Phase 2: Visibility Filter & Owner ID
Check Cross-Plugin Imports / check (push) Has been cancelled

- Add OwnedMixin to 15 models (contact_folder, user_preference, workspace,
  mcp_server_config, agent_definition, automation_definition, report_template,
  report_instance, entity_link, comm_conversation, proactive_suggestion,
  ai_agent, ai_chat_session, tag, share_link)
- Migration 0102: Add owner_id column to 15 tables with backfill from user_id
- Fix EntityPermission Registry: remove notification, add entity_attachment,
  entity_history, subtask, calendar, folder; fix wrong class names
  (DmsFile→File, CalendarEvent→CalendarEntry, Mailbox→MailAccount)
- Add apply_visibility_filter to list endpoints in tags, tasks, mcp_client,
  automation, report_generator, ai_assistant routes
- Add owner_id to create handlers for all new OwnedMixin models
- Patch tasks/services.py and automation/services.py list methods with
  user_id and is_system_admin parameters
This commit is contained in:
Agent Zero
2026-08-04 00:03:29 +02:00
parent 93a330ae40
commit e17b9c9e56
29 changed files with 391 additions and 36 deletions
@@ -11,6 +11,7 @@ from datetime import UTC, datetime
from typing import Any
from sqlalchemy import func, select, text, update
from app.core.visibility import apply_visibility_filter
from sqlalchemy.ext.asyncio import AsyncSession
from app.plugins.builtins.automation.models import (
@@ -40,9 +41,15 @@ class AgentService:
mode: str | None = None,
limit: int = 50,
offset: int = 0,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> tuple[list[AgentDefinition], int]:
"""List agent definitions with optional filters."""
query = select(AgentDefinition).where(AgentDefinition.tenant_id == tenant_id)
if user_id and not is_system_admin:
query = await apply_visibility_filter(
db, query, "agent_definition", AgentDefinition, user_id, tenant_id, is_system_admin
)
count_query = select(func.count()).select_from(AgentDefinition).where(
AgentDefinition.tenant_id == tenant_id
)
@@ -108,6 +115,7 @@ class AgentService:
max_duration_seconds=data.get("max_duration_seconds", 300),
budget_limit_usd=data.get("budget_limit_usd", 1.0),
created_by=user_id,
owner_id=user_id,
)
db.add(agent)
await db.flush()
@@ -291,11 +299,17 @@ class AutomationService:
is_active: bool | None = None,
limit: int = 50,
offset: int = 0,
user_id: uuid.UUID | None = None,
is_system_admin: bool = False,
) -> tuple[list[AutomationDefinition], int]:
"""List automation definitions with optional filters."""
query = select(AutomationDefinition).where(
AutomationDefinition.tenant_id == tenant_id
)
if user_id and not is_system_admin:
query = await apply_visibility_filter(
db, query, "automation_definition", AutomationDefinition, user_id, tenant_id, is_system_admin
)
count_query = (
select(func.count())
.select_from(AutomationDefinition)
@@ -366,6 +380,7 @@ class AutomationService:
is_active=data.get("is_active", True),
dry_run=data.get("dry_run", False),
created_by=user_id,
owner_id=user_id,
)
db.add(automation)
await db.flush()