Skip to content

trunk-merge/pr-110601/6846e8ee-5b94-4e59-86e7-c1faa79c6449 - #110950

Closed
trunk-io[bot] wants to merge 53 commits into
masterfrom
trunk-merge/pr-110601/6846e8ee-5b94-4e59-86e7-c1faa79c6449
Closed

trunk-io[bot] wants to merge 53 commits into
masterfrom
trunk-merge/pr-110601/6846e8ee-5b94-4e59-86e7-c1faa79c6449

Conversation

@trunk-io

@trunk-io trunk-io Bot commented Oct 2, 2026

Copy link
Copy Markdown
Trunk Merge Pull Request Banner

This pull request was created and is being managed by Trunk Merge.

This pull request is based on the master branch at SHA 662ed11756653c2f52b855a01ee19a0c13b23faa.

See more details about each PR in the batch here:

When CI completes, this pull request will be closed automatically.

Pull Requests Being Tested

This pull request is testing a batch with the changes from pull requests 110601, 110579, 110801, and 110856 - batching documentation.

Dependencies

This pull request depends on the changes from pull requests 110905, 110273, 110906, 110347, 110830, 110789, 110415, and 110160.

frankh and others added 30 commits October 1, 2026 17:26
The button opened the Fundamentals tab, which is behind the METRICS_FUNDAMENTALS flag. Without the flag, the scene fell back to the overview tab.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 5a2b9f43-13fb-4aca-b9f3-a249aa554c8d
Removes the Fundamentals tab, its logic, the /metrics/explain/ action with its diagnostics and fundamentals modules, the metrics-fundamentals flag constants, and the MCP tool entry. Regenerates the API types.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 5a2b9f43-13fb-4aca-b9f3-a249aa554c8d
Generated-By: PostHog Desktop
Task-Id: 5a2b9f43-13fb-4aca-b9f3-a249aa554c8d
Direct-mint sites each built an OAuthAccessToken row by hand: generate the
token value, compute expiry from now, set scope and team pinning. Copies of
security-sensitive code drift, and new callers (WebMCP is next) would add one
more. `mint_oauth_access_token` in posthog/models/oauth.py now owns that,
next to the model and the other token lookups, so products can import it
without reaching into posthog.temporal.

- Move the sandbox/wizard run mint in posthog/temporal/oauth.py and both
  streamlit_apps mints (iframe and bridge) onto the helper.
- No behavior change: same token format, scope strings, lifetimes and
  scoped_teams; sandbox_task_id stays null where it was not set.
- Leave the authorization-code/refresh flows (oauth views, agentic and
  Stripe provisioning, Stripe integration, generate_stripe_app_tokens)
  alone. They pair the access token with a refresh token, rotate rows, or
  take values from oauthlib, so they stay explicit.
A click on a text highlight or an image pin opens the thread in a popover next to it. The comments button opens a menu with comments on the whole file and a list of every thread. The comments side panel is removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: b999fc3e-c145-4e0e-9851-6ef273201d04
Add products/autoresearch/backend/** to the selfDriving container-image path filter, and keep it in generalPurpose while both workers register autoresearch.

Include the clipped capture error_description in the InferenceRunError for a failed or partial prediction emit, so a transport failure records the underlying exception text.

Closes #110837

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 738aed62-67b4-4867-adb2-40a71130ad17
A requests transport error starts with the target host and ends with the cause, such as the errno. The head-only clip cut the cause, so a refused connection and a failed DNS lookup gave the same run error. The clip now keeps the start and the end of the description inside the same 200-character limit.

The emit-failure test now uses a requests-style refused-connection message and checks that the errno survives the clip.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 30cf875e-5854-447b-b60d-3fdb1f89e4c3
…er (#110771)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The services query scanned every series-hour row of the last day. The
services_by_hour projection on metrics4_series holds the same rollup per
team, hour and service, but the query shape kept ClickHouse from using it.

The query now filters on time_bucket, counts series with uniq, and
aggregates the bare last_seen column with convertToProjectTimezone off,
converting to UTC outside max(). metric_series exposes time_bucket for
the filter.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 3538a544-5668-418a-aebd-c3430d18864a
The overview test now runs the services query with
force_optimize_projection, so ClickHouse rejects the query when the
projection is not used. HogQL settings accept the new field.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 3538a544-5668-418a-aebd-c3430d18864a
…lest page

Entity endpoints like ad_creatives have no date range to narrow. When Meta
refused the smallest page, the sync raised the shrink-exhausted error, which
is non-retryable and auto-disables the schema. That error is usually load on
Meta's side and clears on a later attempt.

The entity path now retries the smallest page with backoff, then raises a
retryable error without Meta's raw body, so Temporal resumes from the saved
cursor and the schema stays enabled.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The same overview lives on the models scene's data quality tab.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The New chat button in the Today rail opened the old PostHog AI page. It now opens /spaces/new, a Desktop-style page with a space picker and the task composer. The session files into the personal space until the user picks another space.

Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
The Today rail button and its empty-state hint now say New session. The new session page and the space Activity tab render the same SpaceTaskComposer component. The data-attr values stay the same.

Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
…ktop

The heading and composer now sit with their middle 34% down the scene, in a 600px column, as on PostHog Desktop. Flex spacers do the placement, so the block stays below the top edge in a short window and the page does not scroll.

Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
…ult label

A space's New session opens /spaces/:id/new with that space chosen. The generic New session buttons use the last space the person was in, else their personal space, like PostHog Desktop's scoped space. A pick in the heading moves to that space's route. The quill model picker no longer shows the "Default ·" prefix, which Desktop does not show. The space page's ?compose=1 link had no callers left, so it is removed.

Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
…utes

Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
…outes

Generated-By: PostHog Desktop
Task-Id: cf2d5082-cc69-4bf1-8ac5-d16302185ff0
andrewm4894 and others added 23 commits October 2, 2026 15:50
Behind the autoresearch-report-notebook flag, grant the training sandbox notebook:read and notebook:write and add a Finalize step: the agent builds one report notebook from the system.autoresearch_* tables and passes its short_id to complete. report.md stays required.

complete_training_run stores report_notebook_short_id in the run summary only if the notebook exists in the run's team. A bad id or a failed check stores an empty value and never fails completion.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: d418feae-635a-4fa8-a762-6defae581a72
The Data Ops scene no longer has a data quality tab, so /data-ops?tab=data-quality falls back to the default tab and the spec timed out waiting for the check controls. The same overview still renders on the Models scene, so the test navigates there instead and only needs the data quality checks flag.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 789f88f8-021d-4728-8b98-92c94b145315
A cited PostHog object in the task Artifacts tab now shows its own app page in a same-origin frame, for every object kind that has a page. The frame keeps the page's URL and navigation apart from the task page. A frame named posthog-embedded-page puts the app in a new embedded navigation mode, which renders the scene without the navigation, command palette or floating buttons. The per-kind insight, SQL, dashboard and replay embeds are gone, and a kind with no page keeps the card.

The app CSP frame-ancestors now includes 'self', because the app could not frame its own pages before. Events captured in the frame carry embedded_page_frame: true.

Also fixes the app failing to start when Django sends null bootstrap flags, which happens when it cannot evaluate flags locally and a last-seen flag cache exists.

Generated-By: PostHog Desktop
Task-Id: e2367959-ab88-40ff-8761-5632645167aa
The cited-object frame now has a sandbox attribute. It keeps the app's origin, scripts, forms and new tabs, and it cannot navigate the task page.

Events from the frame get embedded_page_frame per event through before_send. register() persisted the property in storage the main window shares, so it marked the user's ordinary events too.

'self' moves out of app_frame_ancestor_sources() and onto the app policy only. The canvas sandbox document on the user-content origin shares that list, so its policy stays as it was.

Generated-By: PostHog Desktop
Task-Id: e2367959-ab88-40ff-8761-5632645167aa
The embed is keyed by its page URL instead of the artifact id, so the loading state starts over for any new page the frame shows.

Generated-By: PostHog Desktop
Task-Id: e2367959-ab88-40ff-8761-5632645167aa
Resolve the SOURCES.md conflict with master while preserving both newly registered AWS sources.
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (27)
products/autoresearch/backend/presentation/AGENTS.md — auto-discovered
products/autoresearch/backend/inference/AGENTS.md — auto-discovered
products/posthog_ai/frontend/AGENTS.md — auto-discovered
.cursor/rules/react-typescript.mdc — auto-discovered
.agents/skills/using-kea-disposables/SKILL.md — configured
.agents/skills/writing-ui-components/SKILL.md — configured
.agents/skills/authoring-ci-workflows/SKILL.md — configured
.agents/skills/gating-production-deploys/SKILL.md — configured
posthog/temporal/AGENTS.md — auto-discovered
.agents/security.md — configured
products/autoresearch/backend/dataset/AGENTS.md — auto-discovered
posthog/hogql/database/schema/AGENTS.md — auto-discovered
products/autoresearch/AGENTS.md — auto-discovered
products/autoresearch/mcp/AGENTS.md — auto-discovered
services/mcp/CONTRIBUTING.md — configured
.agents/skills/sending-notifications/SKILL.md — configured
services/mcp/AGENTS.md — auto-discovered
… and 10 more
📝 Walkthrough

Walkthrough

The pull request adds embedded-frame handling and new task-session routes, changes AI provider and stream cleanup behavior, and adds optional report notebooks to autoresearch runs. It removes metrics fundamentals UI and API functionality while updating metrics overview queries. It also revises task-artifact comments and object previews, adds AWS Inspector as a warehouse source, and changes Meta Ads retry handling. Additional changes centralize OAuth token creation and refine inference capture errors.

Priority: ⬇️ Low

🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description only documents Trunk Merge batching, included PRs, dependencies, and the base commit. It omits the required Problem, Changes, testing details and rationale, Release status, notificatio… Replace the Trunk Merge-only text with a repository-template description. Add a standalone Problem section, summarize the user-visible and mechanical Changes, document automated tests and untested areas with test rationale, select exactly o…
Full details: Description check

Explanation

The description only documents Trunk Merge batching, included PRs, dependencies, and the base commit. It omits the required Problem, Changes, testing details and rationale, Release status, notifications, docs update, and Agent context sections. It does not explain the user-visible purpose of the substantial changes listed in the PR.

Resolution

Replace the Trunk Merge-only text with a repository-template description. Add a standalone Problem section, summarize the user-visible and mechanical Changes, document automated tests and untested areas with test rationale, select exactly one Release status option, complete notification and docs fields, and include Agent context if applicable.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Usage-based review receipt

  • Mode: Continue automatically
  • Reviewed files: 101
  • Waived: $25.25 (charged $0.00)
  • View usage details

Note

This review exceeded your plan’s limits and used usage-based reviews—free during trial. After your trial, your Enterprise plan’s existing billing terms apply. Manage usage-based reviews.


Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (1)
posthog/csp_middleware.py-313-313 (1)

313-313: 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick win

Security Misconfiguration

Reachability: External
CWE: CWE-693

Obtain team-security approval before merging this CSP change. posthog/csp_middleware.py is owned by @PostHog/team-security, and the change adds 'self' to the app frame-ancestors policy. No reviews were returned for the four pull requests containing this commit.

Source: Coding guidelines


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 4cbc4c48-ae57-4931-8fce-5285ed7255f6

📥 Commits

Reviewing files that changed from the base of the PR and between 662ed11 and a942587.

⛔ Files ignored due to path filters (8)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
  • products/autoresearch/frontend/generated/api.schemas.ts is excluded by !**/generated/**
  • products/autoresearch/frontend/generated/api.zod.ts is excluded by !**/generated/**
  • products/metrics/frontend/generated/api.schemas.ts is excluded by !**/generated/**
  • products/metrics/frontend/generated/api.ts is excluded by !**/generated/**
  • products/metrics/frontend/generated/api.zod.ts is excluded by !**/generated/**
  • services/mcp/src/generated/autoresearch/api.ts is excluded by !**/generated/**
  • services/mcp/src/tools/generated/autoresearch.ts is excluded by !**/generated/**
📒 Files selected for processing (118)
  • .github/workflows/container-images-cd.yml
  • docs/internal/ai-observability-judge-inputs.md
  • ee/hogai/utils/asgi.py
  • ee/hogai/utils/test/test_asgi.py
  • frontend/src/layout/navigation-3000/Navigation.tsx
  • frontend/src/layout/navigation-3000/navigationLogic.tsx
  • frontend/src/layout/today/TodaySpaceActions.tsx
  • frontend/src/layout/today/TodaySpacesSidebar.tsx
  • frontend/src/layout/today/todaySpacesLogic.ts
  • frontend/src/lib/constants.tsx
  • frontend/src/lib/utils/embeddedPageFrame.ts
  • frontend/src/loadPostHogJS.tsx
  • frontend/src/productScenes.tsx
  • frontend/src/products.tsx
  • frontend/src/scenes/AuthenticatedShell.tsx
  • frontend/src/scenes/project-homepage/today/Today.stories.tsx
  • frontend/src/scenes/project-homepage/today/TodayHomeSidebar.tsx
  • frontend/src/scenes/sceneTypes.ts
  • playwright/e2e/data-quality-overview.spec.ts
  • posthog/api/streaming.py
  • posthog/api/test/test_streaming.py
  • posthog/csp_middleware.py
  • posthog/hogql/constants.py
  • posthog/hogql/database/schema/metrics.py
  • posthog/models/oauth.py
  • posthog/temporal/ai_observability/evaluation_llm_judge.py
  • posthog/temporal/ai_observability/run_tagger.py
  • posthog/temporal/ai_observability/test_run_evaluation.py
  • posthog/temporal/ai_observability/test_run_tagger.py
  • posthog/temporal/common/posthog_client.py
  • posthog/temporal/oauth.py
  • posthog/test/test_csp_middleware.py
  • products/ai_observability/backend/api/proxy.py
  • products/ai_observability/backend/api/test/test_proxy.py
  • products/ai_observability/backend/llm/errors.py
  • products/ai_observability/backend/llm/providers/_diagnostics.py
  • products/ai_observability/backend/llm/providers/azure_openai.py
  • products/ai_observability/backend/llm/providers/openai.py
  • products/ai_observability/backend/llm/providers/openai_compatible.py
  • products/ai_observability/backend/llm/providers/test/test_azure_openai.py
  • products/ai_observability/backend/llm/providers/test/test_openai_compatible.py
  • products/ai_observability/backend/llm/system_one.py
  • products/autoresearch/backend/access.py
  • products/autoresearch/backend/facade/api.py
  • products/autoresearch/backend/facade/contracts.py
  • products/autoresearch/backend/inference/scoring.py
  • products/autoresearch/backend/inference/test_inference.py
  • products/autoresearch/backend/presentation/views/serializers.py
  • products/autoresearch/backend/presentation/views/views.py
  • products/autoresearch/backend/training/AGENTS.md
  • products/autoresearch/backend/training/promotion.py
  • products/autoresearch/backend/training/runner.py
  • products/autoresearch/backend/training/test_promotion.py
  • products/autoresearch/backend/training/test_training.py
  • products/autoresearch/mcp/tools.yaml
  • products/data_warehouse/frontend/scenes/DataOpsScene/DataWarehouseScene.tsx
  • products/data_warehouse/frontend/scenes/DataOpsScene/dataWarehouseSceneLogic.ts
  • products/metrics/backend/diagnostics.py
  • products/metrics/backend/facade/api.py
  • products/metrics/backend/facade/contracts.py
  • products/metrics/backend/fundamentals.py
  • products/metrics/backend/metrics_overview_query_runner.py
  • products/metrics/backend/presentation/api.py
  • products/metrics/backend/tests/conftest.py
  • products/metrics/backend/tests/test_api.py
  • products/metrics/backend/tests/test_diagnostics.py
  • products/metrics/backend/tests/test_fundamentals.py
  • products/metrics/backend/tests/test_metrics_overview_query_runner.py
  • products/metrics/frontend/MetricsScene.tsx
  • products/metrics/frontend/components/MetricsClauseRow.tsx
  • products/metrics/frontend/components/MetricsFundamentals.tsx
  • products/metrics/frontend/components/metricsFundamentalsLogic.test.ts
  • products/metrics/frontend/components/metricsFundamentalsLogic.tsx
  • products/metrics/frontend/components/metricsHandoff.test.ts
  • products/metrics/frontend/components/metricsOverviewLogic.test.ts
  • products/metrics/frontend/metricsSceneLogic.tsx
  • products/metrics/mcp/tools.yaml
  • products/posthog_ai/frontend/components/composer/ComposerModelEffortPickers.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/TaskRunArtifacts.stories.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactCommentActions.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactCommentThreadCard.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactCommentsMenu.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactCommentsPanel.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactImagePins.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactInlineThread.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactObjectEmbed.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactTextAnnotations.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/components/TaskRunArtifacts.tsx
  • products/posthog_ai/frontend/scenes/TaskTracker/taskArtifactCommentsLogic.ts
  • products/posthog_ai/frontend/scenes/TaskTracker/taskRunArtifacts.ts
  • products/streamlit_apps/backend/logic/oauth.py
  • products/tasks/frontend/spaces/NewSessionScene.tsx
  • products/tasks/frontend/spaces/NewSessionSpaceSelect.tsx
  • products/tasks/frontend/spaces/SpaceScene.tsx
  • products/tasks/frontend/spaces/SpaceTaskComposer.tsx
  • products/tasks/frontend/spaces/SpaceTaskComposerSkeleton.tsx
  • products/tasks/frontend/spaces/newSessionSceneLogic.test.ts
  • products/tasks/frontend/spaces/newSessionSceneLogic.ts
  • products/tasks/frontend/spaces/spaceSceneLogic.test.ts
  • products/tasks/frontend/spaces/spaceSceneLogic.ts
  • products/tasks/manifest.tsx
  • products/tasks/package.json
  • products/warehouse_sources/backend/temporal/data_imports/sources/SOURCES.md
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/aws_inspector.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/canonical_descriptions.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/settings.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/source.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/tests/test_aws_inspector.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/generated_configs/awsinspector.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/meta_ads/meta_ads.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/meta_ads/source.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/meta_ads/test_meta_ads.py
  • services/mcp/schema/generated-tool-definitions.json
  • services/mcp/schema/tool-definitions-all.json
  • services/mcp/src/api/generated.ts
  • services/mcp/src/tools/links/app-url-manifest.json
  • services/mcp/tests/unit/__snapshots__/tool-schemas/generate-app-url.json
  • tach.toml
💤 Files with no reviewable changes (17)
  • products/metrics/mcp/tools.yaml
  • frontend/src/lib/constants.tsx
  • products/metrics/frontend/components/metricsOverviewLogic.test.ts
  • products/metrics/frontend/components/MetricsFundamentals.tsx
  • products/metrics/backend/tests/test_diagnostics.py
  • products/metrics/backend/tests/test_fundamentals.py
  • products/posthog_ai/frontend/scenes/TaskTracker/components/ArtifactCommentsPanel.tsx
  • products/metrics/backend/diagnostics.py
  • products/metrics/backend/facade/api.py
  • products/metrics/frontend/components/metricsFundamentalsLogic.tsx
  • products/data_warehouse/frontend/scenes/DataOpsScene/dataWarehouseSceneLogic.ts
  • products/metrics/frontend/components/metricsFundamentalsLogic.test.ts
  • products/metrics/backend/fundamentals.py
  • products/metrics/backend/presentation/api.py
  • products/metrics/backend/tests/test_api.py
  • products/data_warehouse/frontend/scenes/DataOpsScene/DataWarehouseScene.tsx
  • products/metrics/backend/facade/contracts.py

Limit details: You’ve used all 12 included reviews currently available.

Comment on lines +198 to +211
try:
client.request(endpoint, payload)
except AwsInspectorError as error:
if error.code.startswith("AccessDenied") or error.code == "HTTP 403":
if schema_name is None:
return True, None
return False, f"Grant inspector2:{endpoint.operation} to read this table."
message = error_message(error)
if message:
return False, message
raise
finally:
client.close()
return True, None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🔎 Supported by static analysis

🏁 Script executed:

#!/bin/bash
rg -nP -C4 '\bvalidate_credentials\s*\(' products/warehouse_sources/backend --type=py -g '!**/aws_inspector/**' | head -80

Repository: PostHog/posthog

Length of output: 11226


🏁 Script executed:

#!/bin/bash
set -e
printf '%s\n' '--- target file ---'
sed -n '1,270p' products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/aws_inspector.py
printf '%s\n' '--- AWS Inspector files and bindings ---'
rg -n -C5 'aws_inspector|AwsInspector|validate_credentials' products/warehouse_sources/backend/temporal/data_imports products/warehouse_sources/backend/presentation/views/external_data_source/source_setup.py products/warehouse_sources/backend/presentation/views/external_data_schema.py --glob '*.py' | head -260
printf '%s\n' '--- create validation context ---'
sed -n '2240,2310p' products/warehouse_sources/backend/presentation/views/external_data_source/source_setup.py
printf '%s\n' '--- schema validation context ---'
sed -n '2220,2270p' products/warehouse_sources/backend/presentation/views/external_data_schema.py

Repository: PostHog/posthog

Length of output: 42131


🏁 Script executed:

#!/bin/bash
set -e
printf '%s\n' '--- AWS Inspector files ---'
find products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector -maxdepth 2 -type f -name '*.py' -print
printf '%s\n' '--- AWS Inspector source adapter ---'
sed -n '1,260p' products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/source.py
printf '%s\n' '--- AWS Inspector settings ---'
sed -n '1,260p' products/warehouse_sources/backend/temporal/data_imports/sources/aws_inspector/settings.py
printf '%s\n' '--- create schema setup references ---'
rg -n -C5 'setup_permissions|source_schemas|ExternalDataSchema|create.*schema|schemas' products/warehouse_sources/backend/presentation/views/external_data_source/source_setup.py | sed -n '1,260p'

Repository: PostHog/posthog

Length of output: 24322


🏁 Script executed:

#!/bin/bash
set -e
sed -n '1880,2090p' products/warehouse_sources/backend/presentation/views/external_data_source/source_setup.py
printf '%s\n' '--- source schema helpers ---'
rg -n -C5 'def build_default_schemas|lists_tables_without_credentials|setup_permissions' products/warehouse_sources/backend/temporal/data_imports products/warehouse_sources/backend/facade products/warehouse_sources/backend/presentation --glob '*.py' | head -220

Repository: PostHog/posthog

Length of output: 39938


🏁 Script executed:

#!/bin/bash
set -e
rg -n -C8 'def get_endpoint_permissions|get_endpoint_permissions\(' products/warehouse_sources/backend/temporal/data_imports products/warehouse_sources/backend/presentation/views/external_data_source/source_setup.py --glob '*.py'
printf '%s\n' '--- lower-level create entry ---'
rg -n -C8 'def create\(|def _create_external_data_source|skip_credential_validation' products/warehouse_sources/backend/presentation/views/external_data_source/source_setup.py | head -220

Repository: PostHog/posthog

Length of output: 45659


🏁 Script executed:

#!/bin/bash
set -e
printf '%s\n' '--- base permission method ---'
rg -n -C12 'def get_endpoint_permissions' products/warehouse_sources/backend/temporal/data_imports/sources/common/base.py
printf '%s\n' '--- schema builder ---'
rg -n -C15 'def build_default_schemas' products/warehouse_sources/backend/temporal/data_imports/sources/common products/warehouse_sources/backend/facade --glob '*.py'

Repository: PostHog/posthog

Length of output: 6163


Probe each AWS Inspector table during setup.

AwsInspectorSource inherits the default get_endpoint_permissions, which marks every endpoint as reachable without making an API call. The setup flow then enables those schemas. The initial validator probes only findings and treats an unscoped access denial as success. A source can therefore be created with enabled tables that later fail with AccessDenied.

Suggested fix
 class AwsInspectorSource(ResumableSource[AwsInspectorSourceConfig, AwsInspectorResumeConfig]):
     lists_tables_without_credentials = True
     supported_versions = (INSPECTOR_API_VERSION,)
     default_version = INSPECTOR_API_VERSION
     api_docs_url = "https://docs.aws.amazon.com/inspector/v2/APIReference/Welcome.html"

+    def get_endpoint_permissions(
+        self,
+        config: AwsInspectorSourceConfig,
+        team_id: int,
+        endpoints: list[str],
+        api_version: str | None = None,
+    ) -> dict[str, str | None]:
+        return {
+            endpoint: self.validate_credentials(config, team_id, endpoint, api_version=api_version)[1]
+            for endpoint in endpoints
+        }
+

@trunk-io trunk-io Bot closed this Oct 2, 2026
@trunk-io
trunk-io Bot deleted the trunk-merge/pr-110601/6846e8ee-5b94-4e59-86e7-c1faa79c6449 branch October 2, 2026 16:00
@trunk-io

trunk-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Author

Static Badge   Static Badge   Static Badge

Failed Test Failure Summary Logs
Scenes/Code review Default play-test A logic access error occurred because 'actions' on 'scenes.userLogic' was not mounted, likely due to missing logic connection or incorrect componen... Logs ↗︎
Scenes-App/Notebooks/Nodes/Support Tickets WithTickets smoke-test The test timed out while waiting for the element with class 'LemonTable' to become visible. Logs ↗︎
compareTopLevelSections() reports a modifiers change when the current query overrides the team default A TypeError occurred because the code attempted to access the 'add' property of an undefined object. Logs ↗︎
test_time_range_bounds_results An assertion failed because the expected count was 4, but the actual count was 3. Logs ↗︎

View Full Report ↗︎ ⋅ Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants