What happens
An external Workspace client (a person the agent is shared with, no platform account) opening an agent's page receives other people's runs of that agent: the recent-work read returns every execution except loops, including other users' chat turns, with their run id, trigger, start and end times and duration.
Why
src/backend/client_portal/agent_page.py _recent_work (~L318-368) excludes only _CLIENT_HIDDEN_TRIGGERS = {"loop"} for a client and projects id, status, triggered_by, started_at, completed_at, duration_ms, schedule_name. The message, cost and model are already projected away, but the rows themselves are not scoped to the viewer, so a client learns when and how long other people used the agent.
Repro
- Share an agent with two people; both chat with it.
- As one of them, open the agent in the Workspace and read the agent-page response: the other person's turns are listed with their ids and timings.
(Found in the ent#610 PR A2 review round 2, client walk: 10 of 12 runs listed to the client belonged to another user.)
Fix direction
For a non-platform viewer, scope the rows in SQL to work the viewer can account for — their own turns (source_user_email / source_channel_client = viewer) plus schedule runs — and apply the same scope to the stats band's counts so the two cannot disagree. Keep the platform view unchanged.
Acceptance
What happens
An external Workspace client (a person the agent is shared with, no platform account) opening an agent's page receives other people's runs of that agent: the recent-work read returns every execution except loops, including other users' chat turns, with their run id, trigger, start and end times and duration.
Why
src/backend/client_portal/agent_page.py_recent_work(~L318-368) excludes only_CLIENT_HIDDEN_TRIGGERS = {"loop"}for a client and projectsid,status,triggered_by,started_at,completed_at,duration_ms,schedule_name. The message, cost and model are already projected away, but the rows themselves are not scoped to the viewer, so a client learns when and how long other people used the agent.Repro
(Found in the ent#610 PR A2 review round 2, client walk: 10 of 12 runs listed to the client belonged to another user.)
Fix direction
For a non-platform viewer, scope the rows in SQL to work the viewer can account for — their own turns (
source_user_email/source_channel_client= viewer) plus schedule runs — and apply the same scope to the stats band's counts so the two cannot disagree. Keep the platform view unchanged.Acceptance