Clarify private investigation links and unavailable access - #1640
Merged
Merged
Conversation
PR Summary by QodoClarify private link and unavailable investigation messaging
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can keep summaries lean with Finding overflow, which tucks the rest behind 'View more' |
nadaverell
added a commit
that referenced
this pull request
Sep 6, 2026
## Summary Restore the path from retained automatic evidence to a human investigation without discarding the available findings or turning the original transcript into a mutable chat. Completed automatic investigations offer **Investigate further**. It opens a new human conversation with the original resource and issue ID, using Hub's existing recent-verdict seeding. The header's separate action is explicitly labeled **Start fresh — ignore earlier findings** and sends `fresh: true`. The new action requires a completed background run with an issue ID; running, failed, stopped, stale and unavailable runs do not advertise this handoff. Copy does not promise findings when no eligible recent verdict exists. ## OSS versus hosted behavior - **Radar Cloud SaaS and licensed self-hosted Hub:** automatic retained evidence supports the new context-preserving handoff. The original transcript stays read-only. - **Standalone OSS Radar:** no organization sharing or hosted-copy controls are introduced. Existing human investigation behavior remains; the fresh-start tooltip now states its intent explicitly. This is verdict seeding, not a full transcript or SDK-session fork, and it does not change sharing permissions or model-provider consent. ## Verification | Journey | Proof | |---|---| | Completed automatic evidence → Investigate further | Actual local browser click sends resource + issueId without fresh | | Explicit fresh start | Actual local browser click sends same target + issueId and fresh:true | | Ineligible state / OSS human run | Eligibility matrix covers absent issueId, human trigger, running/error/stopped/stale/gone states | | Request serialization | Both start intents tested at API boundary | | Standalone build | Type-check, 23 targeted tests, full frontend/embed/Go build pass | Browser verification used real local Hub/Postgres and synthetic retained evidence on the existing kind cluster. Job POSTs were intentionally intercepted; this is UI request proof, not a newly executed model investigation. Hub separately tests prompt seeding and authorization. Screenshots were captured and inspected locally. ## Dependencies Follows merged [Radar #1640](#1640). Uses the issueId and prior-evidence authorization from merged [Hub #218](skyhook-dev/radar-hub#218). The retained-evidence entrypoint is in merged [Web #280](skyhook-dev/radar-hub-web#280). Published radar-app 1.13.1 does not include this change. After merging, publish a new Radar package and adopt it in Web to complete the context-preserving handoff. No package publication or deployment is performed by this PR. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > UI-only diagnose flow changes with guarded eligibility; no auth or sharing logic modified in this diff. > > **Overview** > Restores a **context-preserving** path from completed automatic investigations into a new human run, while keeping the original automatic transcript read-only. > > Eligible background runs (`done`, with `issueId`) now show an **Investigate further** action that starts a new investigation with the same resource and issue ID and **without** `fresh: true`, so Hub can seed from recent verdict evidence. The header **+** control is relabeled **Start fresh — ignore earlier findings** and continues to pass `fresh: true` for an explicit clean slate. > > `canInvestigateFurther` centralizes eligibility (no handoff for in-flight, failed, stopped, stale, missing issue, human runs, or when the run is gone). Copy falls back to generic “start a new investigation” when further investigation isn’t offered. > > Adds Vitest coverage for the eligibility matrix and for `createRun` POST bodies for both start intents. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 0815ae8. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Keep investigation links useful without implying that private bookmarks grant access or that every unavailable transcript was deleted.
Testing
make tsc,make build, and 19 targeted DiagnoseSurface tests.Follow-up to merged #1585; used with Hub #218 and Web #280. Release/package adoption remains a separate ordered step; no publishing is performed by this PR.
Note
Low Risk
Copy and accessibility text only; no API, permissions, or link behavior changes.
Overview
Updates Diagnose UI copy so users aren’t misled about who can open shared links or why an investigation can’t be loaded.
Copy link control now takes run
visibility. Private runs use tooltip andaria-label“Copy private link (only you can open it)”; organization-shared runs keep “Copy investigation link.”Unavailable investigation empty states (deep-linked run missing from the list in
DiagnoseSurface, and stream-gone with no transcript inInvestigationView) replace the old “cleared from history” wording with broader guidance: private run, revoked/changed access, or cleared history, plus account/org checks or asking the creator. Inline comments are aligned with that framing.Reviewed by Cursor Bugbot for commit e720aeb. Bugbot is set up for automated code reviews on this repo. Configure here.