chore(posthog-ai): fix stale toolPolicy provenance comment#71582
chore(posthog-ai): fix stale toolPolicy provenance comment#71582skoob13 wants to merge 1 commit into
Conversation
The header claimed the deployed agent-server runs in default permission mode and asks on every PostHog exec call. The web surface actually starts runs in auto mode, where the agent-server auto-runs built-ins and (as of PostHog/code#3514) emits permission requests for PostHog exec calls including destructive sub-tools. Describe the actual contract. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
🤖 CI report✅ Bundle size — no changeUncompressed size of every built Total: 64.82 MiB · no change No file changed by more than 1000 B. Posted automatically by build-bundle-size-report · uncompressed bytes from dist-report ✅ Eager graph — within budgetHow much code each root ships on the eager path — downloaded and parsed before the surface is interactive. Measured from the esbuild output chunks (post-tree-shake, static imports only); lazy
🟢 Largest files eagerly shipped from
|
| Size | File |
|---|---|
| 126.8 KiB | ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js |
| 24.6 KiB | ../node_modules/.pnpm/buffer@6.0.3/node_modules/buffer/index.js |
| 6.3 KiB | ../node_modules/.pnpm/react@18.3.1/node_modules/react/cjs/react.production.min.js |
| 4.5 KiB | ../node_modules/.pnpm/@jspm+core@2.1.0/node_modules/@jspm/core/nodelibs/browser/process.js |
| 3.9 KiB | ../node_modules/.pnpm/scheduler@0.23.2/node_modules/scheduler/cjs/scheduler.production.min.js |
| 1.4 KiB | ../node_modules/.pnpm/base64-js@1.5.1/node_modules/base64-js/index.js |
| 1.3 KiB | src/RootErrorBoundary.tsx |
| 912 B | ../node_modules/.pnpm/ieee754@1.2.1/node_modules/ieee754/index.js |
| 789 B | src/scenes/ChunkLoadErrorBoundary.tsx |
| 762 B | src/index.tsx |
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx
| Size | File |
|---|---|
| 281.3 KiB | ../node_modules/.pnpm/posthog-js@1.402.3/node_modules/posthog-js/dist/rrweb.js |
| 267.7 KiB | ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js |
| 235.5 KiB | src/taxonomy/core-filter-definitions-by-group.json |
| 222.9 KiB | ../node_modules/.pnpm/posthog-js@1.402.3/node_modules/posthog-js/dist/module.js |
| 164.0 KiB | src/queries/validators.js |
| 154.3 KiB | ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js |
| 126.8 KiB | ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js |
| 105.8 KiB | src/lib/api.ts |
| 93.3 KiB | ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js |
| 92.7 KiB | ../packages/quill/packages/quill/dist/index.js |
Posted automatically by check-eager-graph · sizes are eager output bytes (shipped, post-tree-shake) from the esbuild metafile · part of #32479
✅ Dist folder size — 🔺 +817 B (+0.0%)
Total size of the built frontend/dist folder (all assets), compared against the base branch.
Total: 1320.76 MiB · 🔺 +817 B (+0.0%)
Problem
The header comment in
products/posthog_ai/frontend/policy/toolPolicy.tsclaims the deployed agent-server runs indefaultpermission mode and asks for approval on every PostHog exec call. That's stale: the web surface starts runs inautomode (INITIAL_PERMISSION_MODE), where the agent-server auto-runs built-ins server-side. Worse, until PostHog/code#3514 the server's exec gate silently allowed destructive sub-tools inautomode, so the approval card this policy is supposed to drive never appeared.Changes
Comment-only. Rewrites the header to describe the actual contract: the agent-server emits a
permission_requestfor every PostHog exec call inautomode (including destructive sub-tools, as of PostHog/code#3514), and this client policy auto-approves the safe ones while surfacing the approval card for update/delete/destroy/partial-update.How did you test this code?
No runtime change, comment only.
hogli test products/posthog_ai/frontend/policy/toolPolicy.test.tsstill passes.Automatic notifications
Docs update
Not needed, internal code comment.
🤖 Agent context
Autonomy: Human-driven (agent-assisted)
Claude Code traced why the posthog_ai permission card never triggered for destructive PostHog MCP exec sub-tools. Root cause and fix live in the agent server (PostHog/code#3514); this PR only corrects the provenance comment that documented the old (wrong) assumption about the server's permission mode.