Add public privacy page and usage doc - #593
kentcdodds wants to merge 1 commit into
Conversation
Ship /privacy as an unauthenticated page describing per-account data storage, admin visibility boundaries, and deployment operator caveats per the RBAC proposal. Link from login, signup, and account pages; add docs/use/privacy.md; extend smoke E2E to assert the page renders without authentication.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by #596, which combines the full RBAC stack (proposal, core, admin UI, privacy page, MCP context, and docs) into a single PR targeting main. |
Summary
The privacy page from the RBAC plan (stacked on the proposal PR; implemented by a composer 2.5 subagent, parallel to the core phase — it has no code dependency on the RBAC schema).
/privacypage (server handler + client route) covering: what Kody stores per account, what a deployment admin can see (account metadata only), what an admin can never see (secret values and metadata, tokens, values, memories, packages, jobs, email, chat, storage, connectors, OAuth grants), and the honest operator caveat (infrastructure access sits outside application-level controls).docs/use/privacy.mdwith the same content, linked fromdocs/use/index.md./privacyrenders without authentication.The page describes admin visibility in the present tense for the merged state of the full RBAC stack.
System recap — composes existing primitives (low risk)
Mode: recap · Base:
cursor/rbac-support-plan-66a6· Head:8d631f2Classification: composes — one new static page and docs wired through existing route patterns.
Primitives touched
app-ui/privacyrouteTesting
npm run validate(all six checks green)/privacyreturns 200 unauthenticated and renders (see screenshot; full GUI walkthrough video on the integration PR)