Skip to content

Clarify private investigation links and unavailable access - #1640

Merged
nadaverell merged 1 commit into
mainfrom
fix/investigation-sharing-copy
Sep 5, 2026
Merged

nadaverell merged 1 commit into
mainfrom
fix/investigation-sharing-copy

Conversation

@nadaverell

@nadaverell nadaverell commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Keep investigation links useful without implying that private bookmarks grant access or that every unavailable transcript was deleted.

  • Private hosted links say “Copy private link (only you can open it)”. Organization-shared links retain the existing label.
  • Both unavailable-investigation surfaces explain possible privacy, changed access or cleared history, with account/org and creator guidance.
  • No permission changes. Standalone OSS still has no hosted copy/share controls; those require Hub capabilities.

Testing

  • Radar make tsc, make build, and 19 targeted DiagnoseSurface tests.
  • Hub Web consumer production build with this locally packed Radar source.
  • Live browser checks: private-link tooltip and member opening a revoked share. Screenshots captured locally.

Follow-up to merged #1585; used with Hub #218 and Web #280. Release/package adoption remains a separate ordered step; no publishing is performed by this PR.


Note

Low Risk
Copy and accessibility text only; no API, permissions, or link behavior changes.

Overview
Updates Diagnose UI copy so users aren’t misled about who can open shared links or why an investigation can’t be loaded.

Copy link control now takes run visibility. Private runs use tooltip and aria-label “Copy private link (only you can open it)”; organization-shared runs keep “Copy investigation link.”

Unavailable investigation empty states (deep-linked run missing from the list in DiagnoseSurface, and stream-gone with no transcript in InvestigationView) replace the old “cleared from history” wording with broader guidance: private run, revoked/changed access, or cleared history, plus account/org checks or asking the creator. Inline comments are aligned with that framing.

Reviewed by Cursor Bugbot for commit e720aeb. Bugbot is set up for automated code reviews on this repo. Configure here.

@nadaverell
nadaverell requested a review from hisco as a code owner September 5, 2026 22:33
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Clarify private link and unavailable investigation messaging

🐞 Bug fix 🕐 Less than 10 minutes

Grey Divider

AI Description

• Distinguishes private copy links from organization-shareable investigation links.
• Explains unavailable investigations without assuming their history was deleted.
Diagram

graph TD
  A["Diagnose header"] --> B{"Private run?"} -->|Yes| C["Private link warning"]
  B -->|No| D["Investigation link"]
  E["Unavailable transcript"] --> F["Access guidance"]
Loading
High-Level Assessment

The targeted presentation-only approach is appropriate because the UI cannot safely distinguish private, revoked, cleared, and unknown investigations without new backend contracts that could expose authorization details. A shared message constant was considered, but the two surfaces have different surrounding controls and the limited duplication does not justify additional abstraction.

Files changed (2) +15 / -10

Bug fix (2) +15 / -10
DiagnoseSurface.tsxClarify private links and missing investigation recovery +11/-7

Clarify private links and missing investigation recovery

• Uses investigation visibility to warn that private copied links are only accessible to the current user while preserving the existing label for other links. Broadens the missing-run explanation to cover privacy, changed access, account or organization mismatch, and cleared history.

web/src/components/diagnose/DiagnoseSurface.tsx

InvestigationView.tsxBroaden unavailable transcript guidance +4/-3

Broaden unavailable transcript guidance

• Replaces the deleted-history assumption with guidance covering private investigations, revoked access, cleared history, account or organization context, and creator authorization.

web/src/components/diagnose/InvestigationView.tsx

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can keep summaries lean with Finding overflow, which tucks the rest behind 'View more'

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@nadaverell
nadaverell merged commit 8b3e5fb into main Sep 5, 2026
9 checks passed
@nadaverell
nadaverell deleted the fix/investigation-sharing-copy branch September 5, 2026 23:03
nadaverell added a commit that referenced this pull request Sep 6, 2026
## Summary

Restore the path from retained automatic evidence to a human
investigation without
discarding the available findings or turning the original transcript
into a mutable chat.

Completed automatic investigations offer **Investigate further**. It
opens a new
human conversation with the original resource and issue ID, using Hub's
existing
recent-verdict seeding. The header's separate action is explicitly
labeled
**Start fresh — ignore earlier findings** and sends `fresh: true`.

The new action requires a completed background run with an issue ID;
running,
failed, stopped, stale and unavailable runs do not advertise this
handoff. Copy
does not promise findings when no eligible recent verdict exists.

## OSS versus hosted behavior

- **Radar Cloud SaaS and licensed self-hosted Hub:** automatic retained
evidence
supports the new context-preserving handoff. The original transcript
stays read-only.
- **Standalone OSS Radar:** no organization sharing or hosted-copy
controls are
introduced. Existing human investigation behavior remains; the
fresh-start
  tooltip now states its intent explicitly.

This is verdict seeding, not a full transcript or SDK-session fork, and
it does
not change sharing permissions or model-provider consent.

## Verification

| Journey | Proof |
|---|---|
| Completed automatic evidence → Investigate further | Actual local
browser click sends resource + issueId without fresh |
| Explicit fresh start | Actual local browser click sends same target +
issueId and fresh:true |
| Ineligible state / OSS human run | Eligibility matrix covers absent
issueId, human trigger, running/error/stopped/stale/gone states |
| Request serialization | Both start intents tested at API boundary |
| Standalone build | Type-check, 23 targeted tests, full
frontend/embed/Go build pass |

Browser verification used real local Hub/Postgres and synthetic retained
evidence
on the existing kind cluster. Job POSTs were intentionally intercepted;
this is UI
request proof, not a newly executed model investigation. Hub separately
tests prompt
seeding and authorization. Screenshots were captured and inspected
locally.

## Dependencies

Follows merged [Radar
#1640](#1640).
Uses the issueId and prior-evidence authorization from merged [Hub
#218](skyhook-dev/radar-hub#218).
The retained-evidence entrypoint is in merged [Web
#280](skyhook-dev/radar-hub-web#280).
Published radar-app 1.13.1 does not include this change. After merging,
publish a new
Radar package and adopt it in Web to complete the context-preserving
handoff.
No package publication or deployment is performed by this PR.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> UI-only diagnose flow changes with guarded eligibility; no auth or
sharing logic modified in this diff.
> 
> **Overview**
> Restores a **context-preserving** path from completed automatic
investigations into a new human run, while keeping the original
automatic transcript read-only.
> 
> Eligible background runs (`done`, with `issueId`) now show an
**Investigate further** action that starts a new investigation with the
same resource and issue ID and **without** `fresh: true`, so Hub can
seed from recent verdict evidence. The header **+** control is relabeled
**Start fresh — ignore earlier findings** and continues to pass `fresh:
true` for an explicit clean slate.
> 
> `canInvestigateFurther` centralizes eligibility (no handoff for
in-flight, failed, stopped, stale, missing issue, human runs, or when
the run is gone). Copy falls back to generic “start a new investigation”
when further investigation isn’t offered.
> 
> Adds Vitest coverage for the eligibility matrix and for `createRun`
POST bodies for both start intents.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
0815ae8. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant