Skip to content

fix(access-requests): scope previews and audit events correctly - #7873

Merged
waleedlatif1 merged 1 commit into
stagingfrom
codex/access-request-followup-audit
Sep 16, 2026
Merged

waleedlatif1 merged 1 commit into
stagingfrom
codex/access-request-followup-audit

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Scope approval fingerprints to affected workspaces and relevant permission groups so unrelated organization changes no longer force another review.
  • Keep request lifecycle audit events in their canonical workspace, while member credit-limit requests remain organization-scoped.
  • Raise submissions from 25 to 100 per rolling 24 hours, retaining the pending-request safeguard without adding quota labels.

Type of Change

  • Bug fix

Testing

  • 509 permission, application, and audit tests passed, including PostgreSQL coverage for revision changes and unrelated edits.
  • Lint, all 46 repository audits (including API boundary validation), docs manifest checks, and type checks across all 26 workspaces passed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 16, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 16, 2026 3:38am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 10 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/permission-access-requests/application/requests.ts
@greptile-apps

greptile-apps Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no outstanding findings or newly introduced issues since the previous review.

Summary

This PR narrows access-request approval fingerprints to relevant workspaces, groups, grants, and memberships; preserves canonical workspace attribution for request lifecycle audit events; and raises the rolling 24-hour submission limit from 25 to 100.

  • Distinguishes explicit organization-scoped audit entries with workspaceId: null.
  • Attributes creation, cancellation, decline, and fulfillment events to each request’s stored workspace scope.
  • Limits impact revisions to policy changes capable of affecting the reviewed workspaces.
  • Centralizes pending-request and submission-window limits.
  • Adds unit and PostgreSQL coverage for audit attribution and fingerprint invalidation boundaries.

Reviews (2) · Last reviewed commit: "fix(access-requests): scope previews and..."

Comment thread apps/sim/lib/permission-access-requests/impact.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 10 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit dec53e2 into staging Sep 16, 2026
33 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/access-request-followup-audit branch September 16, 2026 04:03

This branch was previously deployed

1 inactive deployment
Preview — 789ffb77 Deployed Sep 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant