mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: audit chat system instructions changes (#27668)
Adds an audit record for administrative events on the deployment-wide
chat instruction settings (system prompt, the include-default toggle,
and the plan-mode instructions), per CODAGT-719 and operator decision
D5. Each endpoint records under a stable identity: resource type
`chat_instruction_settings`, a fixed resource ID and a human-readable
target ("System prompt", "Plan mode instructions"), so two changes to
one setting share an ID and history-by-setting works. A real change
exports a Write entry with the old-to-new text visible; a
value-identical PUT still upserts and still returns 204 but records
nothing.
Attempts are recorded, not only transitions. Identity is assigned before
the authorization check, so a denied PUT exports a 403 row with an empty
diff (no request content reaches it), a validation failure exports a 400
row, and a write failure exports a 500 row, each with an empty diff; an
operator can tell "nothing changed" from "something changed and capture
degraded" by the status code.
The write path stays authoritative. The advisory lock and, on plan-mode,
the transaction exist only to serve change-detection; if any of that
machinery fails (lock, begin, commit, rollback), the handler runs main's
idempotent write path directly and derives the response from it, so a
member-visible failure of audit-only infrastructure can never replace
main's successful response. Accepted consequence: when the lock cannot
be taken, two concurrent identical writes can produce two rows instead
of one. That is audit degradation, which is allowed; changing a member's
response is not. Write failures keep the exact response the endpoint
produced before this wiring (transaction error for the system prompt,
which was always transactional; the raw write error for plan mode, which
was not), and the full transaction error is logged so rollback failures
cannot vanish.
<details>
<summary>CODAGT-66 plan entry: S1 (verbatim)</summary>
**S1 `feat: audit chat system instructions changes`** (CODAGT-719; base:
main)
- Struct: `database.ChatSystemPromptSettings{ID uuid.UUID; SystemPrompt
string; IncludeDefaultSystemPrompt bool; PlanModeInstructions string}`
in `coderd/database/types.go` (ticket-sketched shape; one struct, both
endpoints).
- Registration: union entry (diff.go), table.go entry (`id`
ActionIgnore, other three ActionTrack), `AuditActionMap` Write-only;
four request.go cases (`ResourceTarget` "", `ResourceID` from struct,
`ResourceType` new enum value `chat_system_prompt_settings`,
`ResourceRequiresOrgID` false with the "Artificial ID / deployment
singleton" comment convention).
- Migration: `ALTER TYPE resource_type ADD VALUE IF NOT EXISTS
'chat_system_prompt_settings';` comment-only no-op down (000558 shape);
number picked at push per the numbering constraint.
- codersdk: constant + prose `FriendlyString` ("chat system prompt
settings"); `TestAuditDBEnumsCovered` forces both. `coderd/audit.go`
presentation switches: rely on safe defaults (no link, generic
description); no FE changes (filter label falls back to capitalized
value; acceptable per precedent).
- Wiring `putChatSystemPrompt` and `putChatPlanModeInstructions`:
InitRequest with Action Write; artificial `ID: uuid.New()` on `New` only
when a change is detected; no-op suppression by leaving both aReq sides
unset (nil resource IDs skip the log, request.go skip rule); the write
path itself stays byte-identical (upserts still run unconditionally).
- `putChatSystemPrompt` (writes two keys conditionally in one existing
tx): inside that tx, read the pair via `GetChatSystemPromptConfig` for
`Old`, perform the conditional writes exactly as today, then RE-READ the
pair for `New`. The re-read is load-bearing:
`include_default_system_prompt` is computed from the toggle row AND the
prompt, so a prompt-only write can flip the effective value without the
request carrying the pointer. `PlanModeInstructions` stays zero on both
sides.
- `putChatPlanModeInstructions` (no tx exists today): wrap its
read-upsert in `InTx` (behavior-preserving: same single write);
`Old`/`New` populate only `PlanModeInstructions`; the two system-prompt
fields stay zero on both sides; no cross-key reads.
- Change detection compares the populated payload fields only (never the
artificial ID).
- Tests: handler-level coderdtest with `audit.NewMock()` asserting Write
entry on change and NO entry on a value-identical PUT, for both
endpoints (this also exercises `ResourceRequiresOrgID` end to end); the
fallback-flip case (no explicit include-default row, nonempty prompt set
to empty, effective boolean flips: entry emitted with the boolean diff);
diff assertions (old->new prompt text tracked, not secret) in
`enterprise/audit/diff_internal_test.go`; `TestAuditableResources`
passes by construction.
- Bookkeeping at PR open: correct CODAGT-719's no-op premise ("matches
the existing 204-on-unchanged behavior" does not exist on main;
suppression is new, write path unchanged).
- Review focus: Old capture and the New re-read inside the tx (three of
four existing singletons never set Old; do not copy them; and the
computed include-default value makes a naive New construction wrong);
the skip-on-no-op mechanism; prompt text deliberately visible in diffs.
</details>
Note: the plan excerpt above predates operator decision D5 (2026-07-30),
which this PR implements: the resource type is
`chat_instruction_settings` (not `chat_system_prompt_settings`), each
setting carries a stable ID and a display-name target (not a per-write
artificial ID and an empty target), no-op suppression runs through
`InitRequestWithCancel` (not the nil-ID skip), and attempts (denied,
failed, capture-degraded) record rows with real statuses and empty
diffs. Ticket bookkeeping for CODAGT-719 was corrected on Linear at
kickoff: the ticket's "matches the existing 204-on-unchanged behavior"
premise does not exist on main; suppression is new, and the write path
is unchanged.
> 🤖 This PR was created with the help of Coder Agents, and _will be_
reviewed by a human. 🏂🏻
---------
Co-authored-by: Michael Suchacz <203725896+ibetitsmike@users.noreply.github.com>
This commit is contained in:
co-authored by
Michael Suchacz
parent
ba5717dc67
commit
d3f08b1983
Generated
+2
@@ -7939,6 +7939,7 @@ export type ResourceType =
|
||||
| "ai_seat"
|
||||
| "api_key"
|
||||
| "chat"
|
||||
| "chat_instruction_settings"
|
||||
| "convert_login"
|
||||
| "custom_role"
|
||||
| "git_ssh_key"
|
||||
@@ -7977,6 +7978,7 @@ export const ResourceTypes: ResourceType[] = [
|
||||
"ai_seat",
|
||||
"api_key",
|
||||
"chat",
|
||||
"chat_instruction_settings",
|
||||
"convert_login",
|
||||
"custom_role",
|
||||
"git_ssh_key",
|
||||
|
||||
@@ -155,6 +155,10 @@ export const useResourceTypeFilterMenu = ({
|
||||
label = "Workspace Build";
|
||||
}
|
||||
|
||||
if (type === "chat_instruction_settings") {
|
||||
label = "Chat Instruction Settings";
|
||||
}
|
||||
|
||||
return {
|
||||
value: type,
|
||||
label,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import type { Meta, StoryObj } from "@storybook/react-vite";
|
||||
import type { ComponentProps } from "react";
|
||||
import { expect, within } from "storybook/test";
|
||||
import { expect, fn, screen, userEvent, within } from "storybook/test";
|
||||
import {
|
||||
getDefaultFilterProps,
|
||||
MockMenu,
|
||||
@@ -18,6 +18,7 @@ import {
|
||||
MockUserOwner,
|
||||
} from "#/testHelpers/entities";
|
||||
import { pixelWithTablet } from "#/testHelpers/pixel";
|
||||
import { useResourceTypeFilterMenu } from "./AuditFilter";
|
||||
import { AuditPageView } from "./AuditPageView";
|
||||
|
||||
type FilterProps = ComponentProps<typeof AuditPageView>["filterProps"];
|
||||
@@ -119,6 +120,53 @@ export const NotVisibleWithoutLicenseAccess: Story = {
|
||||
},
|
||||
};
|
||||
|
||||
const onResourceTypeChange = fn();
|
||||
|
||||
// Uses the real resource-type menu so the generated resource type and its
|
||||
// friendly label are verified together.
|
||||
export const FilterByChatInstructionSettings: Story = {
|
||||
args: {
|
||||
auditsQuery: mockSuccessResult,
|
||||
},
|
||||
render: function AuditPageViewWithResourceTypeMenu(args) {
|
||||
const resourceTypeMenu = useResourceTypeFilterMenu({
|
||||
value: undefined,
|
||||
onChange: onResourceTypeChange,
|
||||
});
|
||||
return (
|
||||
<AuditPageView
|
||||
{...args}
|
||||
filterProps={{
|
||||
...defaultFilterProps,
|
||||
menus: {
|
||||
...defaultFilterProps.menus,
|
||||
resourceType: resourceTypeMenu,
|
||||
},
|
||||
}}
|
||||
/>
|
||||
);
|
||||
},
|
||||
play: async ({ canvasElement }) => {
|
||||
const canvas = within(canvasElement);
|
||||
onResourceTypeChange.mockClear();
|
||||
|
||||
await userEvent.click(
|
||||
canvas.getByRole("button", { name: "Select a resource type" }),
|
||||
);
|
||||
const option = await screen.findByRole("option", {
|
||||
name: "Chat Instruction Settings",
|
||||
});
|
||||
await userEvent.click(option);
|
||||
|
||||
await expect(onResourceTypeChange).toHaveBeenCalledWith(
|
||||
expect.objectContaining({
|
||||
value: "chat_instruction_settings",
|
||||
label: "Chat Instruction Settings",
|
||||
}),
|
||||
);
|
||||
},
|
||||
};
|
||||
|
||||
export const MultiOrg: Story = {
|
||||
parameters: { pixel: { matrix: pixelWithTablet } },
|
||||
args: {
|
||||
|
||||
Reference in New Issue
Block a user