Skip to content

fix(error-tracking): show access denied instead of 403s in configuration - #70533

Merged
ablaszkiewicz merged 4 commits into
masterfrom
fix/error-tracking-config-access-denied
Jul 14, 2026
Merged

fix(error-tracking): show access denied instead of 403s in configuration#70533
ablaszkiewicz merged 4 commits into
masterfrom
fix/error-tracking-config-access-denied

Conversation

@ablaszkiewicz

@ablaszkiewicz ablaszkiewicz commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

This all applies only if an org has RBAC enabled. All of this is also enforced on backend - only exception from this rule is auto capture settings - this currently lives on the team model - I will migrate it in the follow up PR

Viewer

If user has no viewer rights

Navigation Inside the page (can't get there via navigation. Had to use direct link or something)
CleanShot 2026-07-13 at 19 33 03@2x CleanShot 2026-07-13 at 19 37 51@2x

Editor

If user has viewer rights but no editor rights, we display everything but each save or modify or new rule button is disabled with a reason:

CleanShot 2026-07-13 at 19 58 12@2x

Configuration sections mounted their UI regardless of the user's
error_tracking access level, so every endpoint returned 403. Gate the
settings section content and the product page Configuration tab behind
the same viewer-level check the backend enforces, rendering the generic
AccessDenied component instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ablaszkiewicz ablaszkiewicz self-assigned this Jul 13, 2026
@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Bundle size — 🔺 +158 B (+0.0%)

Uncompressed size of every built .js bundle, compared against the base branch.

Total: 64.34 MiB · 🔺 +158 B (+0.0%)

No file changed by more than 1000 B.

Posted automatically by build-bundle-size-report · uncompressed bytes from dist-report

Eager graph — within budget

How much code each root ships on the eager path — downloaded and parsed before the surface is interactive. Measured from the esbuild output chunks (post-tree-shake, static imports only); lazy import() / React.lazy chunks are not counted.

Root Eager (shipped) Δ vs base Budget
entry (logged-out pages, app bootstrap)
src/index.tsx
1.21 MiB · 22 files no change ███░░░░░░░ 28.1% of 4.29 MiB
authenticated shell (every logged-in page)
src/scenes/AuthenticatedShell.tsx
8.10 MiB · 2,973 files 🔺 +109 B (+0.0%) █████████░ 87.6% of 9.25 MiB

🟢 node_modules/monaco-editor/ stays out of src/index.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 node_modules/monaco-editor/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx

Largest files eagerly shipped from src/index.tsx
Size File
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
24.6 KiB ../node_modules/.pnpm/buffer@6.0.3/node_modules/buffer/index.js
6.3 KiB ../node_modules/.pnpm/react@18.3.1/node_modules/react/cjs/react.production.min.js
4.5 KiB ../node_modules/.pnpm/@jspm+core@2.1.0/node_modules/@jspm/core/nodelibs/browser/process.js
3.9 KiB ../node_modules/.pnpm/scheduler@0.23.2/node_modules/scheduler/cjs/scheduler.production.min.js
1.4 KiB ../node_modules/.pnpm/base64-js@1.5.1/node_modules/base64-js/index.js
1.3 KiB src/RootErrorBoundary.tsx
912 B ../node_modules/.pnpm/ieee754@1.2.1/node_modules/ieee754/index.js
789 B src/scenes/ChunkLoadErrorBoundary.tsx
668 B src/index.tsx
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx
Size File
278.6 KiB ../node_modules/.pnpm/posthog-js@1.399.2/node_modules/posthog-js/dist/rrweb.js
267.7 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
234.9 KiB src/taxonomy/core-filter-definitions-by-group.json
221.5 KiB ../node_modules/.pnpm/posthog-js@1.399.2/node_modules/posthog-js/dist/module.js
164.0 KiB src/queries/validators.js
154.3 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
105.9 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
90.6 KiB ../node_modules/.pnpm/@tiptap+core@3.20.6_@tiptap+pm@3.20.6/node_modules/@tiptap/core/dist/index.js

Posted automatically by check-eager-graph · sizes are eager output bytes (shipped, post-tree-shake) from the esbuild metafile · part of #32479

⚠️ Dist folder size — 🔺 +12.8 KiB (+0.0%)

Total size of the built frontend/dist folder (all assets), compared against the base branch.

Total: 1278.75 MiB · 🔺 +12.8 KiB (+0.0%)

Playwright — all passed

All tests passed.

View test results →

ablaszkiewicz and others added 3 commits July 13, 2026 19:44
Rule add/edit/reorder, symbol set deletion, and the spike detection and
rate limit save buttons now disable with the standard permission tooltip
when the user lacks editor access, instead of failing with a 403 toast.
The check lives in a shared errorTrackingEditAccessDisabledReason helper.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… access

The configuration sections render the RuleList/RuleModal UI, not the
legacy Rules compound component, so the previous gating missed the
actual add/select/reorder buttons and the modal save/delete. Gate those
plus the code owners import entry point.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
'You don't have sufficient permissions for this error tracking.' read
like a word was missing; follow the same resource-suffix special case
as revenue and web analytics.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ablaszkiewicz
ablaszkiewicz marked this pull request as ready for review July 13, 2026 18:01
Copilot AI review requested due to automatic review settings July 13, 2026 18:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

🦔 Hogbox preview · ✅ ready

▶ Open the preview

🔑 Login test@posthog.com / 12345678 (demo data)
🧩 Running this PR's backend and frontend, on the PostHog :master base
🔗 Link stable across rebuilds — a re-push swaps the box underneath, the URL stays
🔒 Access tailnet only (PostHog VPN)
🛠️ Admin inspect & debug state in hogland
💤 Idle sleeps after ~30 min idle (snapshot to S3, zero node cost) and wakes on your next visit in ~30s, behind a brief "waking up" screen

commit dd12774 · box box-87fe62c3004a · ready in 689s (push → usable) · build log · rebuilds on every push, torn down on close

@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested review from a team, MattBro, cat-ph, fercgomes, hpouillot and rafaeelaudibert and removed request for a team July 13, 2026 18:02
@greptile-apps

greptile-apps Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Reviews (1): Last reviewed commit: "fix(error-tracking): read 'error trackin..." | Re-trigger Greptile

Comment thread frontend/src/scenes/settings/SettingsMap.tsx
@trunk-io

trunk-io Bot commented Jul 13, 2026

Copy link
Copy Markdown

Static BadgeStatic BadgeStatic BadgeStatic Badge

View Full Report ↗︎Docs

@cat-ph cat-ph left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! :shipit: I think the autocapture toggle still "works" if someone gets there? or I might've missed it, I tried the hogland preview with a viewer user but it didn't work for some reason and my dev stack is a bit broken 😬

edit: sorry - I saw you mentioned it in the description, though was thinking it's "simple" to just slap a errorTrackingEditAccessDisabledReason on top of it too, but also happy to defer to the follow-up

@ablaszkiewicz
ablaszkiewicz merged commit 1634816 into master Jul 14, 2026
312 of 314 checks passed
@ablaszkiewicz
ablaszkiewicz deleted the fix/error-tracking-config-access-denied branch July 14, 2026 09:06
@deployment-status-posthog

deployment-status-posthog Bot commented Jul 14, 2026

Copy link
Copy Markdown

Deploy status

Environment Status Deployed At Workflow
dev ✅ Deployed 2026-07-14 09:39 UTC Run
prod-us ✅ Deployed 2026-07-14 09:50 UTC Run
prod-eu ✅ Deployed 2026-07-14 09:54 UTC Run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants