mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-01 11:09:15 +02:00
[management] Let usage_viewer read Agent Network access logs (#7750)
usage_viewer saw account-wide usage but only its own request logs, so the people reviewing cost could not drill into the requests behind it. The role now also holds Read on agent_network.logs, which makes the access-log and session endpoints return every caller's rows instead of self-scoping. Logs can contain captured prompts, so this widens what the role exposes; policies, guardrails, budgets and settings stay hidden. Co-authored-by: Misha Bragin <bangvalo@gmail.com>
This commit is contained in:
co-authored by
Misha Bragin
parent
fd1a0203c7
commit
82e5428c2f
@@ -110,12 +110,12 @@ Two roles delegate Agent Network access without account-admin rights:
|
||||
read-only users, groups, peers, and account info (needed to build policies).
|
||||
Nothing else in the account.
|
||||
- **`usage_viewer`** — the regular User baseline plus read on
|
||||
`agent_network.usage` (the aggregated usage and cost overview) and read-only
|
||||
access to the resources the usage filters resolve against: users, groups,
|
||||
peers, and the provider list (connection config redacted — no upstream URLs
|
||||
or operator-supplied header values). No policies, and no account-wide
|
||||
request-level access logs; like any caller, it still reads its own requests
|
||||
through the self-scoped endpoints below.
|
||||
`agent_network.usage` (the aggregated usage and cost overview) and
|
||||
`agent_network.logs` (the account-wide request-level access logs, which can
|
||||
contain captured prompts), and read-only access to the resources those
|
||||
filters resolve against: users, groups, peers, and the provider list
|
||||
(connection config redacted — no upstream URLs or operator-supplied header
|
||||
values). No policies, guardrails, budgets, or settings.
|
||||
|
||||
Every authenticated user, regardless of role, can read the caller-scoped
|
||||
self-service endpoint `GET /api/agent-network/agent-config` (the endpoint, providers,
|
||||
|
||||
Reference in New Issue
Block a user