Skip to content

fix(permissions): isolate seer and event:write scopes - #572

Merged
dcramer merged 1 commit into
mainfrom
fix-seer-perm
Oct 2, 2025
Merged

dcramer merged 1 commit into
mainfrom
fix-seer-perm

Conversation

@dcramer

@dcramer dcramer commented Oct 2, 2025 •

Copy link
Copy Markdown
Member

Fixes permission isolation issues where "Issue Triage" and "Seer" permissions were incorrectly cascading:

  • Updated "Issue Triage" description to remove "analyze" terminology which was confusing with Seer's analysis capabilities
  • Changed analyze_issue_with_seer tool to only require "seer" scope (not event:read), ensuring proper permission isolation

This ensures users must explicitly opt-in to Seer functionality, and having event:write permissions does not automatically grant Seer access.

Fixes permission isolation issues where "Issue Triage" and "Seer"
permissions were incorrectly cascading:

- Updated "Issue Triage" description to remove "analyze" terminology
  which was confusing with Seer's analysis capabilities
- Changed analyze_issue_with_seer tool to only require "seer" scope
  (not event:read), ensuring proper permission isolation
- Verified permission hierarchy maintains isolation: selecting
  "Issue Triage" grants event:write only, "Seer" grants seer only

This ensures users must explicitly opt-in to Seer functionality,
and having event:write permissions does not automatically grant
Seer access.

Co-Authored-By: Claude Code <noreply@anthropic.com>
export default defineTool({
name: "analyze_issue_with_seer",
requiredScopes: ["event:read", "seer"],
requiredScopes: ["seer"],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Missing Scope Causes API Call Failures

The analyze_issue_with_seer tool had event:read removed from its requiredScopes. This will likely cause runtime authorization failures, as the tool still needs to read issue data for API calls like apiService.getAutofixState and apiService.startAutofix.

Fix in Cursor Fix in Web

@dcramer
dcramer merged commit 751ed07 into main Oct 2, 2025
13 checks passed
@dcramer
dcramer deleted the fix-seer-perm branch October 2, 2025 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant