fix(error-tracking): show access denied instead of 403s in configuration - #70533
Conversation
Configuration sections mounted their UI regardless of the user's error_tracking access level, so every endpoint returned 403. Gate the settings section content and the product page Configuration tab behind the same viewer-level check the backend enforces, rendering the generic AccessDenied component instead. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
🤖 CI report
|
| Root | Eager (shipped) | Δ vs base | Budget |
|---|---|---|---|
entry (logged-out pages, app bootstrap)src/index.tsx |
1.21 MiB · 22 files | no change | ███░░░░░░░ 28.1% of 4.29 MiB |
authenticated shell (every logged-in page)src/scenes/AuthenticatedShell.tsx |
8.10 MiB · 2,973 files | 🔺 +109 B (+0.0%) | █████████░ 87.6% of 9.25 MiB |
🟢 node_modules/monaco-editor/ stays out of src/index.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 node_modules/monaco-editor/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx
Largest files eagerly shipped from src/index.tsx
| Size | File |
|---|---|
| 126.8 KiB | ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js |
| 24.6 KiB | ../node_modules/.pnpm/buffer@6.0.3/node_modules/buffer/index.js |
| 6.3 KiB | ../node_modules/.pnpm/react@18.3.1/node_modules/react/cjs/react.production.min.js |
| 4.5 KiB | ../node_modules/.pnpm/@jspm+core@2.1.0/node_modules/@jspm/core/nodelibs/browser/process.js |
| 3.9 KiB | ../node_modules/.pnpm/scheduler@0.23.2/node_modules/scheduler/cjs/scheduler.production.min.js |
| 1.4 KiB | ../node_modules/.pnpm/base64-js@1.5.1/node_modules/base64-js/index.js |
| 1.3 KiB | src/RootErrorBoundary.tsx |
| 912 B | ../node_modules/.pnpm/ieee754@1.2.1/node_modules/ieee754/index.js |
| 789 B | src/scenes/ChunkLoadErrorBoundary.tsx |
| 668 B | src/index.tsx |
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx
| Size | File |
|---|---|
| 278.6 KiB | ../node_modules/.pnpm/posthog-js@1.399.2/node_modules/posthog-js/dist/rrweb.js |
| 267.7 KiB | ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js |
| 234.9 KiB | src/taxonomy/core-filter-definitions-by-group.json |
| 221.5 KiB | ../node_modules/.pnpm/posthog-js@1.399.2/node_modules/posthog-js/dist/module.js |
| 164.0 KiB | src/queries/validators.js |
| 154.3 KiB | ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js |
| 126.8 KiB | ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js |
| 105.9 KiB | src/lib/api.ts |
| 93.3 KiB | ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js |
| 90.6 KiB | ../node_modules/.pnpm/@tiptap+core@3.20.6_@tiptap+pm@3.20.6/node_modules/@tiptap/core/dist/index.js |
Posted automatically by check-eager-graph · sizes are eager output bytes (shipped, post-tree-shake) from the esbuild metafile · part of #32479
⚠️ Dist folder size — 🔺 +12.8 KiB (+0.0%)
Total size of the built frontend/dist folder (all assets), compared against the base branch.
Total: 1278.75 MiB · 🔺 +12.8 KiB (+0.0%)
Rule add/edit/reorder, symbol set deletion, and the spike detection and rate limit save buttons now disable with the standard permission tooltip when the user lacks editor access, instead of failing with a 403 toast. The check lives in a shared errorTrackingEditAccessDisabledReason helper. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… access The configuration sections render the RuleList/RuleModal UI, not the legacy Rules compound component, so the previous gating missed the actual add/select/reorder buttons and the modal save/delete. Gate those plus the code owners import entry point. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
'You don't have sufficient permissions for this error tracking.' read like a word was missing; follow the same resource-suffix special case as revenue and web analytics. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
🦔 Hogbox preview · ✅ ready▶ Open the preview
commit |
|
Reviews (1): Last reviewed commit: "fix(error-tracking): read 'error trackin..." | Re-trigger Greptile |
There was a problem hiding this comment.
looks good!
I think the autocapture toggle still "works" if someone gets there? or I might've missed it, I tried the hogland preview with a viewer user but it didn't work for some reason and my dev stack is a bit broken 😬
edit: sorry - I saw you mentioned it in the description, though was thinking it's "simple" to just slap a errorTrackingEditAccessDisabledReason on top of it too, but also happy to defer to the follow-up
This all applies only if an org has RBAC enabled. All of this is also enforced on backend - only exception from this rule is auto capture settings - this currently lives on the team model - I will migrate it in the follow up PR
Viewer
If user has no
viewerrightsEditor
If user has
viewerrights but noeditorrights, we display everything but each save or modify or new rule button is disabled with a reason: