Skip to content

Control Center V2 (6/6): activity logs - #1693

Merged
Paul Lizer (paullizer) merged 11 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-control-center-v2-activity-logs
Oct 7, 2026
Merged

Paul Lizer (paullizer) merged 11 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-control-center-v2-activity-logs

Conversation

@paullizer

@paullizer Paul Lizer (paullizer) commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds native Activity Logs investigations with URL-synced UTC filters, deterministic timestamp/ID/partition keyset paging, bounded histogram/facets, saved views, presets, density controls and escaped JSON detail drawers with entity/approval links.
  • Adds capability-protected feed, summary and streamed CSV APIs. CSV uses identical filters, guards formula prefixes and caps activity rows at 10,000; summaries disclose newest-record sampling above 5,000 matches. Legacy activity browsing remains unchanged.
  • Dependencies: Control Center V2 (4/6): group management #1692 (Users/Groups) and Control Center V2 (5/6): public workspace management #1695 (Public Workspaces). Carries all management phases, including Groups review fixes at 38a7582c0 via the normal Phase 5 merge 3731cdda8. Integration head 93e357c7e preserves safe validation responses and fail-closed expiry handling. Base f1c3ddab0 is included; named b0896b4c5 is already an ancestor.
  • Rollout: existing activity_logs containers require the registered descending timestamp/ID/user_id composite via App Maintenance and completion of Cosmos index transformation. New containers receive it automatically; browsing never changes cloud policy. Paging uses a timestamp cutoff, not a transactional snapshot.

Linked issue

No associated issue supplied. Continues #1685/#1686 and depends on #1692/#1695.

Release Notes & Latest Features

  • New Feature
  • Bug Fix
  • UI Enhancement
  • Breaking Change
  • Internal only

Is this visible to end users?

  • Yes
  • No

Is this admin-facing (Admin Settings, governance, deployment, config)?

  • Yes
  • No

Should this become a Latest Feature card?

  • Yes
  • No
  • Already added

Screenshot needed for the card?

  • Yes
  • No
  • Attached

Version bump

  • application/single_app/config.py VERSION third segment bumped, or not needed because this is docs-only
  • deployers/version.txt bumped, or not needed because deployers/ was not changed

Version 0.261.285, above Phase 5's reconciled 0.261.284. Historical implementation versions preserved. No deployer changes.

Testing / validation

  • Push-Location application\v2_ui; npm run build; $result=$LASTEXITCODE; Pop-Location; exit $result — passed; existing large-bundle warning remains.
  • Integrated functional command below — 156 passed, including inherited error-safety regressions. Scoped shim supplies the removed Werkzeug version attribute needed by this machine's older Flask test client; no installed dependencies or production modules modified.
@'
from importlib.metadata import version
from unittest.mock import patch
import pytest
import werkzeug
with patch.object(werkzeug, '__version__', version('werkzeug'), create=True):
    result = pytest.main(['functional_tests/test_v2_control_center_activity_logs_queries.py', 'functional_tests/test_v2_control_center_activity_logs_routes.py', 'functional_tests/test_cosmos_wave3a_indexing_maintenance.py', 'functional_tests/test_control_center_activity_logs_hardening.py', 'functional_tests/test_control_center_safe_exception_responses.py', 'functional_tests/test_v2_control_center_foundation.py', 'functional_tests/test_v2_control_center_dashboard.py', 'functional_tests/test_v2_control_center_users.py', 'functional_tests/test_v2_control_center_groups.py', 'functional_tests/test_v2_control_center_public_workspaces.py', 'functional_tests/test_v2_api_security.py', '-q', '--tb=short', '--disable-warnings'])
raise SystemExit(result)
'@ | python -
  • python -m pytest ui_tests\test_v2_control_center_activity_logs.py ui_tests\test_v2_control_center_public_workspaces.py ui_tests\test_v2_control_center_groups.py ui_tests\test_v2_control_center_users.py ui_tests\test_v2_control_center_dashboard.py -q --tb=short — 24 passed, built local assets/intercepted APIs.
  • Earlier browser command adding ui_tests\test_control_center_activity_logs_layout.py ui_tests\test_control_center_activity_logs_layout_presets.py ui_tests\test_control_center_activity_logs_auto_refresh.py — 24 passed, 3 skipped; legacy suites require a running authenticated app.
  • python functional_tests\route_tests\test_route_blueprint_policy_inventory.py — 12/12 passed.
  • python functional_tests\route_tests\test_route_unauthenticated_policy_contract.py — 7/7 passed.
  • python functional_tests\route_tests\test_route_policy_test_coverage.py — 3/3 passed.
  • python scripts\build_docs_inventory.py — passed, inventory unchanged.
  • python functional_tests\test_docs_app_surface_coverage.py — 7/7 passed.
  • python functional_tests\test_docs_site_quality.py — 6/6 passed.
  • Stacked XSS/BAC commands below — 17 and 7 files passed, respectively.
$base='origin/paullizer-react-v2-ui'
$files=@(git diff --name-only $base HEAD | Where-Object { $_ -match '^application/' -and $_ -match '\.(py|js|html|ts|tsx|jsx|mjs)$' } | ForEach-Object { $_.Replace('/','\') })
python scripts\check_xss_sinks.py --base-sha $base --head-sha HEAD @files
$pythonFiles=@($files | Where-Object { $_ -match '\.py$' })
python scripts\check_broken_access_control.py --base-sha $base --head-sha HEAD @pythonFiles
  • git diff --check — passed. Initial Impeccable mechanical detector — no findings.
  • Not run: live Cosmos/index transformation or Azure-hosted browser service. Contract tests cover timestamp and cross-partition ID ties without gaps/duplicates. Known unrelated admin-rail and management-ID-search failures excluded.
  • Legacy hardening exact historical version assertion uses the shared minimum-version helper; legacy route/template/JS checks remain intact.

Documentation

  • Release notes updated, or not needed
  • Feature documentation updated, or not needed
  • Fix documentation updated, or not needed

Feature/guide describe filters, sampling/export limits, index rollout and saved views. Release notes retain Activity Logs under v0.261.285, Public Workspaces v0.261.284 and Groups validation safety v0.261.283.

Security checklist

  • New Flask routes include @swagger_route(security=get_auth_security())
  • Settings sent to non-admin frontends use sanitize_settings_for_user()
  • Browser JavaScript is served from local SimpleChat static assets only; no CDN-hosted JS
  • No secrets, keys, connection strings, or local-only artifacts are included

Activity APIs require can_view_activity_logs through control_center_required('activity_logs'); dashboard-only readers are denied before storage access. Search is parameterized, CSV prefixes guarded, JSON text escaped, storage failures generic. All inherited Users/Groups validation-safety fixes retained.

Paul Lizer (paullizer) and others added 5 commits October 7, 2026 11:12
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve Router approval links, all management surfaces, and Activity Logs; bump application version to 0.261.284.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer) and others added 2 commits October 7, 2026 11:37
…otes

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread application/single_app/route_backend_control_center.py Fixed
Comment thread application/single_app/route_backend_control_center.py Fixed
Comment thread application/single_app/route_backend_control_center.py Fixed
Comment thread application/single_app/route_backend_control_center.py Fixed
Comment thread application/single_app/route_backend_control_center.py Fixed
Comment thread application/single_app/route_backend_control_center.py Outdated
Comment thread functional_tests/test_v2_control_center_public_workspaces.py Outdated
Comment thread functional_tests/test_v2_control_center_public_workspaces.py Outdated
Comment thread functional_tests/test_v2_control_center_groups.py Fixed
Comment thread application/single_app/route_backend_control_center.py Fixed
Paul Lizer (paullizer) and others added 4 commits October 7, 2026 11:59
Reconcile Activity Logs at 0.261.285 while preserving implementation history and all management validation fixes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Cover all five handlers with sensitive-exception regressions and remove unused test imports. Isolated for Phase 5 backport.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve Activity Logs version 0.261.286 and reconcile shared validation-fix documentation and test headers.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paullizer
Paul Lizer (paullizer) merged commit 01c4959 into microsoft:paullizer-react-v2-ui Oct 7, 2026
11 checks passed
Paul Lizer (paullizer) added a commit to paullizer/simplechat that referenced this pull request Oct 7, 2026
Brings in V2 at 01c4959 (microsoft#1692, VERSION 0.261.282 and 0.261.283,
microsoft#1695, VERSION 0.261.284, and microsoft#1693, VERSION 0.261.285 and 0.261.286).

Conflicts:
- docs/explanation/release_notes.md: V2's file byte-for-byte, with this
  branch's own (v0.261.282) section inserted at the very top, above V2's
  first section, (v0.261.286). Every V2 section is unchanged. The next
  commit renumbers this branch's section, because microsoft#1692 already uses
  0.261.282.
- application/single_app/config.py: V2's file, including its new
  activity-log indexing policy, with this branch's VERSION line
  (0.261.282) kept for the merge. The VERSION line was the only
  conflicting hunk. The next commit renumbers it above V2's 0.261.286.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer) added a commit to paullizer/simplechat that referenced this pull request Oct 7, 2026
V2 now uses 0.261.286 (microsoft#1693), and microsoft#1692 already uses 0.261.282, so this
branch's version moves above both. Renumbers the same 20 lines in 15
files as the previous bump: config.py, this branch's release-notes
section, the documentation version notes and the new tests' headers.
V2's own (v0.261.282) release-notes section is untouched. The tests'
version floor stays 0.261.253.

Refs microsoft#1549

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants