[management] Self-scope usage and log reads; give usage_viewer the filter resources

The usage overview and access-log listings no longer deny callers without
the account-wide grant: the filter is pinned to the caller (their own
user id, group filters dropped), so every authenticated user reads their
own usage and requests through the same endpoints the admin dashboard
uses. The dedicated /agent-network/me/usage/overview endpoint is removed
in favor of that fallback.

usage_viewer gains read-only access to the resources the usage view's
filters and columns resolve against: users, groups, peers, and the
provider list (provider and model filter options).
This commit is contained in:
mlsmaycon
2026-08-18 17:20:08 +00:00
parent bd52434e36
commit a3b9853f31
9 changed files with 123 additions and 172 deletions
@@ -24,22 +24,6 @@ func (m *managerImpl) GetSetupForUser(ctx context.Context, accountID, userID str
return m.effectiveSetupForGroups(ctx, accountID, user.AutoGroups)
}
// GetUsageOverviewForUser returns the same aggregated usage buckets the
// admin overview serves, pinned to the caller's own rows: the filter's
// user id is forced to the caller and any group filter is dropped, which
// is tighter than any role gate — so, like GetSetupForUser, no permission
// check. The response shape is identical to GetUsageOverview so the
// dashboard renders both views with the same component.
func (m *managerImpl) GetUsageOverviewForUser(ctx context.Context, accountID, userID string, filter types.AgentNetworkAccessLogFilter, granularity types.UsageGranularity) ([]*types.AgentNetworkUsageBucket, error) {
filter.UserID = &userID
filter.GroupIDs = nil
rows, err := m.store.GetAgentNetworkUsageRows(ctx, store.LockingStrengthNone, accountID, filter)
if err != nil {
return nil, err
}
return types.AggregateUsageByGranularity(rows, granularity), nil
}
// effectiveSetupForGroups computes the effective Agent Network setup for
// a set of caller groups: the account endpoint plus, per authorized
// provider, the effective model set. It mirrors what the proxy enforces
@@ -253,8 +237,3 @@ func declaredModelIDs(provider *types.Provider) []string {
func (*mockManager) GetSetupForUser(_ context.Context, _, _ string) (*types.EffectiveSetup, error) {
return &types.EffectiveSetup{Providers: []types.EffectiveProvider{}}, nil
}
// GetUsageOverviewForUser on the mock manager returns no buckets.
func (*mockManager) GetUsageOverviewForUser(_ context.Context, _, _ string, _ types.AgentNetworkAccessLogFilter, _ types.UsageGranularity) ([]*types.AgentNetworkUsageBucket, error) {
return nil, nil
}