Skip to content

Conversation

@aayush-se
Copy link
Member

  • endpoints to start agent translation and poll the state for frontend

@aayush-se aayush-se requested review from a team as code owners January 14, 2026 22:29
@github-actions github-actions bot added the Scope: Backend Automatically applied to PRs that change backend components label Jan 14, 2026
@github-actions github-actions bot added the Scope: Frontend Automatically applied to PRs that change frontend components label Jan 14, 2026
@github-actions
Copy link
Contributor

🚨 Warning: This pull request contains Frontend and Backend changes!

It's discouraged to make changes to Sentry's Frontend and Backend in a single pull request. The Frontend and Backend are not atomically deployed. If the changes are interdependent of each other, they must be separated into two pull requests and be made forward or backwards compatible, such that the Backend or Frontend can be safely deployed independently.

Have questions? Please ask in the #discuss-dev-infra channel.

return Response(
{"detail": "Invalid run_id"},
status=status.HTTP_400_BAD_REQUEST,
)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing SEER_AUTOFIX_URL configuration check in state endpoint

Medium Severity

The SearchAgentStateEndpoint is missing a check for settings.SEER_AUTOFIX_URL before calling fetch_search_agent_state(). The companion SearchAgentStartEndpoint correctly checks this configuration at line 155, and other similar Seer endpoints follow the same pattern. Without this check, if SEER_AUTOFIX_URL is not configured, the request will fail with a misleading "Failed to fetch run state" error instead of the expected "Seer is not properly configured" message.

Fix in Cursor Fix in Web

},
)
response.raise_for_status()
return response.json()
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

State endpoint missing organization context in Seer request

High Severity

The fetch_search_agent_state function sends only run_id to Seer without including organization_id. The existing similar function fetch_run_status in client_utils.py includes organization_id in its request body to allow Seer to validate organization ownership. Without this, a user from Organization A could potentially poll for the state of a run created by Organization B if they can guess or enumerate run IDs.

Fix in Cursor Fix in Web

@aayush-se
Copy link
Member Author

🚨 Warning: This pull request contains Frontend and Backend changes!

It's discouraged to make changes to Sentry's Frontend and Backend in a single pull request. The Frontend and Backend are not atomically deployed. If the changes are interdependent of each other, they must be separated into two pull requests and be made forward or backwards compatible, such that the Backend or Frontend can be safely deployed independently.

Have questions? Please ask in the #discuss-dev-infra channel.

The frontend changes are due to the Sentry bot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Scope: Backend Automatically applied to PRs that change backend components Scope: Frontend Automatically applied to PRs that change frontend components

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants