Skip to content

fix(mothership): let Chat read its own permission config and file version history - #8839

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/chat-own-config-file-versions
Oct 9, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/chat-own-config-file-versions

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • workspaces permission-config and files versions list|describe|read|revert answered every Chat call with 403 This operation is unavailable through Mothership, because their use cases admitted no delegated caller
  • permission_groups.read_user_config now admits Copilot delegation (sim:settings) through the same use case. Chat reads the delegating member's own group config in the chat's workspace. The use case resolves the subject user instead of reading principal.userId
  • files.versions.list, .read, .read_content and .revert now admit Copilot delegation through the existing workspace-file funnel (sim:workspace-files). Chat gets the delegating user's role and files.use capability, pinned to its workspace
  • Version text reads from Chat go through the same secret-provenance delivery observer as current-file reads: the snapshot's provenance is imported into the chat's secret registry, and a read without a registry fails with 503 before any bytes reach the model
  • files.versions.delete (irreversible purge) and files.versions.download (raw bytes) stay direct-only. The policy comment that deferred delegated version access now records this split
  • Workspace API key and direct-caller admission are unchanged. Executor delegation is not added
  • copilot-refused-routes.json regenerated from the route inventory (the source for the CLI's mothershipUnavailable flag): version delete and download stay listed as refused

Type of Change

  • Bug fix

Testing

  • New lib/permission-groups/__integration__/copilot-permission-config.integration.ts (real Postgres, Chat's in-process CLI transport, real route and use case): two members each read their own group; a chat pinned to another workspace and a user with no workspace role are both refused with 404 NOT_FOUND. Before the fix all 3 failed; after, 3/3 pass

  • New lib/workspace-files/__integration__/copilot-file-versions.integration.ts (real Postgres, local storage, Chat's composed file-read and scoped transports):

    • a read-only member lists and describes versions
    • a historical version holding a secret reaches the model only as [REDACTED_SECRET], and the same read without a provenance registry answers 503
    • a writer reverts, with the audit recorded as the delegated Copilot actor
    • a read-only member's revert is refused with INSUFFICIENT_WORKSPACE_ROLE
    • version delete and download still answer 403 for Chat

    Before the fix 4 of 5 failed (the direct-only guard passes both ways); after, 5/5 pass

  • Existing lib/permission-groups, lib/workspace-files, lib/api/server/routes, app/api/v2/files, app/api/v2/workspaces, lib/mothership/agent-cli, lib/core/application suites pass (session, personal-key, OAuth and workspace-key cases unchanged)

  • bun run lint, bun run type-check, bun run check:audits (58), docs-manifest:check, block-registry check, root bun run test (one timeout in lib/mothership/agent-cli/services.test.ts under full-suite load; the file passes on its own and does not touch these operations)

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 9, 2026 6:11am UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical impact] The PR appears safe to merge; no actionable defects were found.

Summary

Chat can now read the delegating member’s permission config and list, describe, read, and revert file versions.

  • Workspace, role, and capability checks remain in the shared authorization path.
  • Historical text reads use the existing secret-protection path before model delivery.
  • Version deletion and raw downloads remain direct-only.
  • New integration tests cover delegated reads, refusals, secret protection, and revert attribution.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  Chat[Chat CLI request] --> Scope[Create user and workspace-bound Copilot caller]
  Scope --> Auth[Check workspace and current user access]
  Auth --> Config[Read subject user permission config]
  Auth --> Metadata[List or describe versions]
  Auth --> Text[Read version text and snapshot secret records]
  Text --> Registry{Secret registry available?}
  Registry -->|No| Refuse[Return 503 without content]
  Registry -->|Yes| Protect[Hide secrets before model delivery]
  Auth --> Revert[Write a new version and audit the delegated actor]
  Scope --> DirectOnly[Refuse version delete and raw download]
Loading

Reviews (2) · Last reviewed commit: "chore(mothership): refresh the refused-r..." · Reviewed by Greptile

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the fix/chat-own-config-file-versions branch from 333a003 to 3ba41c8 Compare October 9, 2026 06:11
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit bb60a30 into staging Oct 9, 2026
86 of 89 checks passed

This branch was previously deployed

1 inactive deployment
Preview — 3ba41c89 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant