Skip to content

Add V2 Terms of Use and Approval Requests pages - #1687

Merged
Paul Lizer (paullizer) merged 8 commits into
paullizer-react-v2-uifrom
paullizer-v2-terms-and-approvals
Oct 7, 2026
Merged

Paul Lizer (paullizer) merged 8 commits into
paullizer-react-v2-uifrom
paullizer-v2-terms-and-approvals

Conversation

@paullizer

Copy link
Copy Markdown
Contributor

Summary

V2 users were sent back to the classic UI for both the Terms of Use gate and approval requests. This brings both into the V2 experience.

  • V2 Terms of Use: /v2 page and API requests are now gated to /v2/terms-of-use (new GET /api/v2/terms-of-use, POST .../accept, POST .../decline). Acceptance, versioning, redirect safety and audit logging reuse the classic logic. A V2 tab that gets a terms_of_use_required 403 mid-session redirects to the V2 page. The message is rendered as text only.
  • V2 Approval Requests (/v2/approvals): a full-page layout like V2 Admin Settings. A collapsible category rail on the left (remembered via the v2ApprovalsRailCollapsed user setting; it becomes a category picker on phones), the request list in the middle, and the detail and decision pane on the right.
  • Same coverage as the classic page: all requests, group requests, Microsoft 365 approvals, content screening (feature-flagged), outgoing M365 actions, waiting/paused requests with resume and connect-and-resume, and admin-only agent template approvals.
  • Navigation: new sidebar entry. The notification bell and the Admin Settings agent template link now route to the V2 page, and classic deep links (?approval_id, ?m365_approval, #agent-template-approvals) redirect to the matching request.

Worth a careful look:

  • The /api/approvals list endpoint filters one type at a time and ignores search. The page fetches each status once (up to 10 pages of 200) and filters categories on the client.
  • M365_APPROVALS_HREF and WorkflowProposalCard still link to classic /approvals on purpose. test_v2_orchestration_m365_recovery.py expects that.

Linked issue

N/A

Release Notes & Latest Features

  • New Feature
  • Bug Fix
  • UI Enhancement
  • Breaking Change
  • Internal only

Is this visible to end users?

  • Yes
  • No

Is this admin-facing (Admin Settings, governance, deployment, config)?

  • Yes
  • No

Should this become a Latest Feature card?

  • Yes
  • No
  • Already added

Screenshot needed for the card?

  • Yes
  • No
  • Attached

Version bump

  • application/single_app/config.py VERSION third segment bumped, or not needed because this is docs-only (0.261.277)
  • deployers/version.txt bumped, or not needed because deployers/ was not changed

Testing / validation

  • npm --prefix application/v2_ui run build: passed
  • python functional_tests/test_v2_terms_and_approvals.py: 8/8 passed
  • python functional_tests/test_v2_notifications_bell.py: 10/10 passed
  • python functional_tests/test_terms_of_use.py: 4/4 passed
  • python functional_tests/test_user_settings_allowlist_keys.py: passed
  • Route policy tests in functional_tests/route_tests/ (blueprint policy inventory, unauthenticated policy contract, policy test coverage): passed
  • python -m pytest ui_tests/test_v2_approvals_and_terms_pages.py: 5 passed
  • python functional_tests/test_docs_app_surface_coverage.py: 7/7 passed. python functional_tests/test_docs_site_quality.py: 6/6 passed
  • Not run: ui_tests/test_v2_notifications_bell.py. Collection fails because it imports ui_tests/fixtures/agent_delegation, which was already missing from the repository before this change.

Documentation

  • Release notes updated, or not needed
  • Feature documentation updated, or not needed (V2_TERMS_AND_APPROVALS.md, TERMS_OF_USE.md, guides/review-approval-requests.md)
  • Fix documentation updated, or not needed

Security checklist

  • New Flask routes include @swagger_route(security=get_auth_security())
  • Settings sent to non-admin frontends use sanitize_settings_for_user()
  • Browser JavaScript is served from local SimpleChat static assets only; no CDN-hosted JS
  • No secrets, keys, connection strings, or local-only artifacts are included

Paul Lizer (paullizer) and others added 6 commits October 7, 2026 09:43
- V2 users are gated to /v2/terms-of-use with new /api/v2/terms-of-use routes
- Full-page V2 approvals with category rail, list, and detail pane covering
  group, M365, content screening, outgoing actions, waiting requests, and
  admin agent templates
- Sidebar, notification bell, and admin links route to the V2 page
- Functional and UI tests, docs, version 0.261.277

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bump version to 0.261.280 after base took 0.261.279; adopt base same-origin URL guards for favicon and sidebar links.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bump version to 0.261.281 after base took 0.261.280.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer) and others added 2 commits October 7, 2026 11:40
…lizer-v2-terms-and-approvals

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

# Conflicts:
#	application/single_app/route_backend_users.py
#	application/v2_ui/src/lib/userSettings.ts
Preserve both release note sections and advance terms and approvals to 0.261.287.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paullizer
Paul Lizer (paullizer) merged commit 05fb0ce into paullizer-react-v2-ui Oct 7, 2026
11 checks passed
Paul Lizer (paullizer) added a commit to paullizer/simplechat that referenced this pull request Oct 7, 2026
Brings in V2 at 05fb0ce (microsoft#1687, VERSION 0.261.287).

Conflicts:
- docs/explanation/release_notes.md: V2's file byte-for-byte, with this
  branch's own (v0.261.287) section inserted at the very top, above V2's
  first section, microsoft#1687's own (v0.261.287). Every V2 section is unchanged.
  The next commit renumbers this branch's section, because microsoft#1687 already
  uses 0.261.287.

application/single_app/config.py merged cleanly: both sides set VERSION
to 0.261.287, so the merged file equals V2's. The next commit renumbers
it above V2's 0.261.287.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer) added a commit to paullizer/simplechat that referenced this pull request Oct 7, 2026
V2 now uses 0.261.287 (microsoft#1687), so this branch's version moves above it.
Renumbers the same 20 lines in 15 files as the previous bump: config.py,
this branch's release-notes section, the documentation version notes and
the new tests' headers. V2's own (v0.261.287) release-notes section is
untouched. The tests' version floor stays 0.261.253.

Refs microsoft#1549

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer) added a commit to paullizer/simplechat that referenced this pull request Oct 7, 2026
Every primary link in the V2 left rail opened the classic interface. The rail
built its links with the safeSameOriginUrl helper from lib/adminOperations,
which returns a full URL. React Router treats an absolute URL outside the /v2
basename as external, so it rendered a plain anchor and each click loaded the
classic page at that path. The active highlight never matched either.

Two parallel XSS sink fixes had edited the same line, and the merge kept that
helper instead of the relative safeNavHref allowlist reviewed in microsoft#1687.

- Restore safeNavHref so rail links stay relative to /v2.
- Add a functional test that also flags router links built from the page
  origin anywhere in the V2 source.
- Add a Playwright UI test that clicks each rail link and checks it routes
  inside the SPA.
- Document the fix and bump the version to 0.261.290.

Fixes microsoft#1698

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant