feat: add network calls list to AI session threads API (#27425)

The AI session threads API returned only a network call *summary*
(total/blocked counts + top domains). This adds the per-call list so the
session detail can render individual Agent Firewall network calls.

`ListAIBridgeSessionNetworkCalls` reuses the same sequence-number
windowing as the existing summary and includes all protocols. The list
is exposed as `network_call_logs` on the threads response and is capped
server-side at 100 rows. The summary (`network_calls.total`/`blocked`)
remains authoritative for whole-session totals: the list length and its
blocked count equal the summary only when a session has at most 100
calls, and are truncated beyond that.

### PR map (merge strictly bottom-up)

This change is a 4-PR stack. Each PR depends on all the ones below it,
so merge in this exact order:

1. #27417 — backend network summary
2. #27418 — frontend summary rows
3. #27425 — backend per-call list `network_call_logs`
4. #27426 — frontend network-calls panel

Refs AIGOV-464

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Sas Swart
2026-08-03 11:34:27 +02:00
committed by GitHub
co-authored by Claude Opus 4.8
parent fba9f0d485
commit 8886a5749a
17 changed files with 432 additions and 61 deletions
+14
View File
@@ -195,6 +195,20 @@ Alias: also available at /api/v2/aibridge/sessions/{session_id} for backward com
"models": [
"string"
],
"network_call_logs": [
{
"allowed": true,
"captured_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"detail": "string",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"matched_rule": "string",
"method": "string",
"proto": "string",
"sequence_number": 0,
"session_id": "1ffd059c-17ea-40a8-8aef-70fd0307db82"
}
],
"network_calls": {
"blocked": 0,
"total": 0
+33 -18
View File
@@ -691,6 +691,20 @@
"models": [
"string"
],
"network_call_logs": [
{
"allowed": true,
"captured_at": "2019-08-24T14:15:22Z",
"created_at": "2019-08-24T14:15:22Z",
"detail": "string",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"matched_rule": "string",
"method": "string",
"proto": "string",
"sequence_number": 0,
"session_id": "1ffd059c-17ea-40a8-8aef-70fd0307db82"
}
],
"network_calls": {
"blocked": 0,
"total": 0
@@ -785,24 +799,25 @@
### Properties
| Name | Type | Required | Restrictions | Description |
|------------------------|------------------------------------------------------------------------------------------|----------|--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `client` | string | false | | |
| `ended_at` | string | false | | |
| `id` | string | false | | |
| `initiator` | [codersdk.MinimalUser](#codersdkminimaluser) | false | | |
| `metadata` | object | false | | |
| » `[any property]` | any | false | | |
| `models` | array of string | false | | |
| `network_calls` | [codersdk.AIBridgeSessionNetworkCallSummary](#codersdkaibridgesessionnetworkcallsummary) | false | | Network calls summarizes the Agent Firewall network calls made during the session. A nil value means the session did not pass through Agent Firewall, so network call monitoring was not active, which the UI surfaces as "Disabled". |
| `network_domain_count` | integer | false | | |
| `network_top_domains` | array of [codersdk.AIBridgeSessionNetworkDomain](#codersdkaibridgesessionnetworkdomain) | false | | Network top domains lists the most contacted destination hosts, ordered by call count descending. NetworkDomainCount is the total number of distinct domains, used to render a "+N more" overflow beyond the listed domains. |
| `page_ended_at` | string | false | | |
| `page_started_at` | string | false | | |
| `providers` | array of string | false | | |
| `started_at` | string | false | | |
| `threads` | array of [codersdk.AIBridgeThread](#codersdkaibridgethread) | false | | |
| `token_usage_summary` | [codersdk.AIBridgeSessionThreadsTokenUsage](#codersdkaibridgesessionthreadstokenusage) | false | | |
| Name | Type | Required | Restrictions | Description |
|------------------------|------------------------------------------------------------------------------------------|----------|--------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `client` | string | false | | |
| `ended_at` | string | false | | |
| `id` | string | false | | |
| `initiator` | [codersdk.MinimalUser](#codersdkminimaluser) | false | | |
| `metadata` | object | false | | |
| » `[any property]` | any | false | | |
| `models` | array of string | false | | |
| `network_call_logs` | array of [codersdk.AgentFirewallLog](#codersdkagentfirewalllog) | false | | Network call logs is the chronological list of individual network calls made during the session, holding the earliest calls up to a server-side cap. NetworkCalls remains authoritative for whole-session totals, so a shorter list than NetworkCalls.Total means the list was truncated. Empty when the session did not pass through Agent Firewall. |
| `network_calls` | [codersdk.AIBridgeSessionNetworkCallSummary](#codersdkaibridgesessionnetworkcallsummary) | false | | Network calls summarizes the Agent Firewall network calls made during the session. A nil value means the session did not pass through Agent Firewall, so network call monitoring was not active, which the UI surfaces as "Disabled". |
| `network_domain_count` | integer | false | | |
| `network_top_domains` | array of [codersdk.AIBridgeSessionNetworkDomain](#codersdkaibridgesessionnetworkdomain) | false | | Network top domains lists the most contacted destination hosts, ordered by call count descending. NetworkDomainCount is the total number of distinct domains, used to render a "+N more" overflow beyond the listed domains. |
| `page_ended_at` | string | false | | |
| `page_started_at` | string | false | | |
| `providers` | array of string | false | | |
| `started_at` | string | false | | |
| `threads` | array of [codersdk.AIBridgeThread](#codersdkaibridgethread) | false | | |
| `token_usage_summary` | [codersdk.AIBridgeSessionThreadsTokenUsage](#codersdkaibridgesessionthreadstokenusage) | false | | |
## codersdk.AIBridgeSessionThreadsTokenUsage