fix(ui): stop useCan from fetching the org list for capabilities that don't use it

useCan called useIsOrgAdmin unconditionally, which fires
/organization/list via useOrganizations. That broke UsageTab and
CostOptimizationView tests (they render without a QueryClientProvider,
so the useQuery inside useIsOrgAdmin threw "No QueryClient set") and
also broke Workflows / Memory / Guardrails Monitor integration tests
that assert no fetch fires for a non-admin role.

Only viewDeletedTeams reads the org-admin flag (ORG_ADMIN_CAPABILITIES),
so drop the useIsOrgAdmin call from useCan and OR the org-admin
membership check in at the single caller in view_logs. The org-admin
membership fallback for viewDeletedTeams is preserved.

Co-authored-by: Krrish Dholakia <krrish-berri-2@users.noreply.github.com>
This commit is contained in:
Cursor Agent 2026-08-11 06:23:38 +00:00
parent 1a8cd8a078
commit 714122ec90
No known key found for this signature in database
2 changed files with 3 additions and 4 deletions

View file

@ -3,12 +3,10 @@
import { hasCapability, type Capability } from "@/utils/capabilities";
import useAuthorized from "./useAuthorized";
import useIsOrgAdmin from "./useIsOrgAdmin";
const useCan = (capability: Capability): boolean => {
const { userRole } = useAuthorized();
const isOrgAdmin = useIsOrgAdmin();
return hasCapability(userRole, capability, isOrgAdmin);
return hasCapability(userRole, capability);
};
export default useCan;

View file

@ -1,6 +1,7 @@
import { useState } from "react";
import { Tab, TabGroup, TabList, TabPanel, TabPanels } from "@tremor/react";
import useCan from "@/app/(dashboard)/hooks/useCan";
import useIsOrgAdmin from "@/app/(dashboard)/hooks/useIsOrgAdmin";
import DeletedKeysPage from "../DeletedKeysPage/DeletedKeysPage";
import DeletedTeamsPage from "../DeletedTeamsPage/DeletedTeamsPage";
import AuditLogsPanel from "./AuditLogsPanel";
@ -30,7 +31,7 @@ const DELETED_TEAMS_TAB: LogsTab = { id: "deleted teams", label: "Deleted Teams"
export default function SpendLogsTable({ accessToken, token, userRole, userID, premiumUser }: SpendLogsTableProps) {
const [activeTab, setActiveTab] = useState<LogsTabId>(REQUEST_LOGS_TAB.id);
const canViewAuditLogs = useCan("viewAuditLogs");
const canViewDeletedTeams = useCan("viewDeletedTeams");
const canViewDeletedTeams = useCan("viewDeletedTeams") || useIsOrgAdmin();
if (!accessToken || !token || !userRole || !userID) {
return (