From cf28b5694d59d8181148419d25bf90069ab4d2c0 Mon Sep 17 00:00:00 2001 From: TyperBody Date: Sat, 26 Sep 2026 02:33:45 +0800 Subject: [PATCH] fix(operation-trace): default tracing to off Tracing is now opt-in: a Workspace records nothing until an owner or admin explicitly turns it on, so auditing stays off the hot path by default. View and configure remain limited to owners and admins: the audit.view permission is granted to those roles only, non-owner/admin callers receive a 403 from the governance write route, and the panel already gates both on the owner/admin membership role. --- src/langbot/pkg/api/http/service/settings.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/langbot/pkg/api/http/service/settings.py b/src/langbot/pkg/api/http/service/settings.py index 114abc64b..6b56c9820 100644 --- a/src/langbot/pkg/api/http/service/settings.py +++ b/src/langbot/pkg/api/http/service/settings.py @@ -54,7 +54,10 @@ OPERATION_RETENTION_DAYS_KEY = 'operation_log_retention_days' OPERATION_MAX_ROWS_KEY = 'operation_log_max_rows' OPERATION_DEDUPE_WINDOW_KEY = 'operation_log_dedupe_seconds' -DEFAULT_OPERATION_LEVEL = OPERATION_LEVEL_READ +#: Tracing is opt-in: a Workspace records nothing until an owner or admin +#: explicitly turns it on. This keeps auditing off the hot path by default and +#: avoids collecting administrative activity before the operator asked for it. +DEFAULT_OPERATION_LEVEL = OPERATION_LEVEL_NONE DEFAULT_RETENTION_DAYS = 30 DEFAULT_MAX_ROWS = 20000