Repository navigation
Control Center V2 (5/6): public workspace management - #1695
Merged
Paul Lizer (paullizer) merged 10 commits intoOct 7, 2026
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Implement batched group inventory, guarded bulk status, detail workflows, approval-only destructive actions, reusable drawer sections, and regression coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve reviewed Users changes, advance Groups to version 0.261.282, retain dashboard safety fixes, and align approval links with the V2 Approvals detail contract. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
15 of 24 tasks
Preserve both release histories and existing Groups version lineage; return stable validation errors in all nine reviewed handlers, document fail-closed expiry handling, and remove redundant test imports. Advance application patch to 0.261.283. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Cover all five handlers with sensitive-exception regressions and remove unused test imports. Isolated for Phase 5 backport. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer)
merged commit Oct 7, 2026
0494663
into
microsoft:paullizer-react-v2-ui
11 checks passed
Paul Lizer (paullizer)
added a commit
to paullizer/simplechat
that referenced
this pull request
Oct 7, 2026
Brings in V2 at 01c4959 (microsoft#1692, VERSION 0.261.282 and 0.261.283, microsoft#1695, VERSION 0.261.284, and microsoft#1693, VERSION 0.261.285 and 0.261.286). Conflicts: - docs/explanation/release_notes.md: V2's file byte-for-byte, with this branch's own (v0.261.282) section inserted at the very top, above V2's first section, (v0.261.286). Every V2 section is unchanged. The next commit renumbers this branch's section, because microsoft#1692 already uses 0.261.282. - application/single_app/config.py: V2's file, including its new activity-log indexing policy, with this branch's VERSION line (0.261.282) kept for the merge. The VERSION line was the only conflicting hunk. The next commit renumbers it above V2's 0.261.286. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
38a7582c01100585076cfd76e7b7a1c577398f7f(including integrationf1c3ddab0). Integration base is used because Groups head branch is fork-only; this carries reviewed Users/Groups until Control Center V2 (4/6): group management #1692 lands. No rebase/amend/force-push.89114a2076b313126c61ddf51153778e8e45f13d, current version 0.261.285. Isolated Phase 6 commit4c99eeeebwas backported asee6f9ab8c: all five public workspace validation catches return fixed safe messages with HTTP 400 preserved; shared sensitive-exception regressions and unused-import cleanup included. No Phase 6 implementation pulled in.Linked issue
No standalone Phase 5 issue supplied. Dependency #1692; downstream #1693. No issue-closing claim.
Release Notes & Latest Features
Is this visible to end users?
Is this admin-facing (Admin Settings, governance, deployment, config)?
Should this become a Latest Feature card?
Screenshot needed for the card?
Version bump
application/single_app/config.pyVERSIONthird segment bumped, or not needed because this is docs-onlydeployers/version.txtbumped, or not needed becausedeployers/was not changedCurrent 0.261.285; feature implementation history remains 0.261.283, parent reconciliation .284, public validation safety .285. No deployer changes.
Testing / validation
Ignored local
.venvuses repository-compatible Flask 3.1.3 to avoid host Flask2/Werkzeug3 mismatch. Root commands unless noted.Latest safe-response backport: 127 passed (43 warnings)
Post-Groups-merge integrated suite: 256 passed (67 warnings) (before isolated error-message-only backport)
Post-merge typecheck/build passed; existing large-bundle warning. No UI code changed in backport.
18 built-local-UI browser tests passed (post-Groups merge; APIs intercepted; not rerun for message-only backport).
Standalone route-policy scripts: 12/12, 7/7, 3/3 passed; routes/decorators unchanged by backport.
Inventory regenerated after Groups merge; coverage 7/7 and quality 6/6 passed again after backport.
Latest backport XSS/BAC checks: passed, one changed route file each; whitespace passed.
Full Phase 5 post-merge guardrails: XSS4/BAC2 passed.
Implementation-phase Impeccable detector returned no findings. No live Azure tenant/Cosmos validation. Known unrelated rail-collapse/legacy management-pagination failures untouched.
Limitations: live OFFSET pages can shift during writes; equal recorded sort values lack guaranteed secondary ordering. List metrics are recorded snapshots with freshness; legacy refresh may not record tokens. Established public retention API cannot reset custom values to inherited
default. Activity/export uses recent20 allowlisted records. Existing public destructive routes submit correctly scoped approvals; the pre-existing executor can continue after individual document-cleanup failures. No direct classic bulk document deletion or approval queue added.Documentation
Updated V2_CONTROL_CENTER feature documentation, guide, release notes, and V2_CONTROL_CENTER_VALIDATION_ERRORS_FIX with current/implementation versions, exact supported workflows and limitations. Inventory unchanged after regeneration.
Security checklist
@swagger_route(security=get_auth_security())sanitize_settings_for_user()No new settings disclosure path. Inputs are bounded/parameterized; bulk cap500, export cap10,000. Native public permissions remain enforced. All fourteen Users/Groups/Public Workspace validation catches are covered by sensitive-exception response regressions.