From bab99db9e72062c7ff931376affd61b9ef373017 Mon Sep 17 00:00:00 2001 From: Jake Howell Date: Wed, 18 Feb 2026 10:26:45 +1100 Subject: [PATCH] fix: update `` permissions check (#22129) Closes #20965 This pull-request enables a quick permission check that the user is allowed to view the `` under the admin panel. Previously, users would be able to view this page and browse their own logs if they had this permission (which was fine), however now we've decided as this is an admin page, they should only be able to do this via the API/CLI not from the main admin panel. --- .../RequestLogsPage/RequestLogsPage.tsx | 25 +++++++++++++------ 1 file changed, 18 insertions(+), 7 deletions(-) diff --git a/site/src/pages/AIBridgePage/RequestLogsPage/RequestLogsPage.tsx b/site/src/pages/AIBridgePage/RequestLogsPage/RequestLogsPage.tsx index 07d48e2c26..ee53cbbfde 100644 --- a/site/src/pages/AIBridgePage/RequestLogsPage/RequestLogsPage.tsx +++ b/site/src/pages/AIBridgePage/RequestLogsPage/RequestLogsPage.tsx @@ -1,8 +1,10 @@ import { paginatedInterceptions } from "api/queries/aiBridge"; import { useFilter } from "components/Filter/Filter"; import { useUserFilterMenu } from "components/Filter/UserFilter"; +import { useAuthenticated } from "hooks"; import { usePaginatedQuery } from "hooks/usePaginatedQuery"; import { useFeatureVisibility } from "modules/dashboard/useFeatureVisibility"; +import { RequirePermission } from "modules/permissions/RequirePermission"; import type { FC } from "react"; import { useSearchParams } from "react-router"; import { pageTitle } from "utils/page"; @@ -11,12 +13,21 @@ import { RequestLogsPageView } from "./RequestLogsPageView"; const RequestLogsPage: FC = () => { const feats = useFeatureVisibility(); - const isRequestLogsVisible = Boolean(feats.aibridge); + const { permissions } = useAuthenticated(); + + // Users are allowed to view their own request logs via the API, + // but this page is only visible if the feature is enabled and the user + // has the `viewAnyAIBridgeInterception` permission. + // (as its defined in the Admin settings dropdown). + const isEntitled = Boolean(feats.aibridge); + const hasPermission = permissions.viewAnyAIBridgeInterception; + const canViewRequestLogs = isEntitled && hasPermission; const [searchParams, setSearchParams] = useSearchParams(); - const interceptionsQuery = usePaginatedQuery( - paginatedInterceptions(searchParams), - ); + const interceptionsQuery = usePaginatedQuery({ + ...paginatedInterceptions(searchParams), + enabled: canViewRequestLogs, + }); const filter = useFilter({ searchParams, onSearchParamsChange: setSearchParams, @@ -42,12 +53,12 @@ const RequestLogsPage: FC = () => { }); return ( - <> + {pageTitle("Request Logs", "AI Bridge")} { }, }} /> - + ); };