Repository navigation
Fix Control Center groups query and redesign V2 Activity Logs - #1708
Merged
Paul Lizer (paullizer) merged 3 commits intoOct 8, 2026
Merged
Paul Lizer (paullizer) merged 3 commits into
Paul Lizer (paullizer) merged 3 commits into
Conversation
GROUP is a reserved Cosmos SQL keyword, so dotted access such as c.group.group_id returned HTTP 400 and broke the V2 groups inventory, the group detail drawer, the Activity Logs group filter, every Activity Logs search (group.group_name was a search field) and the classic group activity timeline. Group paths are now bracket-quoted (c['group']) and the Cosmos query guard rejects dotted access to reserved keywords across all Control Center SQL. The groups inventory also tolerates malformed legacy group documents. Activity Logs now uses an Azure-portal-style filter pill bar, a slim clickable trend strip and a log table that shows people and workspace names (resolved server-side, cached and batched) instead of raw IDs. People, activity types and workspaces cross-filter in one click; a detail drawer ports V1's per-type details. Search also matches people names and emails. Times show in local time with a remembered UTC toggle. Saved views move to the account (one-time import from this browser). CSV export adds readable name and summary columns. New people and workspace lookup routes back the pill comboboxes. Version 0.261.294. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…s UX branch Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The V2 branch moved to 0.261.295 (workflow hand-off card), so this change and its docs and tests move from 0.261.294 to 0.261.296. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Paul Lizer (paullizer)
merged commit Oct 8, 2026
fe9ea87
into
paullizer-react-v2-ui
11 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GROUPis a reserved word in Cosmos SQL, so the dotted pathc.group.group_idwas a syntax error (HTTP 400). It broke the Groups list, the group details drawer, the Activity Logs group filter, every Activity Logs search (group.group_namewas a search field) and the classic group activity timeline. The nested object is now read asc['group']. A functional test now scans all Control Center SQL (classic routes included, plus the generated Activity Logs queries) for reserved keywords used as dotted names or aliases, so this can't quietly come back. Legacy group documents with a malformed owner, members or name no longer fail the whole list.Screenshots (Chromium, mocked data from the UI test fixture):
Worth a careful look:
GET /api/v2/control-center/activity-logs/people?q=andGET /api/v2/control-center/activity-logs/workspaces?q=, both with@swagger_route,@login_requiredand@control_center_required('activity_logs'). The existing page, summary and export routes also return names now (presentation,filter_labels,type_catalog). A failed name or people lookup is logged and degrades to IDs instead of failing the page.raw_json, but six readable columns (user_name,user_email,activity,summary,workspace_id,workspace_name) now sit before it, soraw_jsonmoves from column 6 to column 12.v2ActivityLogSavedViewsandv2ActivityLogPrefsare added to the user settings allowlist. While settings are loading or failed, the Views menu hides saving and the saved list, so a save can't overwrite views it couldn't read.paullizer-react-v2-ui(workflow hand-off card, 0.261.295) and bumps to 0.261.296. The only conflict wasVERSION.Linked issue
N/A (no issue was filed for this work).
Release Notes & Latest Features
Is this visible to end users?
Is this admin-facing (Admin Settings, governance, deployment, config)?
Should this become a Latest Feature card?
Screenshot needed for the card?
Version bump
application/single_app/config.pyVERSIONthird segment bumped, or not needed because this is docs-only (0.261.295 to 0.261.296)deployers/version.txtbumped, or not needed becausedeployers/was not changed (deployers/not changed)Testing / validation
All run on the final head
284ebe681(merged withpaullizer-react-v2-uiatcd333de9d). Python commands used a venv with Flask 3.1.3 and Werkzeug 3.1.6.python scripts/check_xss_sinks.py --base-sha cd333de9d --head-sha 284ebe681 <17 changed application files>: passed (17 files)python scripts/check_broken_access_control.py --base-sha cd333de9d --head-sha 284ebe681 <6 changed application .py files>: passed (6 files)python -m pytest functional_tests/test_v2_control_center_*.py functional_tests/test_v2_user_settings_*.py functional_tests/test_user_settings_allowlist_keys.py -q -p no:cacheprovider: 223 passedpython functional_tests/route_tests/test_route_blueprint_policy_inventory.py: 12/12 passedpython functional_tests/route_tests/test_route_unauthenticated_policy_contract.py: 7/7 passedpython functional_tests/route_tests/test_route_policy_test_coverage.py: 3/3 passedpython functional_tests/test_docs_app_surface_coverage.py: 7/7 passedpython functional_tests/test_docs_site_quality.py: 6/6 passednpm run buildinapplication/v2_ui(tsc -b && vite build): passedpython -m pytest test_v2_control_center_activity_logs.py test_v2_control_center_dashboard.py test_v2_control_center_data_health_removed.py test_v2_control_center_groups.py test_v2_control_center_public_workspaces.py test_v2_control_center_users.py -q -p no:cacheprovider --browser chromium(fromui_tests/, after the build): 37 passedpython -m pytest functional_tests/test_v2_admin_settings_rail_collapse.py -q -p no:cacheprovidergives 1 failed, 3 passed both here and on the target tipcd333de9d. It assertsdisabled={delegationDirty}in the admin settings rail, which this PR doesn't touch.Documentation
docs/explanation/features/V2_CONTROL_CENTER.md,docs/guides/v2-control-center.md)docs/explanation/fixes/V2_CONTROL_CENTER_RESERVED_KEYWORD_QUERY_FIX.md, follow-up note inV2_CONTROL_CENTER_COSMOS_QUERY_COMPATIBILITY_FIX.md)Security checklist
@swagger_route(security=get_auth_security())sanitize_settings_for_user()(no app settings are returned by the new or changed routes)