Repository navigation
Roles → Person picker: filter to user-kind principals only (CL-6664) - #566
Merged
TheGreatAxios merged 1 commit intoSep 3, 2026
Conversation
Contributor
Author
|
Review — Skywalker (orchestrator) lens · implementation Filters the Roles "Assign a role" picker to user-kind principals only, matching the People section roster. Removes now-unused optgroup structure and PRINCIPAL_KIND imports. Key paths:
Critic review: clean (all findings VERIFIED, zero defects, zero blockers). |
TheGreatAxios
commented
Sep 3, 2026
TheGreatAxios
left a comment
Contributor
Author
There was a problem hiding this comment.
Component-level kind === "user" filter on the Roles picker/table — correctly scoped and tested; no backend or package-move conflicts found.
Must fix
- None.
Consider
- The filter is UI-only:
listPrincipals(tenantId)still fetches the full principal list (including the 49+ duplicate placeholders) over the network before this component discards them client-side. Fine for a legibility fix, but worth confirming there's no perf/payload concern if that list grows further, and that no other consumer oflistPrincipalsin this section relies on seeing agent/workflow entries. identity.ts's comment now describes Grants/Roles pickers separately; double check the Grants picker (grants-section.tsx) intentionally keeps agents/workflows (it does — confirmed viaPRINCIPAL_KIND_ORDER/PRINCIPAL_KIND_LABELstill imported there), just flagging so reviewers don't read the identity.ts comment as implying Grants changed too.
Verified
peoplefilter (principals.filter(p => p.kind === "user")) is applied consistently to both the picker<select>and theassignmentsflatMap, so the table can't show agent/workflow rows either.- Backend role-assignment route is not kind-restricted (by design — Grants still assigns roles to agents/workflows), so this is correctly a UI scoping change, not a broken/bypassable authz control.
- No references to the deleted
hub-clientpackage, and@corbits/error-sink/@corbits/connectionsare unaffected by this diff (settings-ui's existing error-sink dependency is untouched). - All 4 CI jobs relevant to this diff pass (build-test, lint, typecheck, structural); rewritten tests in
roles-section.test.tsxcover user-only filtering, flat-list rendering, and agent exclusion from the assignments table.
TheGreatAxios
force-pushed
the
cl-6664-roles-assign-a-role-person-picker-49-duplicate-placeholder
branch
from
September 3, 2026 02:02
1ea83bc to
2ca3b54
Compare
The "Assign a role" person picker showed all principals — people, agents, and workflows — in one flat list. This surfaced 49+ duplicate placeholder- named service accounts (e.g. "Dana Reyes Gaj0a5c7 Localhost") in the picker, none scoped to the workbench's actual member roster. Fix by filtering principals to kind === "user" in both the picker select and the assignments table, matching the People section's member list. Remove the now-unused optgroup structure and PRINCIPAL_KIND imports. All 4 tests rewritten to verify user-only filtering.
TheGreatAxios
force-pushed
the
cl-6664-roles-assign-a-role-person-picker-49-duplicate-placeholder
branch
from
September 3, 2026 02:12
2ca3b54 to
a5f31ce
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes CL-6664
The "Assign a role" person picker was pulling from the full principals list — people, agents, and workflows — surfacing 49+ duplicate placeholder-named service accounts (e.g. "Dana Reyes Gaj0a5c7 Localhost") indistinguishable from real members.
What changed:
roles-section.tsx: filter principals tokind === "user"only for both the picker and assignments table, replace optgroup with flat<select>identity.ts: updated comment to reflect Roles' picker is user-onlytest/roles-section.test.tsx: 4 rewritten tests covering user-only filter, flat list, agent exclusion from assignments table, and single-kind label artifactWhy component-level filter: The picker already receives the full principals list from the parent. A
kind === "user"filter at the component boundary is the simplest, most localized fix — no backend changes, no new API params. The People section already validates that user-kind principals represent actual workbench members.