Repository navigation
Add V2 Terms of Use and Approval Requests pages - #1687
Merged
Paul Lizer (paullizer) merged 8 commits intoOct 7, 2026
Merged
Paul Lizer (paullizer) merged 8 commits into
Paul Lizer (paullizer) merged 8 commits into
Conversation
- V2 users are gated to /v2/terms-of-use with new /api/v2/terms-of-use routes - Full-page V2 approvals with category rail, list, and detail pane covering group, M365, content screening, outgoing actions, waiting requests, and admin agent templates - Sidebar, notification bell, and admin links route to the V2 page - Functional and UI tests, docs, version 0.261.277 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bump version to 0.261.280 after base took 0.261.279; adopt base same-origin URL guards for favicon and sidebar links. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bump version to 0.261.281 after base took 0.261.280. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
15 of 24 tasks
…lizer-v2-terms-and-approvals Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> # Conflicts: # application/single_app/route_backend_users.py # application/v2_ui/src/lib/userSettings.ts
Preserve both release note sections and advance terms and approvals to 0.261.287. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer)
merged commit Oct 7, 2026
05fb0ce
into
paullizer-react-v2-ui
11 checks passed
Paul Lizer (paullizer)
added a commit
to paullizer/simplechat
that referenced
this pull request
Oct 7, 2026
Brings in V2 at 05fb0ce (microsoft#1687, VERSION 0.261.287). Conflicts: - docs/explanation/release_notes.md: V2's file byte-for-byte, with this branch's own (v0.261.287) section inserted at the very top, above V2's first section, microsoft#1687's own (v0.261.287). Every V2 section is unchanged. The next commit renumbers this branch's section, because microsoft#1687 already uses 0.261.287. application/single_app/config.py merged cleanly: both sides set VERSION to 0.261.287, so the merged file equals V2's. The next commit renumbers it above V2's 0.261.287. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer)
added a commit
to paullizer/simplechat
that referenced
this pull request
Oct 7, 2026
V2 now uses 0.261.287 (microsoft#1687), so this branch's version moves above it. Renumbers the same 20 lines in 15 files as the previous bump: config.py, this branch's release-notes section, the documentation version notes and the new tests' headers. V2's own (v0.261.287) release-notes section is untouched. The tests' version floor stays 0.261.253. Refs microsoft#1549 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
14 of 24 tasks
Paul Lizer (paullizer)
added a commit
to paullizer/simplechat
that referenced
this pull request
Oct 7, 2026
Every primary link in the V2 left rail opened the classic interface. The rail built its links with the safeSameOriginUrl helper from lib/adminOperations, which returns a full URL. React Router treats an absolute URL outside the /v2 basename as external, so it rendered a plain anchor and each click loaded the classic page at that path. The active highlight never matched either. Two parallel XSS sink fixes had edited the same line, and the merge kept that helper instead of the relative safeNavHref allowlist reviewed in microsoft#1687. - Restore safeNavHref so rail links stay relative to /v2. - Add a functional test that also flags router links built from the page origin anywhere in the V2 source. - Add a Playwright UI test that clicks each rail link and checks it routes inside the SPA. - Document the fix and bump the version to 0.261.290. Fixes microsoft#1698 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
15 of 24 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
V2 users were sent back to the classic UI for both the Terms of Use gate and approval requests. This brings both into the V2 experience.
/v2page and API requests are now gated to/v2/terms-of-use(newGET /api/v2/terms-of-use,POST .../accept,POST .../decline). Acceptance, versioning, redirect safety and audit logging reuse the classic logic. A V2 tab that gets aterms_of_use_required403 mid-session redirects to the V2 page. The message is rendered as text only./v2/approvals): a full-page layout like V2 Admin Settings. A collapsible category rail on the left (remembered via thev2ApprovalsRailCollapseduser setting; it becomes a category picker on phones), the request list in the middle, and the detail and decision pane on the right.?approval_id,?m365_approval,#agent-template-approvals) redirect to the matching request.Worth a careful look:
/api/approvalslist endpoint filters one type at a time and ignores search. The page fetches each status once (up to 10 pages of 200) and filters categories on the client.M365_APPROVALS_HREFandWorkflowProposalCardstill link to classic/approvalson purpose.test_v2_orchestration_m365_recovery.pyexpects that.Linked issue
N/A
Release Notes & Latest Features
Is this visible to end users?
Is this admin-facing (Admin Settings, governance, deployment, config)?
Should this become a Latest Feature card?
Screenshot needed for the card?
Version bump
application/single_app/config.pyVERSIONthird segment bumped, or not needed because this is docs-only (0.261.277)deployers/version.txtbumped, or not needed becausedeployers/was not changedTesting / validation
npm --prefix application/v2_ui run build: passedpython functional_tests/test_v2_terms_and_approvals.py: 8/8 passedpython functional_tests/test_v2_notifications_bell.py: 10/10 passedpython functional_tests/test_terms_of_use.py: 4/4 passedpython functional_tests/test_user_settings_allowlist_keys.py: passedfunctional_tests/route_tests/(blueprint policy inventory, unauthenticated policy contract, policy test coverage): passedpython -m pytest ui_tests/test_v2_approvals_and_terms_pages.py: 5 passedpython functional_tests/test_docs_app_surface_coverage.py: 7/7 passed.python functional_tests/test_docs_site_quality.py: 6/6 passedui_tests/test_v2_notifications_bell.py. Collection fails because it importsui_tests/fixtures/agent_delegation, which was already missing from the repository before this change.Documentation
V2_TERMS_AND_APPROVALS.md,TERMS_OF_USE.md,guides/review-approval-requests.md)Security checklist
@swagger_route(security=get_auth_security())sanitize_settings_for_user()