Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion application/single_app/config.py
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,7 @@
EXECUTOR_TYPE = 'thread'
EXECUTOR_MAX_WORKERS = 30
SESSION_TYPE = 'filesystem'
VERSION = "0.261.291"
VERSION = "0.261.292"
IS_DEVELOPMENT = is_development_env_enabled()

# Opt-out for deployments where App Service Easy Auth is active but the platform
Expand Down
31 changes: 0 additions & 31 deletions application/single_app/functions_activity_logging.py
Original file line number Diff line number Diff line change
Expand Up @@ -40,37 +40,6 @@ def _create_activity_record(record, idempotency_key=None):
return record


def has_activity_log_for_resource(user_id, activity_type, resource_id, workspace_type=None):
"""Check for an existing creation record within its user partition."""
if not user_id or not resource_id:
return False

if activity_type == 'conversation_creation':
resource_path = 'c.conversation.conversation_id'
elif activity_type == 'document_creation':
resource_path = 'c.document.document_id'
else:
raise ValueError("Unsupported activity type for resource lookup.")

query = (
"SELECT TOP 1 VALUE c.id FROM c "
f"WHERE c.activity_type = @activity_type AND {resource_path} = @resource_id"
)
parameters = [
{'name': '@activity_type', 'value': activity_type},
{'name': '@resource_id', 'value': resource_id},
]
if workspace_type:
query += " AND c.workspace_type = @workspace_type"
parameters.append({'name': '@workspace_type', 'value': workspace_type})
matches = cosmos_activity_logs_container.query_items(
query=query,
parameters=parameters,
partition_key=user_id,
)
return next(iter(matches), None) is not None


def coerce_activity_log_user_id(user_id: Any) -> str:
"""Extract a stable string user id from a scalar or session-style identity payload."""
if user_id is None:
Expand Down
59 changes: 30 additions & 29 deletions application/single_app/functions_control_center_groups.py
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
"""Server-side group inventory and validated selection for Control Center."""

import re
from collections import Counter, defaultdict
from datetime import datetime, timezone


Expand Down Expand Up @@ -118,49 +119,49 @@


def load_group_inventory(groups_container, documents_container, activity_container):
"""Four batched queries, independent of row count. Fail rather than invent totals."""
"""Four batched queries, independent of row count. Fail rather than invent totals.

The Python Cosmos SDK cannot run cross-partition GROUP BY, so the document, token and

Check warning on line 124 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
activity queries stream narrow projections and the totals are aggregated here.
"""
groups = list(groups_container.query_items(
query=("SELECT c.id, c.name, c.description, c.owner, c.users, c.admins, "
"c.documentManagers, c.status, c.createdDate, c.metrics FROM c"),
enable_cross_partition_query=True,
))
documents = {
row["group_id"]: int(row.get("total") or 0)
for row in documents_container.query_items(
query=("SELECT c.group_id, COUNT(1) AS total FROM c "
"WHERE c.type = 'document_metadata' AND IS_DEFINED(c.group_id) GROUP BY c.group_id"),
enable_cross_partition_query=True,
)
}
tokens = {
row["group_id"]: int(row.get("total") or 0)
for row in activity_container.query_items(
query=("SELECT c.workspace_context.group_id AS group_id, SUM(c.usage.total_tokens) AS total "
"FROM c WHERE c.activity_type = 'token_usage' "
"AND IS_DEFINED(c.workspace_context.group_id) AND IS_NUMBER(c.usage.total_tokens) "
"GROUP BY c.workspace_context.group_id"),
enable_cross_partition_query=True,
)
}
documents = Counter(documents_container.query_items(
query=("SELECT VALUE c.group_id FROM c "
"WHERE c.type = 'document_metadata' AND IS_STRING(c.group_id)"),
enable_cross_partition_query=True,
))
tokens = defaultdict(int)

Check warning on line 137 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
for row in activity_container.query_items(
query=("SELECT c.workspace_context.group_id AS group_id, c.usage.total_tokens AS tokens "

Check warning on line 139 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
"FROM c WHERE c.activity_type = 'token_usage' "

Check warning on line 140 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
"AND IS_STRING(c.workspace_context.group_id) AND IS_NUMBER(c.usage.total_tokens)"),

Check warning on line 141 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
enable_cross_partition_query=True,
):
tokens[row["group_id"]] += row["tokens"]

Check warning on line 144 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
# The writers use three group locations. One coalesced expression avoids duplicate
# records and includes admin CSV and approval events that use top-level group_id.
group_expression = (
"IIF(IS_STRING(c.group_id) AND c.group_id != '', c.group_id, "
"IIF(IS_STRING(c.group.group_id) AND c.group.group_id != '', "
"c.group.group_id, c.workspace_context.group_id))"
)
activity_times = {
row["group_id"]: row.get("last_activity")
for row in activity_container.query_items(
query=(f"SELECT {group_expression} AS group_id, MAX(c.timestamp) AS last_activity FROM c "
f"WHERE IS_STRING({group_expression}) AND {group_expression} != '' "
f"GROUP BY {group_expression}"),
enable_cross_partition_query=True,
)
}
activity_times = {}
for row in activity_container.query_items(
query=(f"SELECT {group_expression} AS group_id, c.timestamp FROM c "
f"WHERE IS_STRING({group_expression}) AND {group_expression} != '' "
"AND IS_STRING(c.timestamp)"),
enable_cross_partition_query=True,
):
group_id, timestamp = row["group_id"], row["timestamp"]
if timestamp > activity_times.get(group_id, ""):
activity_times[group_id] = timestamp
calculated_at = datetime.now(timezone.utc).isoformat()
return {
"rows": [group_row(group, documents.get(group["id"], 0), tokens.get(group["id"], 0),
"rows": [group_row(group, documents.get(group["id"], 0), int(tokens.get(group["id"], 0)),

Check warning on line 164 in application/single_app/functions_control_center_groups.py

View workflow job for this annotation

GitHub Actions / malicious-pr-security-review

Important - Changed line contains secret or sensitive data source marker. Recommendation%3A Pair this source with any nearby network, logging, serialization, or process execution sink before approving.
activity_times.get(group["id"])) for group in groups],
"calculated_at": calculated_at,
}
Expand Down
Loading
Loading