Add stable investigation links and hosted sharing UI - #1585
Conversation
PR Summary by QodoAdd stable investigation links and capability-driven sharing
AI Description
Diagram
High-Level Assessment
Files changed (11)
|
Code Review by Qodo
1.
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 01f18ab. Configure here.
## Summary Keep investigation links useful without implying that private bookmarks grant access or that every unavailable transcript was deleted. - Private hosted links say “Copy private link (only you can open it)”. Organization-shared links retain the existing label. - Both unavailable-investigation surfaces explain possible privacy, changed access or cleared history, with account/org and creator guidance. - No permission changes. Standalone OSS still has no hosted copy/share controls; those require Hub capabilities. ## Testing - Radar `make tsc`, `make build`, and 19 targeted DiagnoseSurface tests. - Hub Web consumer production build with this locally packed Radar source. - Live browser checks: private-link tooltip and member opening a revoked share. Screenshots captured locally. Follow-up to merged [#1585](#1585); used with [Hub #218](skyhook-dev/radar-hub#218) and [Web #280](skyhook-dev/radar-hub-web#280). Release/package adoption remains a separate ordered step; no publishing is performed by this PR. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Copy and accessibility text only; no API, permissions, or link behavior changes. > > **Overview** > Updates Diagnose UI copy so users aren’t misled about who can open shared links or why an investigation can’t be loaded. > > **Copy link control** now takes run `visibility`. Private runs use tooltip and `aria-label` **“Copy private link (only you can open it)”**; organization-shared runs keep **“Copy investigation link.”** > > **Unavailable investigation** empty states (deep-linked run missing from the list in `DiagnoseSurface`, and stream-gone with no transcript in `InvestigationView`) replace the old “cleared from history” wording with broader guidance: private run, revoked/changed access, or cleared history, plus account/org checks or asking the creator. Inline comments are aligned with that framing. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit e720aeb. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->

Summary
Radar investigations become stable browser state instead of transient panel state. Existing retained runs reopen through
?ai-run=<id>, survive navigation and reloads, and expose a localradar_urlin Diagnose/CLI results. When Radar is embedded behind an authorized host, the same UI renders the host's private, organization-shared, and automatic-investigation capabilities.OSS remains local-first: it gains bookmarkable same-instance URLs, but no copy-link or sharing UI. Cloud collaboration remains entirely server-authorized.
What changed
Stable retained-run navigation
ai-runradar_urlfrom local Diagnose and background/CLI resultsHosted capability-driven UI
radarUrl, so it is absent in ordinary OSScanManageVisibilityand the follow-up composer oncanContinuestoppingstate, keep polling while a turn drains, and prevent new starts/follow-ups until it becomes terminalrunningsummary, without making automatic or genuinely sessionless runs resumableBehavior by environment
?ai-run=<id>radarUrlAn OSS URL is not a portable sharing artifact: it works only while the same reachable Radar instance retains that run. This PR adds no OSS identity, permission, cross-instance lookup, or transcript export model.
Live-tested journeys
?ai-run=URLVerification
npm run tscnpm run buildgit diff --checkDependencies and rollout
This PR is self-contained for OSS bookmark behavior and the hosted component contract. Cloud authorization and durable transcript semantics live in radar-hub#218; Fleet handoff and cross-organization bootstrap live in radar-hub-web#280.
After approval, Cloud rollout requires publishing a new
@skyhook-io/radar-appversion and bumping Hub Web to it. This PR does not publish, tag, deploy, or expand access by itself.Note
Medium Risk
Changes URL/history synchronization, investigation lifecycle gates, and authenticated Diagnose API usage across navigation and cluster switches; sharing UI is capability-gated but org-wide visibility is a sensitive mutation on hosted backends.
Overview
Investigations are now bookmarkable browser state via durable
?ai-run=<id>links instead of one-shot deep links. The local server addsGET /diagnose/runs/{id}for runs outside the bounded history list; the diagnose CLI JSON output includes an escapedradar_url.DiagnoseProvider keeps the focused run in the URL (with popstate sync and Fleet/embed guards), resolves missing list entries through
getRun, and avoids hammering 404s for cleared runs. App navigation and cluster switches preserveai-run; maximized investigations close before primary-rail navigation so the destination is visible.When the host exposes capabilities, the UI adds copy-link (
radarUrl), private/organization visibility, grouped organization/automatic history, actor labels on turns, and stricter Stop / follow-up / new investigation rules forstopping, background runs, and lagging summaries. Diagnose API calls send auth headers; OSS still has no share/copy UI unlessradarUrlis present.Reviewed by Cursor Bugbot for commit 22d6119. Bugbot is set up for automated code reviews on this repo. Configure here.