mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
Assistant chats from High Compliance projects now flow to Braintrust like any other project. The constraint that required suppressing them no longer applies, see AI-1241 for the details. `isTracingAllowed` now takes only the project region to maintain EU exclusion. Traces also carry an `isHighComplianceProject` metadata field, so the project's status at the time of the trace is recorded rather than looked up later against a setting customers can toggle. To verify, see [this sample trace](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=afabbdcc-aa89-446e-aa52-78aaa90d44a4&v=Production&s=afabbdcc-aa89-446e-aa52-78aaa90d44a4&tvt=trace) from a High Compliance project on staging which indicates that tracing is now enabled for these projects and that it carries metadata showing the high compliance status. | High Compliance project setting | `isHighComplianceProject` metadata | |--------|--------| | <img width="1554" height="454" alt="CleanShot 2026-09-22 at 5 14 58 PM@2x" src="https://github.com/user-attachments/assets/23901c6e-0d79-44e8-a6dd-43cdedba1799" /> | <img width="1674" height="990" alt="CleanShot 2026-09-22 at 5 17 40 PM@2x" src="https://github.com/user-attachments/assets/fb2fba55-bcc1-4136-a432-b33a5c7f9ca2" /> | Closes AI-1241 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Changes** * AI project compliance information is now represented by a unified high-compliance project status. * AI response tracing is now determined by project region: tracing remains disabled for EU and unknown regions, while known non-EU regions are eligible. * AI feedback and SQL generation now use the updated compliance and regional handling. * **Tests** * Updated coverage to reflect the revised compliance and tracing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
226 lines
7.0 KiB
TypeScript
226 lines
7.0 KiB
TypeScript
import { beforeEach, describe, expect, it, vi } from 'vitest'
|
|
|
|
import { getAIDetails } from './ai-details'
|
|
|
|
vi.mock('@/data/organizations/organizations-query', () => ({
|
|
getOrganizations: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('@/data/projects/project-detail-query', () => ({
|
|
getProjectDetail: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('@/data/config/project-settings-v2-query', () => ({
|
|
getProjectSettings: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('@/hooks/misc/useOrgOptedIntoAi', () => ({
|
|
getAiOptInLevel: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('@/data/entitlements/entitlements-query', () => ({
|
|
checkEntitlement: vi.fn(),
|
|
}))
|
|
|
|
const AUTH = 'Bearer token'
|
|
const HEADERS = { 'Content-Type': 'application/json', Authorization: AUTH }
|
|
const ORG_SLUG = 'test-org'
|
|
const PROJECT_REF = 'test-project'
|
|
|
|
describe('getAIDetails', () => {
|
|
let mockGetOrganizations: ReturnType<typeof vi.fn>
|
|
let mockGetProjectDetail: ReturnType<typeof vi.fn>
|
|
let mockGetProjectSettings: ReturnType<typeof vi.fn>
|
|
let mockGetAiOptInLevel: ReturnType<typeof vi.fn>
|
|
let mockCheckEntitlement: ReturnType<typeof vi.fn>
|
|
|
|
beforeEach(async () => {
|
|
const orgsQuery = await import('@/data/organizations/organizations-query')
|
|
const projectQuery = await import('@/data/projects/project-detail-query')
|
|
const settingsQuery = await import('@/data/config/project-settings-v2-query')
|
|
const aiHook = await import('@/hooks/misc/useOrgOptedIntoAi')
|
|
const entitlementsQuery = await import('@/data/entitlements/entitlements-query')
|
|
|
|
mockGetOrganizations = vi.mocked(orgsQuery.getOrganizations)
|
|
mockGetProjectDetail = vi.mocked(projectQuery.getProjectDetail)
|
|
mockGetProjectSettings = vi.mocked(settingsQuery.getProjectSettings)
|
|
mockGetAiOptInLevel = vi.mocked(aiHook.getAiOptInLevel)
|
|
mockCheckEntitlement = vi.mocked(entitlementsQuery.checkEntitlement)
|
|
|
|
mockGetOrganizations.mockResolvedValue([
|
|
{ id: 1, slug: ORG_SLUG, plan: { id: 'pro' }, opt_in_tags: [] },
|
|
])
|
|
mockGetProjectDetail.mockResolvedValue({
|
|
ref: PROJECT_REF,
|
|
region: 'us-east-1',
|
|
organization_id: 1,
|
|
})
|
|
mockGetProjectSettings.mockResolvedValue({ is_sensitive: false })
|
|
mockCheckEntitlement.mockResolvedValue({ hasAccess: false })
|
|
mockGetAiOptInLevel.mockReturnValue('schema')
|
|
})
|
|
|
|
it('returns the resolved posture when the project belongs to the org', async () => {
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result).toEqual({
|
|
aiOptInLevel: 'schema',
|
|
hasAccessToAdvanceModel: false,
|
|
orgId: 1,
|
|
orgSlug: ORG_SLUG,
|
|
planId: 'pro',
|
|
region: 'us-east-1',
|
|
isHighComplianceProject: false,
|
|
})
|
|
})
|
|
|
|
it('flags a High Compliance project', async () => {
|
|
mockGetProjectSettings.mockResolvedValue({ is_sensitive: true })
|
|
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.isHighComplianceProject).toBe(true)
|
|
})
|
|
|
|
it('calls getAiOptInLevel with the matched org opt_in_tags', async () => {
|
|
const opt_in_tags = ['AI_SQL_GENERATOR_OPT_IN']
|
|
mockGetOrganizations.mockResolvedValue([
|
|
{ id: 1, slug: ORG_SLUG, plan: { id: 'pro' }, opt_in_tags },
|
|
])
|
|
|
|
await getAIDetails({ orgSlug: ORG_SLUG, projectRef: PROJECT_REF, authorization: AUTH })
|
|
|
|
expect(mockGetAiOptInLevel).toHaveBeenCalledWith(opt_in_tags)
|
|
})
|
|
|
|
it('returns hasAccessToAdvanceModel true when the entitlement grants access', async () => {
|
|
mockCheckEntitlement.mockResolvedValue({ hasAccess: true })
|
|
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.hasAccessToAdvanceModel).toBe(true)
|
|
})
|
|
|
|
it('finds the correct org when multiple orgs are returned', async () => {
|
|
mockGetOrganizations.mockResolvedValue([
|
|
{ id: 1, slug: 'org-1', plan: { id: 'free' }, opt_in_tags: [] },
|
|
{ id: 2, slug: ORG_SLUG, plan: { id: 'pro' }, opt_in_tags: [] },
|
|
])
|
|
mockGetProjectDetail.mockResolvedValue({
|
|
ref: PROJECT_REF,
|
|
region: 'us-east-1',
|
|
organization_id: 2,
|
|
})
|
|
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.orgId).toBe(2)
|
|
expect(result.planId).toBe('pro')
|
|
})
|
|
|
|
it('forwards authorization headers to all fetches', async () => {
|
|
await getAIDetails({ orgSlug: ORG_SLUG, projectRef: PROJECT_REF, authorization: AUTH })
|
|
|
|
expect(mockGetOrganizations).toHaveBeenCalledWith({ headers: HEADERS })
|
|
expect(mockCheckEntitlement).toHaveBeenCalledWith(
|
|
ORG_SLUG,
|
|
'assistant.advance_model',
|
|
undefined,
|
|
HEADERS
|
|
)
|
|
expect(mockGetProjectDetail).toHaveBeenCalledWith(
|
|
{ ref: PROJECT_REF, skipWake: true },
|
|
undefined,
|
|
HEADERS
|
|
)
|
|
expect(mockGetProjectSettings).toHaveBeenCalledWith(
|
|
{ projectRef: PROJECT_REF },
|
|
undefined,
|
|
HEADERS
|
|
)
|
|
})
|
|
|
|
describe('when the project does not belong to the org', () => {
|
|
beforeEach(() => {
|
|
mockGetOrganizations.mockResolvedValue([
|
|
{ id: 1, slug: ORG_SLUG, plan: { id: 'pro' }, opt_in_tags: ['AI_SQL_GENERATOR_OPT_IN'] },
|
|
{ id: 2, slug: 'other-org', plan: { id: 'free' }, opt_in_tags: [] },
|
|
])
|
|
mockGetProjectDetail.mockResolvedValue({
|
|
ref: PROJECT_REF,
|
|
region: 'us-east-1',
|
|
organization_id: 2,
|
|
})
|
|
mockGetAiOptInLevel.mockReturnValue('schema_and_log_and_data')
|
|
mockCheckEntitlement.mockResolvedValue({ hasAccess: true })
|
|
})
|
|
|
|
it('falls back to the most restrictive posture', async () => {
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.aiOptInLevel).toBe('disabled')
|
|
expect(result.hasAccessToAdvanceModel).toBe(false)
|
|
expect(result.orgId).toBeUndefined()
|
|
expect(result.orgSlug).toBeUndefined()
|
|
expect(result.planId).toBeUndefined()
|
|
})
|
|
|
|
it('leaves the region undefined so tracing checks fail closed', async () => {
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.region).toBeUndefined()
|
|
})
|
|
})
|
|
|
|
it('falls back to the most restrictive posture when the org slug matches no org', async () => {
|
|
mockGetOrganizations.mockResolvedValue([])
|
|
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.aiOptInLevel).toBe('disabled')
|
|
expect(result.orgId).toBeUndefined()
|
|
expect(result.orgSlug).toBeUndefined()
|
|
})
|
|
|
|
it('falls back to the most restrictive posture when project detail is unavailable', async () => {
|
|
mockGetProjectDetail.mockResolvedValue(undefined)
|
|
|
|
const result = await getAIDetails({
|
|
orgSlug: ORG_SLUG,
|
|
projectRef: PROJECT_REF,
|
|
authorization: AUTH,
|
|
})
|
|
|
|
expect(result.aiOptInLevel).toBe('disabled')
|
|
expect(result.region).toBeUndefined()
|
|
})
|
|
})
|