Skip to content

chore(posthog-ai): fix stale toolPolicy provenance comment#71582

Closed
skoob13 wants to merge 1 commit into
masterfrom
chore/toolpolicy-comment-auto-mode
Closed

chore(posthog-ai): fix stale toolPolicy provenance comment#71582
skoob13 wants to merge 1 commit into
masterfrom
chore/toolpolicy-comment-auto-mode

Conversation

@skoob13

@skoob13 skoob13 commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Problem

The header comment in products/posthog_ai/frontend/policy/toolPolicy.ts claims the deployed agent-server runs in default permission mode and asks for approval on every PostHog exec call. That's stale: the web surface starts runs in auto mode (INITIAL_PERMISSION_MODE), where the agent-server auto-runs built-ins server-side. Worse, until PostHog/code#3514 the server's exec gate silently allowed destructive sub-tools in auto mode, so the approval card this policy is supposed to drive never appeared.

Changes

Comment-only. Rewrites the header to describe the actual contract: the agent-server emits a permission_request for every PostHog exec call in auto mode (including destructive sub-tools, as of PostHog/code#3514), and this client policy auto-approves the safe ones while surfacing the approval card for update/delete/destroy/partial-update.

How did you test this code?

No runtime change, comment only. hogli test products/posthog_ai/frontend/policy/toolPolicy.test.ts still passes.

Automatic notifications

  • Publish to changelog?
  • Alert Sales and Marketing teams?

Docs update

Not needed, internal code comment.

🤖 Agent context

Autonomy: Human-driven (agent-assisted)

Claude Code traced why the posthog_ai permission card never triggered for destructive PostHog MCP exec sub-tools. Root cause and fix live in the agent server (PostHog/code#3514); this PR only corrects the provenance comment that documented the old (wrong) assumption about the server's permission mode.

The header claimed the deployed agent-server runs in default permission mode and asks on every PostHog exec call. The web surface actually starts runs in auto mode, where the agent-server auto-runs built-ins and (as of PostHog/code#3514) emits permission requests for PostHog exec calls including destructive sub-tools. Describe the actual contract.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@skoob13 skoob13 added the skip-agent-review Save $$$, skip auto agent reviews (Greptile) — use for trivial or chore PRs label Jul 16, 2026
@skoob13 skoob13 self-assigned this Jul 16, 2026
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

🤖 CI report

Bundle size — no change

Uncompressed size of every built .js bundle, compared against the base branch.

Total: 64.82 MiB · no change

No file changed by more than 1000 B.

Posted automatically by build-bundle-size-report · uncompressed bytes from dist-report

Eager graph — within budget

How much code each root ships on the eager path — downloaded and parsed before the surface is interactive. Measured from the esbuild output chunks (post-tree-shake, static imports only); lazy import() / React.lazy chunks are not counted.

Root Eager (shipped) Δ vs base Budget
entry (logged-out pages, app bootstrap)
src/index.tsx
1.22 MiB · 22 files no change ███░░░░░░░ 28.4% of 4.29 MiB
authenticated shell (every logged-in page)
src/scenes/AuthenticatedShell.tsx
8.14 MiB · 2,987 files no change █████████░ 88.0% of 9.25 MiB

🟢 node_modules/monaco-editor/ stays out of src/index.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 [object Object] stays out of src/index.tsx
🟢 node_modules/monaco-editor/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx
🟢 [object Object] stays out of src/scenes/AuthenticatedShell.tsx

Largest files eagerly shipped from src/index.tsx
Size File
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
24.6 KiB ../node_modules/.pnpm/buffer@6.0.3/node_modules/buffer/index.js
6.3 KiB ../node_modules/.pnpm/react@18.3.1/node_modules/react/cjs/react.production.min.js
4.5 KiB ../node_modules/.pnpm/@jspm+core@2.1.0/node_modules/@jspm/core/nodelibs/browser/process.js
3.9 KiB ../node_modules/.pnpm/scheduler@0.23.2/node_modules/scheduler/cjs/scheduler.production.min.js
1.4 KiB ../node_modules/.pnpm/base64-js@1.5.1/node_modules/base64-js/index.js
1.3 KiB src/RootErrorBoundary.tsx
912 B ../node_modules/.pnpm/ieee754@1.2.1/node_modules/ieee754/index.js
789 B src/scenes/ChunkLoadErrorBoundary.tsx
762 B src/index.tsx
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx
Size File
281.3 KiB ../node_modules/.pnpm/posthog-js@1.402.3/node_modules/posthog-js/dist/rrweb.js
267.7 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
235.5 KiB src/taxonomy/core-filter-definitions-by-group.json
222.9 KiB ../node_modules/.pnpm/posthog-js@1.402.3/node_modules/posthog-js/dist/module.js
164.0 KiB src/queries/validators.js
154.3 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
105.8 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
92.7 KiB ../packages/quill/packages/quill/dist/index.js

Posted automatically by check-eager-graph · sizes are eager output bytes (shipped, post-tree-shake) from the esbuild metafile · part of #32479

Dist folder size — 🔺 +817 B (+0.0%)

Total size of the built frontend/dist folder (all assets), compared against the base branch.

Total: 1320.76 MiB · 🔺 +817 B (+0.0%)

@skoob13 skoob13 closed this Jul 16, 2026
@trunk-io

trunk-io Bot commented Jul 16, 2026

Copy link
Copy Markdown

Static BadgeStatic BadgeStatic BadgeStatic Badge

View Full Report ↗︎Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-agent-review Save $$$, skip auto agent reviews (Greptile) — use for trivial or chore PRs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant