Skip to content

feat: restrict account_id in GET /api/chats to ORG/RECOUP keys - #171

Merged
sweetmantech merged 2 commits into
testfrom
sweetmantech/myc-4062-api-apichat-account_id-only-for-org-recoup-keys-same-as
Jan 29, 2026
Merged

feat: restrict account_id in GET /api/chats to ORG/RECOUP keys#171
sweetmantech merged 2 commits into
testfrom
sweetmantech/myc-4062-api-apichat-account_id-only-for-org-recoup-keys-same-as

Conversation

@sweetmantech

Copy link
Copy Markdown
Contributor

Summary

  • Makes account_id query parameter optional in GET /api/chats (previously required)
  • Personal API keys can no longer specify account_id - returns 403 error
  • Org keys can filter by account_id only for accounts that are members of their organization
  • Recoup admin keys can filter by any account_id
  • Without account_id parameter:
    • Personal keys: Returns only their own chats
    • Org keys: Returns all org member chats
    • Recoup admin: Returns all chats

This matches the authorization pattern used in /api/pulses.

Test plan

  • Verify personal API key returns only their own chats without account_id param
  • Verify personal API key gets 403 when trying to filter by account_id
  • Verify org API key returns all org member chats without account_id param
  • Verify org API key can filter by account_id for org members
  • Verify org API key gets 403 when filtering by non-member account_id
  • Verify Recoup admin key returns all chats without account_id param
  • Verify Recoup admin key can filter by any account_id

🤖 Generated with Claude Code

@vercel

vercelBot commented Jan 29, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentReviewUpdated (UTC)
recoup-apiReadyReadyPreviewJan 29, 2026 3:36pm

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jan 29, 2026

Copy link
Copy Markdown

Braintrust eval report

Catalog Opportunity Analysis Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
Catalog_availability12.3% (+11pp)2 🟢-
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration38.99s (-3.09s)3 🟢2 🔴

Catalog Songs Count Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
AnswerCorrectness19% (0pp)1 🟢2 🔴
Factuality33.3% (-33pp)1 🟢2 🔴
Llm_calls4 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Completion_accepted_prediction_tokens0tok (+0tok)--
Completion_rejected_prediction_tokens0tok (+0tok)--
Completion_audio_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration17.55s (+4.06s)1 🟢2 🔴

First Week Album Sales Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
Factuality25% (-15pp)-2 🔴
Llm_calls1 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Completion_accepted_prediction_tokens0tok (+0tok)--
Completion_rejected_prediction_tokens0tok (+0tok)--
Completion_audio_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration16.24s (-0.71s)3 🟢1 🔴

Memory & Storage Tools Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration15.62s (-6.61s)1 🟢-

Monthly Listeners Tracking Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
AnswerSimilarity76.6% (-2pp)1 🟢4 🔴
Llm_calls2 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration15.46s (+2.18s)1 🟢4 🔴

Search Web Tool Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
AnswerCorrectness27.7% (+0pp)6 🟢5 🔴
Llm_calls3 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Completion_accepted_prediction_tokens0tok (+0tok)--
Completion_rejected_prediction_tokens0tok (+0tok)--
Completion_audio_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration30.1s (+3.99s)4 🟢7 🔴

Social Scraping Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration24.67s (+1.66s)1 🟢5 🔴

Spotify Followers Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
AnswerCorrectness20.6% (+0pp)4 🟢1 🔴
Llm_calls3 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Completion_accepted_prediction_tokens0tok (+0tok)--
Completion_rejected_prediction_tokens0tok (+0tok)--
Completion_audio_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration14.77s (-1.68s)4 🟢1 🔴

Spotify Tools Evaluation (HEAD-1769700933)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration36.56s (+6.11s)-2 🔴

TikTok Analytics Questions Evaluation (HEAD-1769700932)

ScoreAverageImprovementsRegressions
Question_answered0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration13.67s (-8.19s)2 🟢-

- Make account_id query parameter optional in /api/chats
- Personal API keys can no longer specify account_id (403 error)
- Org keys can only filter by account_id for org members
- Recoup admin keys can filter by any account_id
- Personal keys: Returns only their own chats
- Org keys: Returns all org member chats
- Recoup admin: Returns all chats
Uses snake_case naming (account_id, artist_id, org_id) to match API docs.
This matches the authorization pattern used in /api/pulses.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@sweetmantech
sweetmantechforce-pushed the sweetmantech/myc-4062-api-apichat-account_id-only-for-org-recoup-keys-same-as branch from f9c6484 to 995e218CompareJanuary 29, 2026 15:18
The rooms table has no FK from account_id to accounts, so the join
approach was silently returning empty results. Changed to fetch org
member account IDs via getAccountOrganizations first, then filter rooms.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@sweetmantech
sweetmantech merged commit f9e8900 into testJan 29, 2026
5 checks passed
@sweetmantech
sweetmantech deleted the sweetmantech/myc-4062-api-apichat-account_id-only-for-org-recoup-keys-same-as branch January 29, 2026 15:42
@sweetmantechsweetmantech mentioned this pull request Jan 29, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@sweetmantech