Skip to content

Add public privacy page and usage doc - #593

Closed
kentcdodds wants to merge 1 commit into
cursor/rbac-support-plan-66a6from
cursor/rbac-privacy-page-66a6
Closed

kentcdodds wants to merge 1 commit into
cursor/rbac-support-plan-66a6from
cursor/rbac-privacy-page-66a6

Conversation

@kentcdodds

Copy link
Copy Markdown
Owner

Summary

The privacy page from the RBAC plan (stacked on the proposal PR; implemented by a composer 2.5 subagent, parallel to the core phase — it has no code dependency on the RBAC schema).

  • Public, unauthenticated /privacy page (server handler + client route) covering: what Kody stores per account, what a deployment admin can see (account metadata only), what an admin can never see (secret values and metadata, tokens, values, memories, packages, jobs, email, chat, storage, connectors, OAuth grants), and the honest operator caveat (infrastructure access sits outside application-level controls).
  • Footer-style links from the login, signup, and account pages.
  • docs/use/privacy.md with the same content, linked from docs/use/index.md.
  • Playwright E2E assertion that /privacy renders without authentication.

The page describes admin visibility in the present tense for the merged state of the full RBAC stack.

Privacy page

System recap — composes existing primitives (low risk)

Mode: recap · Base: cursor/rbac-support-plan-66a6 · Head: 8d631f2

Classification: composes — one new static page and docs wired through existing route patterns.

Primitives touched

Primitive Group Impact
app-ui surfaces composes — new public /privacy route

Testing

  • ✅ npm run validate (all six checks green)
  • ✅ Manually verified /privacy returns 200 unauthenticated and renders (see screenshot; full GUI walkthrough video on the integration PR)
Open in Web Open in Cursor 

Ship /privacy as an unauthenticated page describing per-account data storage,
admin visibility boundaries, and deployment operator caveats per the RBAC
proposal. Link from login, signup, and account pages; add docs/use/privacy.md;
extend smoke E2E to assert the page renders without authentication.
@coderabbitai

coderabbitai Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 803ad348-86d7-43c7-91e3-33d11b8637bd

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/rbac-privacy-page-66a6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kody-bot
kody-bot marked this pull request as ready for review July 3, 2026 05:23
@kody-bot

kody-bot commented Jul 3, 2026

Copy link
Copy Markdown
Collaborator

Superseded by #596, which combines the full RBAC stack (proposal, core, admin UI, privacy page, MCP context, and docs) into a single PR targeting main.

@kody-bot kody-bot closed this Jul 3, 2026
@kody-bot
kody-bot deleted the cursor/rbac-privacy-page-66a6 branch July 21, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants