Repository navigation
🐛 Fix(evaluation): surface run delete errors and hide the delete button for unauthorized users - #4042
Merged
Merged
Conversation
cj2026-bit
requested review from
Dallas98,
WMC001,
YehongPan,
hhhhsc701 and
jeffwu-1999
as code owners
September 29, 2026 13:20
jeffwu-1999
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
fetch(DELETE /api/agent-evaluations/{id})and then removed the row from the table without ever looking at the response.fetchonly rejects on network errors, so every HTTP failure was treated as success. For a non-creator DEV user the backend answers 403160208("Only the creator or a tenant administrator can delete this evaluation run"): the row vanished with no message, the run stayed in the database and "came back" after a refresh — a silent false success.SU/ADMIN/SPEED/ASSET_OWNER) to delete a run.Fix
Run delete (root cause)
getI18nErrorMessagemaps the backend codes (160208,000501; the zh/enerrorCode.*translations already exist) — and keep the row; remove it from the table only on success.Button visibility
run.created_by === user.idor the role is inSU/ADMIN/SPEED/ASSET_OWNER(mirrors the backendCAN_EDIT_ALL_USER_ROLESinconsts/const.py). The list API already returnscreated_byand the auth context providesuser.id/user.role, so no backend change was needed. While the user context is still loading the button stays hidden (fail-safe).Evaluator delete / publish
agentEvaluation.publishFailed(zh/en); every other message reuses existing keys and existingerrorCode.*translations.Scope
Verification
Local full-mode stack, frontend and backend both started from this branch:
created_by, so the creator check works on real data.000501, the toast "资源不存在" appears and the row is kept. Before the fix this exact flow removed the row silently.160208.tsc --noEmit: no new errors (the twovitest.config.tsoverload errors also exist on the develop base); pre-commit hooks pass.