Skip to content

trunk-merge/pr-108896/91445bc8-77e0-4bd6-8e5f-202f267ff86a-bisection - #108911

Closed
trunk-io[bot] wants to merge 4 commits into
masterfrom
trunk-merge/pr-108896/91445bc8-77e0-4bd6-8e5f-202f267ff86a-bisection
Closed

trunk-io[bot] wants to merge 4 commits into
masterfrom
trunk-merge/pr-108896/91445bc8-77e0-4bd6-8e5f-202f267ff86a-bisection

Conversation

@trunk-io

@trunk-io trunk-io Bot commented Sep 30, 2026

Copy link
Copy Markdown
Trunk Merge Pull Request Banner

This pull request was created and is being managed by Trunk Merge.

This pull request is based on the master branch at SHA 1c66a26fd9f969905a64bc564e302f70bee1736d.

See more details here.

When CI completes, this pull request will be closed automatically.

Pull Requests Being Tested

This pull request is testing the changes from pull request 108896.

Batch Bisection

This pull request is in a batch bisection. Pull requests successfully tested by this PR will re-enter the main queue.

puemos and others added 4 commits September 30, 2026 06:06
The web today-rail-nav Spaces pane now uses the same collapsible Pinned, Recent and Spaces sections as the PostHog Desktop Work column.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 85589ca0-f089-4bfd-b89c-8568fd2d4ed5
Reorder the inline typegen block so the CI typegen check passes. Show an error state with a retry button when recent sessions fail to load. Use local-time fixtures in the day-label tests so they pass in any TZ.

Generated-By: PostHog Desktop
Task-Id: 8ee12b4a-4ffe-4706-9769-51722a1653cb
The star action and the "Add the spaces you work in" button return with the space menu. This keeps the PR under the stamphog size gate.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 85589ca0-f089-4bfd-b89c-8568fd2d4ed5
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: b5374d89-580f-4999-9775-b3f863c6101d

📥 Commits

Reviewing files that changed from the base of the PR and between 1c66a26 and 9f0c1b1.

📒 Files selected for processing (7)
  • frontend/src/layout/today/TodayPaneSection.tsx
  • frontend/src/layout/today/TodayShell.scss
  • frontend/src/layout/today/TodaySpacesSidebar.tsx
  • frontend/src/layout/today/todaySpacesLogic.ts
  • frontend/src/layout/today/todayWorkItems.test.ts
  • frontend/src/layout/today/todayWorkItems.ts
  • frontend/src/scenes/project-homepage/today/Today.stories.tsx

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The Today sidebar now displays collapsible Pinned, Recent, and Spaces sections. Recent items combine sessions and chats, exclude pinned or archived sessions, sort by activity, and group by day. Spaces can show starred spaces or all visible spaces. Task loading, empty, and retry states are reflected in the sidebar.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 9f0c1

The sidebar adds collapsible pinned and recent work sections while preserving access to all spaces through the browse control. No concrete merge-blocking risk remains after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 9f0c1

The sidebar reuses existing task APIs and navigation. No new authorization bypass has been established, and ordinary project switching and logout replace the page. Server-side task visibility controls and some asynchronous lifecycle behavior remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The added exposure is automatic retrieval and presentation of task summaries in the existing sidebar, rather than task execution or a new privileged operation. The effective data scope depends on the existing task endpoint's authorization and response filtering; request limits and client-side filters do not establish tenant or asset isolation.

Trust Boundaries and Controls

  • observed — The frontend requires team context for pinned reads and team plus user context for recent reads. These guards prevent requests without local context, but projectId, pinned, and created_by remain client-supplied parameters. Backend enforcement of membership, task visibility, and field redaction was not verified.

Resilience and Maintainability Implications

  • inferred — Existing full-document navigation on ordinary project/organization switching and logout limits the stale-identity scenario suggested by untagged frontend task state. This counterevidence does not establish protection for every possible identity transition or framework-level late response, so those remain coverage limitations rather than verified PR vulnerabilities.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description only contains Trunk Merge metadata. It does not explain the user problem, visible changes, testing, release status, notifications, documentation impact, or agent context required by th… Replace the Trunk Merge-only text with a completed repository-template description. Add Problem, Changes, How did you test this code?, Release status, Automatic notifications, Docs update, and Agent context sections. Include screenshots for…
Full details: Description check

Explanation

The description only contains Trunk Merge metadata. It does not explain the user problem, visible changes, testing, release status, notifications, documentation impact, or agent context required by the repository template.

Resolution

Replace the Trunk Merge-only text with a completed repository-template description. Add Problem, Changes, How did you test this code?, Release status, Automatic notifications, Docs update, and Agent context sections. Include screenshots for the frontend changes and state the automated tests that were run or what could not be tested.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@trunk-io trunk-io Bot closed this Sep 30, 2026
@trunk-io
trunk-io Bot deleted the trunk-merge/pr-108896/91445bc8-77e0-4bd6-8e5f-202f267ff86a-bisection branch September 30, 2026 05:51
@trunk-io

trunk-io Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Author

Static Badge   Static Badge   Static Badge

Failed Test Failure Summary Logs
Dashboards › Editing an insight updates the dashboard tile The test exceeded the maximum allowed time and timed out. Logs ↗︎

View Full Report ↗︎ ⋅ Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant