Skip to content

Control Center V2 (5/6): public workspace management - #1695

Merged
Paul Lizer (paullizer) merged 10 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-control-center-v2-public-workspaces
Oct 7, 2026
Merged

Paul Lizer (paullizer) merged 10 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-control-center-v2-public-workspaces

Conversation

@paullizer

@paullizer Paul Lizer (paullizer) commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Production-ready Public Workspaces list: parameterized query-level search/status/owner filters, sorting/pagination, bounded cross-page selection, partial-failure bulk status actions, and injection-safe filtered CSV export. Five V2 APIs require Control Center admin; dashboard readers are denied.
  • Shared Groups drawer supports public metrics/status history, supported members/CSV, native retention, ownership/destructive approval submissions, activity/export, and Users/Activity Logs links. Native Owner/Admin permissions and existing public approval dispatch remain authoritative.
  • Depends on Control Center V2 (4/6): group management #1692; Control Center V2 (6/6): activity logs #1693 depends on this PR. Normally merged reviewed Groups 38a7582c01100585076cfd76e7b7a1c577398f7f (including integration f1c3ddab0). Integration base is used because Groups head branch is fork-only; this carries reviewed Users/Groups until Control Center V2 (4/6): group management #1692 lands. No rebase/amend/force-push.
  • Latest head 89114a2076b313126c61ddf51153778e8e45f13d, current version 0.261.285. Isolated Phase 6 commit 4c99eeeeb was backported as ee6f9ab8c: all five public workspace validation catches return fixed safe messages with HTTP 400 preserved; shared sensitive-exception regressions and unused-import cleanup included. No Phase 6 implementation pulled in.

Linked issue

No standalone Phase 5 issue supplied. Dependency #1692; downstream #1693. No issue-closing claim.

Release Notes & Latest Features

  • New Feature
  • Bug Fix
  • UI Enhancement
  • Breaking Change
  • Internal only

Is this visible to end users?

  • Yes
  • No

Is this admin-facing (Admin Settings, governance, deployment, config)?

  • Yes
  • No

Should this become a Latest Feature card?

  • Yes
  • No
  • Already added

Screenshot needed for the card?

  • Yes
  • No
  • Attached

Version bump

  • application/single_app/config.py VERSION third segment bumped, or not needed because this is docs-only
  • deployers/version.txt bumped, or not needed because deployers/ was not changed

Current 0.261.285; feature implementation history remains 0.261.283, parent reconciliation .284, public validation safety .285. No deployer changes.

Testing / validation

Ignored local .venv uses repository-compatible Flask 3.1.3 to avoid host Flask2/Werkzeug3 mismatch. Root commands unless noted.

Latest safe-response backport: 127 passed (43 warnings)

.\.venv\Scripts\python.exe -m pytest functional_tests\test_control_center_safe_exception_responses.py functional_tests\test_v2_control_center_public_workspaces.py functional_tests\test_v2_control_center_groups.py functional_tests\test_v2_control_center_users.py functional_tests\test_control_center_public_writers.py -q --tb=short --disable-warnings

Post-Groups-merge integrated suite: 256 passed (67 warnings) (before isolated error-message-only backport)

.\.venv\Scripts\python.exe -m pytest functional_tests\test_v2_control_center_public_workspaces.py functional_tests\test_v2_control_center_groups.py functional_tests\test_v2_control_center_users.py functional_tests\test_v2_control_center_foundation.py functional_tests\test_v2_control_center_dashboard.py functional_tests\test_v2_api_security.py functional_tests\test_control_center_public_writers.py functional_tests\test_control_center_safe_exception_responses.py functional_tests\route_tests\test_route_blueprint_policy_inventory.py functional_tests\route_tests\test_route_unauthenticated_policy_contract.py functional_tests\route_tests\test_route_policy_test_coverage.py functional_tests\test_v2_ui_local_assets.py functional_tests\test_public_membership_apis.py functional_tests\test_public_workspace_membership_writer_safety.py -q --tb=short --disable-warnings

Post-merge typecheck/build passed; existing large-bundle warning. No UI code changed in backport.

cd application\v2_ui; npm run typecheck && npm run build

18 built-local-UI browser tests passed (post-Groups merge; APIs intercepted; not rerun for message-only backport).

.\.venv\Scripts\python.exe -m pytest ui_tests\test_v2_control_center_public_workspaces.py ui_tests\test_v2_control_center_groups.py ui_tests\test_v2_control_center_users.py -q --tb=short --disable-warnings

Standalone route-policy scripts: 12/12, 7/7, 3/3 passed; routes/decorators unchanged by backport.

.\.venv\Scripts\python.exe functional_tests\route_tests\test_route_blueprint_policy_inventory.py
.\.venv\Scripts\python.exe functional_tests\route_tests\test_route_unauthenticated_policy_contract.py
.\.venv\Scripts\python.exe functional_tests\route_tests\test_route_policy_test_coverage.py

Inventory regenerated after Groups merge; coverage 7/7 and quality 6/6 passed again after backport.

python .\scripts\build_docs_inventory.py
python .\functional_tests\test_docs_app_surface_coverage.py
python .\functional_tests\test_docs_site_quality.py

Latest backport XSS/BAC checks: passed, one changed route file each; whitespace passed.

python .\scripts\check_xss_sinks.py --base-sha 3731cdda8 application\single_app\route_backend_control_center.py
python .\scripts\check_broken_access_control.py --base-sha 3731cdda8 application\single_app\route_backend_control_center.py
git diff --check

Full Phase 5 post-merge guardrails: XSS4/BAC2 passed.

python .\scripts\check_xss_sinks.py --base-sha 38a7582c01100585076cfd76e7b7a1c577398f7f application\v2_ui\src\components\controlCenter\PublicWorkspacesSection.tsx application\v2_ui\src\components\controlCenter\GroupDetailDrawer.tsx application\v2_ui\src\components\controlCenter\ControlCenterPrimitives.tsx application\single_app\route_backend_control_center.py
python .\scripts\check_broken_access_control.py --base-sha 38a7582c01100585076cfd76e7b7a1c577398f7f application\single_app\route_backend_control_center.py application\single_app\functions_control_center_public_workspaces.py

Implementation-phase Impeccable detector returned no findings. No live Azure tenant/Cosmos validation. Known unrelated rail-collapse/legacy management-pagination failures untouched.

Limitations: live OFFSET pages can shift during writes; equal recorded sort values lack guaranteed secondary ordering. List metrics are recorded snapshots with freshness; legacy refresh may not record tokens. Established public retention API cannot reset custom values to inherited default. Activity/export uses recent20 allowlisted records. Existing public destructive routes submit correctly scoped approvals; the pre-existing executor can continue after individual document-cleanup failures. No direct classic bulk document deletion or approval queue added.

Documentation

  • Release notes updated, or not needed
  • Feature documentation updated, or not needed
  • Fix documentation updated, or not needed

Updated V2_CONTROL_CENTER feature documentation, guide, release notes, and V2_CONTROL_CENTER_VALIDATION_ERRORS_FIX with current/implementation versions, exact supported workflows and limitations. Inventory unchanged after regeneration.

Security checklist

  • New Flask routes include @swagger_route(security=get_auth_security())
  • Settings sent to non-admin frontends use sanitize_settings_for_user()
  • Browser JavaScript is served from local SimpleChat static assets only; no CDN-hosted JS
  • No secrets, keys, connection strings, or local-only artifacts are included

No new settings disclosure path. Inputs are bounded/parameterized; bulk cap500, export cap10,000. Native public permissions remain enforced. All fourteen Users/Groups/Public Workspace validation catches are covered by sensitive-exception response regressions.

Paul Lizer (paullizer) and others added 6 commits October 7, 2026 10:25
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Implement batched group inventory, guarded bulk status, detail workflows, approval-only destructive actions, reusable drawer sections, and regression coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve reviewed Users changes, advance Groups to version 0.261.282, retain dashboard safety fixes, and align approval links with the V2 Approvals detail contract.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer) and others added 2 commits October 7, 2026 11:53
Preserve both release histories and existing Groups version lineage; return stable validation errors in all nine reviewed handlers, document fail-closed expiry handling, and remove redundant test imports. Advance application patch to 0.261.283.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread application/single_app/route_backend_control_center.py Outdated
Comment thread application/single_app/route_backend_control_center.py Outdated
Comment thread application/single_app/route_backend_control_center.py Outdated
Comment thread application/single_app/route_backend_control_center.py Outdated
Comment thread application/single_app/route_backend_control_center.py Outdated
Comment thread functional_tests/test_v2_control_center_public_workspaces.py Outdated
Comment thread functional_tests/test_v2_control_center_public_workspaces.py Outdated
Paul Lizer (paullizer) and others added 2 commits October 7, 2026 12:10
Cover all five handlers with sensitive-exception regressions and remove unused test imports. Isolated for Phase 5 backport.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paullizer
Paul Lizer (paullizer) merged commit 0494663 into microsoft:paullizer-react-v2-ui Oct 7, 2026
11 checks passed
Paul Lizer (paullizer) added a commit to paullizer/simplechat that referenced this pull request Oct 7, 2026
Brings in V2 at 01c4959 (microsoft#1692, VERSION 0.261.282 and 0.261.283,
microsoft#1695, VERSION 0.261.284, and microsoft#1693, VERSION 0.261.285 and 0.261.286).

Conflicts:
- docs/explanation/release_notes.md: V2's file byte-for-byte, with this
  branch's own (v0.261.282) section inserted at the very top, above V2's
  first section, (v0.261.286). Every V2 section is unchanged. The next
  commit renumbers this branch's section, because microsoft#1692 already uses
  0.261.282.
- application/single_app/config.py: V2's file, including its new
  activity-log indexing policy, with this branch's VERSION line
  (0.261.282) kept for the merge. The VERSION line was the only
  conflicting hunk. The next commit renumbers it above V2's 0.261.286.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants