mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
Assistant chats from High Compliance projects now flow to Braintrust like any other project. The constraint that required suppressing them no longer applies, see AI-1241 for the details. `isTracingAllowed` now takes only the project region to maintain EU exclusion. Traces also carry an `isHighComplianceProject` metadata field, so the project's status at the time of the trace is recorded rather than looked up later against a setting customers can toggle. To verify, see [this sample trace](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=afabbdcc-aa89-446e-aa52-78aaa90d44a4&v=Production&s=afabbdcc-aa89-446e-aa52-78aaa90d44a4&tvt=trace) from a High Compliance project on staging which indicates that tracing is now enabled for these projects and that it carries metadata showing the high compliance status. | High Compliance project setting | `isHighComplianceProject` metadata | |--------|--------| | <img width="1554" height="454" alt="CleanShot 2026-09-22 at 5 14 58 PM@2x" src="https://github.com/user-attachments/assets/23901c6e-0d79-44e8-a6dd-43cdedba1799" /> | <img width="1674" height="990" alt="CleanShot 2026-09-22 at 5 17 40 PM@2x" src="https://github.com/user-attachments/assets/fb2fba55-bcc1-4136-a432-b33a5c7f9ca2" /> | Closes AI-1241 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Changes** * AI project compliance information is now represented by a unified high-compliance project status. * AI response tracing is now determined by project region: tracing remains disabled for EU and unknown regions, while known non-EU regions are eligible. * AI feedback and SQL generation now use the updated compliance and regional handling. * **Tests** * Updated coverage to reflect the revised compliance and tracing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
72 lines
2.5 KiB
TypeScript
72 lines
2.5 KiB
TypeScript
import { getProjectSettings } from '@/data/config/project-settings-v2-query'
|
|
import { checkEntitlement } from '@/data/entitlements/entitlements-query'
|
|
import { getOrganizations } from '@/data/organizations/organizations-query'
|
|
import { getProjectDetail } from '@/data/projects/project-detail-query'
|
|
import { getAiOptInLevel, type AiOptInLevel } from '@/hooks/misc/useOrgOptedIntoAi'
|
|
|
|
export type AIDetails = {
|
|
aiOptInLevel: AiOptInLevel
|
|
hasAccessToAdvanceModel: boolean
|
|
orgId: number | undefined
|
|
orgSlug: string | undefined
|
|
planId: string | undefined
|
|
region: string | undefined
|
|
/** "High Compliance" in the dashboard, `is_sensitive` in the platform API. */
|
|
isHighComplianceProject: boolean | undefined
|
|
}
|
|
|
|
// Resolves the AI opt-in level, model access and tracing inputs for one org/project pair.
|
|
// Both identifiers come from the request body, so an unconfirmed pairing resolves to the
|
|
// most restrictive posture rather than the requested one.
|
|
export const getAIDetails = async ({
|
|
orgSlug,
|
|
projectRef,
|
|
authorization,
|
|
}: {
|
|
orgSlug: string
|
|
projectRef: string
|
|
authorization: string
|
|
}): Promise<AIDetails> => {
|
|
const headers = {
|
|
'Content-Type': 'application/json',
|
|
...(authorization && { Authorization: authorization }),
|
|
}
|
|
|
|
const [organizations, advanceModelAccess, project, projectSettings] = await Promise.all([
|
|
getOrganizations({ headers }),
|
|
checkEntitlement(orgSlug, 'assistant.advance_model', undefined, headers),
|
|
// skipWake: only organization_id and region are needed, neither requires a running project
|
|
getProjectDetail({ ref: projectRef, skipWake: true }, undefined, headers),
|
|
getProjectSettings({ projectRef }, undefined, headers),
|
|
])
|
|
|
|
const selectedOrg = organizations.find((org) => org.slug === orgSlug)
|
|
const region = project?.region
|
|
const isHighComplianceProject = projectSettings?.is_sensitive ?? undefined
|
|
|
|
const isProjectInOrg = selectedOrg !== undefined && project?.organization_id === selectedOrg.id
|
|
|
|
if (!isProjectInOrg) {
|
|
return {
|
|
aiOptInLevel: 'disabled',
|
|
hasAccessToAdvanceModel: false,
|
|
orgId: undefined,
|
|
orgSlug: undefined,
|
|
planId: undefined,
|
|
// Undefined rather than the real region so isTracingAllowed fails closed
|
|
region: undefined,
|
|
isHighComplianceProject: undefined,
|
|
}
|
|
}
|
|
|
|
return {
|
|
aiOptInLevel: getAiOptInLevel(selectedOrg.opt_in_tags),
|
|
hasAccessToAdvanceModel: advanceModelAccess.hasAccess,
|
|
orgId: selectedOrg.id,
|
|
orgSlug: selectedOrg.slug,
|
|
planId: selectedOrg.plan.id,
|
|
region,
|
|
isHighComplianceProject,
|
|
}
|
|
}
|