Skip to content

trunk-merge/pr-110530/e7ac1ae0-9283-4294-94e2-4c8e34138983 - #110535

Closed
trunk-io[bot] wants to merge 18 commits into
masterfrom
trunk-merge/pr-110530/e7ac1ae0-9283-4294-94e2-4c8e34138983
Closed

trunk-io[bot] wants to merge 18 commits into
masterfrom
trunk-merge/pr-110530/e7ac1ae0-9283-4294-94e2-4c8e34138983

Conversation

@trunk-io

@trunk-io trunk-io Bot commented Oct 2, 2026

Copy link
Copy Markdown
Trunk Merge Pull Request Banner

This pull request was created and is being managed by Trunk Merge.

This pull request is based on the master branch at SHA 3d69600a8a7a599bf78ea186748e56d12462a7ac.

See more details about each PR in the batch here:

When CI completes, this pull request will be closed automatically.

Pull Requests Being Tested

This pull request is testing a batch with the changes from pull requests 110530 and 107531 - batching documentation.

Dependencies

This pull request depends on the changes from pull requests 109387 and 110527.

a-lider and others added 18 commits September 30, 2026 20:21
The pending invite indicator in the account menu moves from the project row to the organization row, and the pending invite list moves from the project switcher to the organization switcher. An invite joins an organization, so the indicator now sits where the invite is accepted.

Generated-By: PostHog Desktop
Task-Id: 3c469151-6420-43b0-8fb4-d290680020ab
The dot now carries a tooltip that names the organization that sent the invite and says where to accept it. The old project button no longer sets its own tooltip, so a single tooltip appears on hover.

Generated-By: PostHog Desktop
Task-Id: 3c469151-6420-43b0-8fb4-d290680020ab
The dot halo no longer spills onto the project name, the tooltip is one
sentence, and the pending invite row in the organization switcher uses
the same logo, alignment and tag as the other organization rows.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…letion

The pending deletion page showed the organization switcher only to users
with other organizations. Pending invites now live in that switcher, so
show it when the user has a pending invite too.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
6 updated, 4 removed
Run: feb50236-da32-4eb9-abfc-f9b4d0f6a0c2

Co-authored-by: a-lider <221966567+a-lider@users.noreply.github.com>
The test opens the briefing once with a Prague timezone and once with the
project's UTC, and expects the same briefing. A briefing day starts at
eight local time, so between 06:00 and 08:00 UTC the two calls fall on
different days and the test fails for every pull request.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Between 06:00 and 08:00 UTC a call without a timezone reads the project's
briefing day, which is the day before for a person in Prague. The day
boundary test now asserts that at a pinned time.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (18)
.cursor/rules/react-typescript.mdc — auto-discovered
.agents/skills/using-kea-disposables/SKILL.md — configured
.agents/skills/writing-ui-components/SKILL.md — configured
.agents/security.md — configured
.agents/skills/sending-notifications/SKILL.md — configured
services/mcp/AGENTS.md — auto-discovered
docs/published/handbook/engineering/type-system.md — configured
.agents/skills/implementing-mcp-tools/SKILL.md — configured
.agents/skills/writing-tests/SKILL.md — configured
docs/internal/person-data-access.md — configured
.agents/skills/adopting-generated-api-types/SKILL.md — configured
.agents/skills/setting-feature-flags-in-storybook/SKILL.md — configured
.agents/skills/placing-product-frontend-code/SKILL.md — configured
.claude/commands/conventions.md — configured
.agents/skills/writing-kea-logics/SKILL.md — configured
.agents/skills/writing-user-facing-copy/SKILL.md — configured
.agents/skills/implementing-mcp-ui-apps/SKILL.md — configured
… and 1 more
📝 Walkthrough

Walkthrough

Billing usage and spend requests now default to the last 30 complete UTC days when both dates are omitted. Pending invitations appear in the organization switcher and account navigation, while the project switcher no longer handles invitations. The changes also update briefing timezone tests and the sandbox agent version pin.

Priority: ⬇️ Low

Estimated code review effort:

Merge Risk: 🔵 Low · up to 2d48d

The invitation action works, but its missing stable selector makes it harder to target reliably in analytics and automated tests. This is a localized fix and does not block merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2d48d

The inspected changes preserve billing access controls and route invitations through the existing acceptance flow. No new access or broader permissions were demonstrated, but some release and recovery behavior remains unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected date changes affect the time window within existing authorized billing reads, not the caller’s organization or project authority. Moving invitation navigation likewise preserves the existing ID-based acceptance path rather than granting access through organization selection.

Trust Boundaries and Controls

  • observed — Billing consumers resolve the organization, validate requested project ownership, and narrow project scope before forwarding requests. Organization-timeseries handling checks effective grants and intersects credential, visible-project, and token scopes; export handling applies additional export permissions independently of date defaults.
  • observed — Invitation validation rejects recipient mismatches, expired invitations, and existing organization membership. Acceptance invokes this validation again through invite.use; missing or already-consumed invite rows are rejected. These controls and the acceptance implementation are unchanged by the navigation move.

Resilience and Maintainability Implications

  • observed — The existing acceptance implementation encloses membership creation, inviter attribution, private-project grants, and invite cleanup in a transaction. It locks the invite row before mutation to serialize acceptance of the same invitation, and the API wraps new-user creation and acceptance in an outer transaction. These provide database failure containment, without proving all post-transaction response-loss or concurrent sibling-invitation outcomes.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description only documents the Trunk Merge batch, base commit, dependencies, and automatic closure. It does not describe the user-facing problem, changes, tests, release status, docs update, or ag… Replace or supplement the Trunk Merge text with a complete PR description. Add Problem, Changes, How did you test this code?, Test rationale, exactly one Release status option, Automatic notifications, Docs update, and required Agent contex…
Full details: Description check

Explanation

The description only documents the Trunk Merge batch, base commit, dependencies, and automatic closure. It does not describe the user-facing problem, changes, tests, release status, docs update, or agent context required by the repository template.

Resolution

Replace or supplement the Trunk Merge text with a complete PR description. Add Problem, Changes, How did you test this code?, Test rationale, exactly one Release status option, Automatic notifications, Docs update, and required Agent context details. Include screenshots for the frontend changes and testing evidence for the billing, navigation, briefing, and sandbox updates.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (1)
frontend/src/lib/components/Account/OrgSwitcher.tsx-317-317 (1)

317-317: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add a stable selector to the invitation button.

Combobox.Item supplies only Base UI state attributes. ButtonPrimitive forwards them but does not create a meaningful data-attr. Add the required kebab-case selector.

Suggested fix
 <ButtonPrimitive
     {...props}
+    data-attr="org-switcher-pending-invite"
     menuItem

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 8e0ded9f-37b9-437e-8447-3a7ee3db2f72

📥 Commits

Reviewing files that changed from the base of the PR and between 3d69600 and 2d48d1f.

⛔ Files ignored due to path filters (3)
  • products/billing/frontend/generated/api.schemas.ts is excluded by !**/generated/**
  • services/mcp/src/generated/billing/api.ts is excluded by !**/generated/**
  • services/mcp/src/tools/generated/billing.ts is excluded by !**/generated/**
📒 Files selected for processing (17)
  • docs/published/handbook/engineering/ai/implementing-mcp-tools.md
  • ee/api/billing.py
  • ee/api/test/test_billing.py
  • frontend/snapshots.yml
  • frontend/src/lib/components/Account/NewAccountMenu.tsx
  • frontend/src/lib/components/Account/OrgSwitcher.stories.tsx
  • frontend/src/lib/components/Account/OrgSwitcher.tsx
  • frontend/src/lib/components/Account/ProjectMenu.tsx
  • frontend/src/lib/components/Account/ProjectSwitcher.stories.tsx
  • frontend/src/lib/components/Account/ProjectSwitcher.tsx
  • frontend/src/scenes/project/PendingDeletion.tsx
  • products/billing/mcp/tools.yaml
  • products/tasks/backend/sandbox/images/Dockerfile.sandbox-base
  • products/today/backend/tests/test_api.py
  • services/mcp/src/api/generated.ts
  • services/mcp/tests/unit/__snapshots__/tool-schemas/billing-spend-get.json
  • services/mcp/tests/unit/__snapshots__/tool-schemas/billing-usage-get.json
💤 Files with no reviewable changes (1)
  • products/billing/mcp/tools.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 4 remain after this review.

@trunk-io trunk-io Bot closed this Oct 2, 2026
@trunk-io
trunk-io Bot deleted the trunk-merge/pr-110530/e7ac1ae0-9283-4294-94e2-4c8e34138983 branch October 2, 2026 07:27
@trunk-io

trunk-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Author

Static Badge   Static Badge   Static Badge

Failed Test Failure Summary Logs
Scenes/Code review Default play-test The test failed because a logic component was not mounted when accessed, and there were unhandled network requests intercepted by the mock service... Logs ↗︎
Scenes/Code review Default play-test A logic access error occurred because 'actions' on 'scenes.userLogic' was not mounted, likely due to missing logic connection or incorrect componen... Logs ↗︎

View Full Report ↗︎ ⋅ Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants