspace member] --> Boundary[Restricted feature boundary]
  Boundary --> Create[Create access request]
  Create --> Requests[(Access-request records)]
  Requests --> Notify[Outbox notification]
  Notify --> Admin[Organization administrator]
  Admin --> Preview[Preview policy impact]
  Preview --> Recheck[Recheck rollout, authorization, and policy]
  Recheck --> Resolve{Decision}
  Resolve -->|Approve| Apply[Apply permission or limit change]
  Resolve -->|Deny| Denied[Record denial]
  Apply --> Requests
  Denied --> Requests
  Member --> History[Request history]
  History --> Requests
Loading

Reviews (3) · Last reviewed commit: "fix(access-requests): recheck rollout an..."

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 109 files

Confidence score: 3/5

  • In apps/sim/ee/access-control/components/access-control.tsx, the permission-access-requests rollout gate can be bypassed, allowing admins to view request history and change the organization opt-out; gate OrganizationAccessRequests and its controls behind the flag.
  • In apps/sim/app/workspace/[workspaceId]/knowledge/knowledge.tsx, the wrapper causes existing knowledge component tests to fail before rendering because Knowledge is mounted without React Query context; mock PermissionAccessBoundary in knowledge.test.tsx or render the required context.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/app/workspace/[workspaceId]/knowledge/knowledge.tsx">

<violation number="1" location="apps/sim/app/workspace/[workspaceId]/knowledge/knowledge.tsx:199">
P2: This wrapper breaks the existing knowledge component tests before the list renders because they mount `Knowledge` without React Query context. Mock `PermissionAccessBoundary` in `knowledge.test.tsx` or render the test through a `QueryClientProvider`.</violation>
</file>

<file name="apps/sim/ee/access-control/components/access-control.tsx">

<violation number="1" location="apps/sim/ee/access-control/components/access-control.tsx:71">
P2: When `permission-access-requests` is disabled, this switch still exposes `OrganizationAccessRequests`; admins can view request history and change the organization opt-out despite the rollout gate. Gate this view and its settings mutations on the global flag.</violation>
</file>

Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread apps/sim/lib/permission-access-requests/policy.ts Outdated
Comment thread apps/sim/components/access-requests/permission-access-boundary.tsx
Comment thread apps/sim/app/workspace/[workspaceId]/tables/tables.tsx
Comment thread apps/sim/app/workspace/[workspaceId]/knowledge/knowledge.tsx
Comment thread apps/sim/ee/access-control/components/access-control.tsx
Comment thread packages/db/schema.ts Outdated
Comment thread apps/sim/lib/permission-access-requests/notification-events.ts Outdated
Comment thread packages/testing/src/mocks/schema.mock.ts
@waleedlatif1
waleedlatif1 force-pushed the codex/permission-access-requests branch from a5e7dae to e1db271 Compare September 16, 2026 00:34
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 129 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/permission-access-requests/application/requests.ts
Comment thread apps/sim/lib/permission-access-requests/application/review.ts
Comment thread apps/sim/lib/permission-access-requests/catalog-registry.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

The latest summary appears to include changes inherited from staging during the rebase. The retired-column migration 0348 and its backfill/dev schema-push changes are already in the staging base (commit 783cf17); they are absent from this PR's current diff against staging. The migration introduced here is 0349_permission_access_requests.sql, which adds the access-request and organization-preference tables. This PR does not change packages/db/scripts or .github/workflows/test-build.yml. Please reassess the current staging-to-HEAD PR diff rather than the previous-head-to-current-head comparison. The access-request migration safety checks and both PostgreSQL CI modes passed.

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 131 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 83c165a into staging Sep 16, 2026
33 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/permission-access-requests branch September 16, 2026 02:13

This branch was previously deployed

1 inactive deployment
Preview — 1addafb4 Deployed Sep 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant