You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
v1 knowledge base list, detail, and update returned docCount/tokenCount over every document in the base, including connector documents the caller cannot read. They now count through the caller's access (resolveV1KnowledgeReadAccess), the same way the v1 documents routes already do. v1 detail also now returns its real connectorTypes
The internal KB list joined document through the full access predicate on every call, but only the Knowledge page shows the totals. The list contract gains includeCounts (default false), and without it the query reads only knowledge_base columns. The service option is countsFor: access, so a count without an access filter can't be written
React Query: counted lists get their own key beside list(), used only by the Knowledge page and its server prefetch. Document, upload, and connector mutations refresh only the counted lists; KB create, rename, delete, restore, and move refresh both
Removed getKnowledgeBaseById, whose unfiltered count join ran on every context resolution. Callers use getActiveKnowledgeBaseReference, and single-base totals come only from attachKnowledgeBaseConnectors(kb, access)
The v2 list keeps returning totals, since its public contract requires them
Type of Change
Bug fix
Testing
New app/api/v1/knowledge/route.integration.ts (real Postgres, only auth mocked): a read-role caller sees docCount: 1 for a base holding one upload plus one admin-only connector document on v1 list and detail. All 3 tests fail on the old code
Search-index policy integration suite and the knowledge service, application, and context unit suites updated and passing
[Medium risk] Refactors knowledge-base document counting to respect access control.
The PR appears safe to merge based on the reviewed changes and current thread states.
Summary
The PR scopes v1 knowledge-base totals to documents the caller can read and makes internal-list totals opt-in, with a separate counted-list cache for the Knowledge page.
Removes unfiltered count reads from base-reference and update paths.
Updates list contracts, prefetching, cache invalidation, and integration coverage.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docCount/tokenCountover every document in the base, including connector documents the caller cannot read. They now count through the caller's access (resolveV1KnowledgeReadAccess), the same way the v1 documents routes already do. v1 detail also now returns its realconnectorTypesdocumentthrough the full access predicate on every call, but only the Knowledge page shows the totals. The list contract gainsincludeCounts(default false), and without it the query reads onlyknowledge_basecolumns. The service option iscountsFor: access, so a count without an access filter can't be writtenlist(), used only by the Knowledge page and its server prefetch. Document, upload, and connector mutations refresh only the counted lists; KB create, rename, delete, restore, and move refresh bothgetKnowledgeBaseById, whose unfiltered count join ran on every context resolution. Callers usegetActiveKnowledgeBaseReference, and single-base totals come only fromattachKnowledgeBaseConnectors(kb, access)Type of Change
Testing
app/api/v1/knowledge/route.integration.ts(real Postgres, only auth mocked): a read-role caller seesdocCount: 1for a base holding one upload plus one admin-only connector document on v1 list and detail. All 3 tests fail on the old codecheck:auditspassChecklist