Skip to content

feat(flags): warn when SQL reads $feature_flag_called from events - #114059

Merged
trunk-io[bot] merged 10 commits into
masterfrom
haacked/flag-called-sql-warning
Oct 9, 2026
Merged

trunk-io[bot] merged 10 commits into
masterfrom
haacked/flag-called-sql-warning

Conversation

@haacked

@haacked haacked commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Problem

  • A SQL editor user who queries $feature_flag_called from events gets no sign that the query will stop returning those rows.
  • The event is moving to posthog.flag_evaluations. Once an organization reaches flag_evaluations_mode 2, ingestion stops writing it to events.

Part of #88126.

Changes

  • The SQL editor marks '$feature_flag_called' with a warning when a query compares it to the events table's event column.
  • The warning reads: "$feature_flag_called is moving from events to posthog.flag_evaluations. Once the move finishes for your organization, this query will stop returning these events and you can query posthog.flag_evaluations instead."
  • The flag-called-move-notices feature flag gates the warning. The flag stays off until the customer announcement about the move goes out.
  • Once the flag is on, every organization gets the warning, including those that can't query posthog.flag_evaluations yet. The copy describes the move in the future tense for that reason.
  • HogQL metadata resolves a copy of the user's query, the same way index eligibility does, so the warning sits on the literal the user typed.
  • The flag and the check run only when the query text contains $feature_flag_called.
  • A failure in the flag evaluation or the check is logged and never marks the query invalid.
  • A saved view's body and a saved expression's body get no warning. The resolver inlines both from their own text, so their offsets don't point into the user's query.

Note

Users on the hogql-language-service flag don't see the warning yet. The Go language service answers their editor metadata, and this check runs only in Python. Adding it there is a follow-up, and that follow-up checks the same flag-called-move-notices flag.

A stacked follow-up adds a "Learn more" link to the announcement from the flag's payload. That PR adds a field to HogQLNotice, so it gets its own review.

Not detected: a value supplied by a query variable, equals(event, …) written as a function call, and an event column read through a subquery or CTE.

No screenshot: the warning uses the editor's existing warning marker.

How did you test this code?

Test rationale: test_metadata_warns_for_flag_called_read_from_events is parameterized and asserts the exact span of each warning.

  • It warns for =, IN, posthog.events, a table alias, a column alias, and an organization that can't see posthog.flag_evaluations.
  • It does not warn for posthog.flag_evaluations, a saved view's body, a saved expression's body, a property named event, or a literal not compared to event.
  • It does not warn when the flag-called-move-notices flag is off.

Checked by hand in a local SQL editor: the literal gets the warning marker, and the hover shows the warning.

👉 Stay up-to-date with PostHog coding conventions for a smoother review.

Release status

  • This change is behind a feature flag and is not available to users

The flag-called-move-notices flag stays off until the customer announcement about the $feature_flag_called move goes out.

Docs update

None.

🤖 Agent context

Autonomy: Human-driven (agent-assisted)

Agent: Claude Code, Opus 5.5 (claude-opus-5-5)

  • Skills: /writing-tests, /writing-user-facing-copy, /writing-code-comments, /writing-pr-descriptions, /reviewing-with-coderabbit, /address-pr-reviews, /run-posthog.
  • A code review pass found two bugs, and both are fixed with tests. A saved view's body put warnings at offsets from the view's own SQL. A precached AST from a debug run logged a stack trace.
  • CodeRabbit CLI ran with --deep and reported one finding: a precached compilation suppresses the warning. Rejected. Only debug query execution passes a precached AST, its AST may already be rewritten, and the editor never takes that path.
  • ReviewHog found two more issues, and both are fixed. A saved expression's body put warnings at offsets from its own text, and a new test case covers it. The finder followed resolved field types into shared CTE types, which took exponential time on chained CTEs. No test covers that one.

https://claude.ai/code/session_01XWFfg4SwPhiAnWJq7zBjsq
https://claude.ai/code/session_0182H46NbivitrX4jyFFg61N

HogQL metadata adds a warning on each $feature_flag_called literal that a
query compares to the events table's event column. The warning names
posthog.flag_evaluations. Queries on posthog.flag_evaluations, and literals
that are not compared to the event column, get no warning.

Claude-Session: https://claude.ai/code/session_012rGhDjtKCS47JbyFu5gMQz
@trunk-io

trunk-io Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

😎 Stack merged successfully - details.

@haacked haacked self-assigned this Oct 8, 2026
@haacked haacked added the reviewhog ($$$) Reviews pull requests before humans do label Oct 8, 2026
@haacked
haacked requested a balanced review from Copilot October 8, 2026 16:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@posthog

posthog Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🦔 PostHog Review reviewed this pull request

Found 0 must fix, 1 should fix, 1 consider.

Published 2 findings (view the review).

Not resolving comments: this pull request is submitted to the merge queue

A fix commit would change what was submitted, or remove it from the queue, so the open threads stay with you.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Trunk lane — backend Python lane

This PR is assigned to the backend Python lane. It runs backend Python tests and may merge in parallel with PRs in other lanes.

⚠️ Complexity (TypeScript) — 1 function above the limit (max 11)

Cyclomatic complexity above the limit in changed typescript files (10 for production files, 15 for test files). Warn only: worth simplifying when you next touch these functions.

Function Location Complexity Limit
<anonymous> frontend/src/lib/monaco/codeEditorLogic.tsx:301 11 10
✅ Duplication (Python) — clean

New Python code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

✅ Duplication (TypeScript) — clean

New TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

🚨 Comment density — 7% of added code lines are comments (12 of 179)

This section warns when comments are more than 3% of the code lines a PR adds, and alerts above 6%. Before agent-assisted PRs, the typical share was about 2%. Only full-line comments count. Docstrings, generated files, snapshots, migrations, and workflow files are left out.

Comments that restate the code, record how the change came about, or narrate the next line add noise for the next reader. Keep the comments that explain a reason the code cannot show, and remove the rest. See .agents/skills/writing-code-comments/SKILL.md for the house rules.

Files with the most added comment lines:

File Comment lines Added lines
posthog/hogql/flag_called_warnings.py 10 79
posthog/hogql/metadata.py 2 29

This check does not block merging. It updates on every push and clears when the share drops.

⚠️ Bundle size — 🔺 +62.6 KiB (+0.1%)

Uncompressed size of every built .js bundle, compared against the base branch.

Total: 76.78 MiB · 🔺 +62.6 KiB (+0.1%)

File Size Δ vs base
render-query/src/render-query/render-query.js 25.68 MiB 🔺 +35.2 KiB (+0.1%)
posthog-app/_parent/products/workflows/frontend/WorkflowsScene.js 48.5 KiB 🔺 +19.7 KiB (+68.3%)
posthog-app/_parent/products/replay_vision/frontend/replay_scanners/ReplayScannersScene.js 86.2 KiB 🟢 -17.5 KiB (-16.8%)
posthog-app/_parent/products/alerts_platform/frontend/PlatformAlertScene.js 8.7 KiB 🔺 +8.7 KiB (new)
posthog-app/_parent/products/metrics/frontend/MetricsScene.js 25.0 KiB 🟢 -6.6 KiB (-21.0%)
posthog-app/_parent/products/alerts_platform/frontend/PlatformAlertsScene.js 6.4 KiB 🔺 +6.4 KiB (new)
posthog-app/_parent/products/autoresearch/frontend/AutoresearchPipelineScene.js 70.1 KiB 🔺 +4.3 KiB (+6.6%)
posthog-app/src/scenes/experiments/Experiment.js 311.5 KiB 🔺 +3.3 KiB (+1.1%)
posthog-app/src/scenes/data-pipelines/batch-exports/BatchExportScene.js 79.4 KiB 🔺 +2.8 KiB (+3.6%)
posthog-app/_parent/products/tasks/frontend/spaces/NewSessionScene.js 7.7 KiB 🟢 -1.9 KiB (-19.5%)
posthog-app/_parent/products/autoresearch/frontend/AutoresearchScene.js 18.4 KiB 🟢 -1.6 KiB (-7.9%)
posthog-app/_parent/products/signals/frontend/inbox/InboxScene.js 447.7 KiB 🔺 +1.4 KiB (+0.3%)
toolbar/src/toolbar/debug/chunk-EventDebugMenu.js 302.8 KiB 🔺 +1.2 KiB (+0.4%)

Posted automatically by build-bundle-size-report · uncompressed bytes from dist-report

✅ Eager graph — within budget

How much code each root ships on the eager path — downloaded and parsed before the surface is interactive. Measured from the esbuild output chunks (post-tree-shake, static imports only); lazy import() / React.lazy chunks are not counted.

Root Eager (shipped) Δ vs base Budget
entry (logged-out pages, app bootstrap)
src/index.tsx
1.65 MiB · 23 files 🔺 +1.3 KiB (+0.1%) █████████░ 89.9% of 1.84 MiB
logged-out boot: index + App + bootApp (preloaded by every page, including /login)
src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
3.80 MiB · 675 files 🔺 +2.4 KiB (+0.1%) █████████░ 94.3% of 4.03 MiB
authenticated shell (every logged-in page)
src/scenes/AuthenticatedShell.tsx
7.74 MiB · 2,458 files 🔺 +6.4 KiB (+0.1%) █████████░ 92.9% of 8.34 MiB
dashboard scene
src/scenes/dashboard/Dashboard.tsx
9.98 MiB · 3,540 files 🔺 +13.0 KiB (+0.1%) █████████░ 91.4% of 10.92 MiB
today home path
src/scenes/AuthenticatedShell.tsx + src/scenes/project-homepage/ProjectHomepage.tsx + src/scenes/project-homepage/today/TodayHome.tsx
7.76 MiB · 2,468 files 🔺 +6.4 KiB (+0.1%) █████████░ 90.4% of 8.58 MiB
events scene
src/scenes/activity/explore/EventsScene.tsx
9.60 MiB · 3,391 files 🔺 +12.6 KiB (+0.1%) █████████░ 91.3% of 10.51 MiB
replay detail scene
src/scenes/session-recordings/detail/SessionRecordingDetail.tsx
12.30 MiB · 4,187 files 🔺 +7.5 KiB (+0.1%) ████████░░ 78.2% of 15.72 MiB

🟢 node_modules/monaco-editor/ stays out of src/index.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/index.tsx
🟢 node_modules/@posthog/brand/dist/generated/hoggies/svg/ stays out of src/index.tsx
🟢 node_modules/@posthog/brand/dist/generated/hoggies/components/ stays out of src/index.tsx
🟢 node_modules/monaco-editor/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/layout/navigation-3000/navigationLogic.tsx stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/scenes/dashboard/dashboardLogic.tsx stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/lib/lemon-ui/LemonMarkdown/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/lib/components/RichContentEditor/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/lib/components/CodeSnippet/ stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 src/taxonomy/core-filter-definitions-by-group.json stays out of src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
🟢 node_modules/monaco-editor/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/lib/components/ActivityLog/describers stays out of src/scenes/AuthenticatedShell.tsx
🟢 products/dashboards/frontend/widgets/previews/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/scenes/session-recordings/player/sessionRecordingPlayerLogic.ts stays out of src/scenes/AuthenticatedShell.tsx
🟢 zod/v4/locales/de.js stays out of src/scenes/AuthenticatedShell.tsx
🟢 node_modules/@posthog/brand/dist/generated/hoggies/svg/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 node_modules/@posthog/brand/dist/generated/hoggies/components/ stays out of src/scenes/AuthenticatedShell.tsx
🟢 src/scenes/session-recordings/playlist/SessionRecordingsPlaylist.tsx stays out of src/scenes/dashboard/Dashboard.tsx
🟢 src/scenes/web-analytics/tiles/WebAnalyticsTile.tsx stays out of src/scenes/dashboard/Dashboard.tsx
🟢 src/scenes/project-homepage/ai-first/AiFirstHomepage.tsx stays out of src/scenes/AuthenticatedShell.tsx + src/scenes/project-homepage/ProjectHomepage.tsx + src/scenes/project-homepage/today/TodayHome.tsx
🟢 src/scenes/project-homepage/today/TodayReportPage.tsx stays out of src/scenes/AuthenticatedShell.tsx + src/scenes/project-homepage/ProjectHomepage.tsx + src/scenes/project-homepage/today/TodayHome.tsx
🟢 src/queries/Query/Query.tsx stays out of src/scenes/AuthenticatedShell.tsx + src/scenes/project-homepage/ProjectHomepage.tsx + src/scenes/project-homepage/today/TodayHome.tsx
🟢 src/scenes/session-recordings/playlist/SessionRecordingsPlaylist.tsx stays out of src/scenes/activity/explore/EventsScene.tsx
🟢 src/scenes/web-analytics/tiles/WebAnalyticsTile.tsx stays out of src/scenes/activity/explore/EventsScene.tsx

Largest files eagerly shipped from src/index.tsx
Size File
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
24.6 KiB ../node_modules/.pnpm/buffer@6.0.3/node_modules/buffer/index.js
6.3 KiB ../node_modules/.pnpm/react@18.3.1/node_modules/react/cjs/react.production.min.js
4.5 KiB ../node_modules/.pnpm/@jspm+core@2.1.0/node_modules/@jspm/core/nodelibs/browser/process.js
3.9 KiB ../node_modules/.pnpm/scheduler@0.23.2/node_modules/scheduler/cjs/scheduler.production.min.js
1.4 KiB ../node_modules/.pnpm/base64-js@1.5.1/node_modules/base64-js/index.js
1.3 KiB src/index.tsx
1.3 KiB src/RootErrorBoundary.tsx
912 B ../node_modules/.pnpm/ieee754@1.2.1/node_modules/ieee754/index.js
839 B src/scenes/ChunkLoadErrorBoundary.tsx
Largest files eagerly shipped from src/index.tsx + src/scenes/App.tsx + src/scenes/bootApp.ts
Size File
316.7 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
220.8 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
99.8 KiB src/lib/api.ts
93.1 KiB src/products.tsx
69.0 KiB src/lib/lemon-ui/icons/icons.tsx
40.7 KiB src/lib/utils/eventUsageLogic.ts
38.7 KiB ../node_modules/.pnpm/@dnd-kit+core@6.0.8_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@dnd-kit/core/dist/core.esm.js
33.9 KiB ../node_modules/.pnpm/kea@4.0.0-pre.6_patch_hash=139b8d1f1304f9d9da452a9a1244c94ea679dbcb85687d8999563146879fb6f5_react@18.3.1/node_modules/kea/lib/index.cjs.js
29.0 KiB ../node_modules/.pnpm/zod@4.3.6/node_modules/zod/v4/core/schemas.js
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx
Size File
316.7 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
280.8 KiB src/taxonomy/core-filter-definitions-by-group.json
220.8 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
153.7 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
112.1 KiB ../packages/quill/packages/quill/dist/index.js
99.8 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
93.1 KiB src/products.tsx
90.6 KiB ../node_modules/.pnpm/@tiptap+core@3.20.6_@tiptap+pm@3.20.6/node_modules/@tiptap/core/dist/index.js
Largest files eagerly shipped from src/scenes/dashboard/Dashboard.tsx
Size File
316.7 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
280.8 KiB src/taxonomy/core-filter-definitions-by-group.json
220.8 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
181.9 KiB src/queries/validators.js
153.7 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
112.1 KiB ../packages/quill/packages/quill/dist/index.js
99.8 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
93.1 KiB src/products.tsx
Largest files eagerly shipped from src/scenes/AuthenticatedShell.tsx + src/scenes/project-homepage/ProjectHomepage.tsx + src/scenes/project-homepage/today/TodayHome.tsx
Size File
316.7 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
280.8 KiB src/taxonomy/core-filter-definitions-by-group.json
220.8 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
153.7 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
112.1 KiB ../packages/quill/packages/quill/dist/index.js
99.8 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
93.1 KiB src/products.tsx
90.6 KiB ../node_modules/.pnpm/@tiptap+core@3.20.6_@tiptap+pm@3.20.6/node_modules/@tiptap/core/dist/index.js
Largest files eagerly shipped from src/scenes/activity/explore/EventsScene.tsx
Size File
316.7 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
280.8 KiB src/taxonomy/core-filter-definitions-by-group.json
220.8 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
181.9 KiB src/queries/validators.js
153.7 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
112.1 KiB ../packages/quill/packages/quill/dist/index.js
99.8 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js
93.1 KiB src/products.tsx
Largest files eagerly shipped from src/scenes/session-recordings/detail/SessionRecordingDetail.tsx
Size File
316.7 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/module.mjs
316.0 KiB ../node_modules/.pnpm/posthog-js@1.438.1_@types+react@18.3.27_react@18.3.1/node_modules/posthog-js/dist/rrweb.js
280.8 KiB src/taxonomy/core-filter-definitions-by-group.json
220.8 KiB ../node_modules/.pnpm/@posthog+icons@0.38.0_react-dom@18.3.1_react@18.3.1__react@18.3.1/node_modules/@posthog/icons/dist/posthog-icons.es.js
181.9 KiB src/queries/validators.js
153.7 KiB ../node_modules/.pnpm/re2js@0.4.1/node_modules/re2js/build/index.esm.js
126.8 KiB ../node_modules/.pnpm/react-dom@18.3.1_react@18.3.1/node_modules/react-dom/cjs/react-dom.production.min.js
112.1 KiB ../packages/quill/packages/quill/dist/index.js
99.8 KiB src/lib/api.ts
93.3 KiB ../node_modules/.pnpm/prosemirror-view@1.40.1/node_modules/prosemirror-view/dist/index.js

Posted automatically by check-eager-graph · sizes are eager output bytes (shipped, post-tree-shake) from the esbuild metafile · part of #32479

✅ Toolbar bundle — eager 2.24 MiB within budget

What the toolbar ships to customer pages, measured from the esbuild output (minified, post-tree-shake). The eager set is the entry plus everything statically imported from it — fetched before any feature runs; deferred chunks load lazily. The eager guardrail is 5.72 MiB. Each output file must also stay below 10 MB, where CloudFront stops compressing it. The module boundary is enforced separately by check-toolbar-graph.

Metric Size Δ vs base Budget
Eager (shipped)
entry + static imports
2.24 MiB · 19 files 🔺 +1.9 KiB (+0.1%) ████░░░░░░ 39.1% of 5.72 MiB
Deferred (lazy) 2.19 MiB · 44 files 🔺 +1.2 KiB (+0.1%) n/a — loads on demand
Loader dist/toolbar.js 1.2 KiB no change █░░░░░░░░░ 6.0% of 19.5 KiB
Largest eagerly-shipped chunks
Size File
861.5 KiB dist/toolbar/toolbar-app-QGEQZP2M.css
669.8 KiB dist/toolbar/chunk-chunk-CBU6SMOV.js
259.5 KiB dist/toolbar/chunk-chunk-2SI7EDOJ.js
138.2 KiB dist/toolbar/chunk-chunk-4Q4LESTO.js
131.8 KiB dist/toolbar/chunk-chunk-FDH2IBXT.js
75.2 KiB dist/toolbar/toolbar-app-EGSYMIYI.js
69.0 KiB dist/toolbar/chunk-chunk-TSAL54PB.js
35.6 KiB dist/toolbar/chunk-chunk-T6Z6U46Q.js
21.7 KiB dist/toolbar/chunk-chunk-WGMP64BC.js
6.8 KiB dist/toolbar/chunk-chunk-DV7IWQNF.js

Posted automatically by check-toolbar-size · sizes are toolbar output bytes (shipped, post-tree-shake) from the esbuild metafile

✅ Dist folder size — 🔺 +1.52 MiB (+0.2%)

Total size of the built frontend/dist folder (all assets), compared against the base branch.

Total: 1010.62 MiB · 🔺 +1.52 MiB (+0.2%)

ℹ️ MCP UI apps size — 32 app(s), 17208.5 KB JS

Built size of each MCP UI app (main.js + styles.css).

App JS CSS
debug 597.9 KB 203.4 KB
action 454.2 KB 203.4 KB
action-list 564.3 KB 203.4 KB
cohort 453.2 KB 203.4 KB
cohort-list 563.3 KB 203.4 KB
email-template 453.0 KB 203.4 KB
error-details 469.7 KB 203.4 KB
error-issue 454.6 KB 203.4 KB
error-issue-list 564.9 KB 203.4 KB
experiment 561.4 KB 203.4 KB
experiment-list 565.0 KB 203.4 KB
experiment-results 566.4 KB 203.4 KB
feature-flag 566.9 KB 203.4 KB
feature-flag-list 570.6 KB 203.4 KB
feature-flag-testing 457.4 KB 203.4 KB
inline-scan 453.7 KB 203.4 KB
insight-actors 562.4 KB 203.4 KB
llm-costs 559.4 KB 203.4 KB
session-recording 455.4 KB 203.4 KB
survey 454.8 KB 203.4 KB
survey-global-stats 562.0 KB 203.4 KB
survey-list 565.0 KB 203.4 KB
survey-stats 562.0 KB 203.4 KB
trace-span 453.6 KB 203.4 KB
trace-span-list 564.2 KB 203.4 KB
vision-observation-list 563.4 KB 203.4 KB
workflow 453.5 KB 203.4 KB
workflow-list 563.6 KB 203.4 KB
loops-review 457.9 KB 203.4 KB
query-results 786.9 KB 203.4 KB
render-ui 870.2 KB 203.4 KB
visual-review-snapshots 458.0 KB 203.4 KB
✅ Playwright — all passed

All tests passed.

View test results →

⚠️ Backend snapshots — 12 updated (12 modified, 0 added, 0 deleted)

Query snapshots: Backend query snapshots updated

Changes: 12 snapshots (12 modified, 0 added, 0 deleted)

What this means:

  • Query snapshots have been automatically updated to match current output
  • These changes reflect modifications to database queries or schema

Next steps:

  • Review the query changes to ensure they're intentional
  • If unexpected, investigate what caused the query to change

Review snapshot changes →

⚠️ Backend coverage — 95.0% of changed backend lines covered — 5 uncovered

🧪 Backend test coverage

Patch coverage — changed backend lines (products + core): ███████████████████░ 95.0% (97 / 102)

File Patch Uncovered changed lines
posthog/hogql/metadata.py 88.9% 334, 337–338
posthog/hogql/flag_called_warnings.py 96.4% 73, 86

🤖 Agents: add a test only if an uncovered line exposes a realistic regression that existing tests miss. Otherwise explain why no new test is needed under "How did you test this code?". Gap list: the patch-coverage artifact on this run (gh run download 253197284140945 -n patch-coverage), or the coverage-data block at the end of this comment.

Per-product line coverage (touched products)
Product Coverage Lines
platform_features ██░░░░░░░░░░░░░░░░░░ 12.1% 7 / 58
demo ███████████░░░░░░░░░ 55.9% 1,510 / 2,700
data_tools ████████████░░░░░░░░ 61.2% 90 / 147
warehouse_sources_queue █████████████░░░░░░░ 66.9% 1,915 / 2,862
aeo ███████████████░░░░░ 76.3% 617 / 809
batch_exports ████████████████░░░░ 80.1% 21,344 / 26,648
apm █████████████████░░░ 84.1% 1,306 / 1,553
engineering_analytics █████████████████░░░ 85.3% 10,670 / 12,514
mcp_analytics █████████████████░░░ 85.7% 4,844 / 5,651
ml_inference █████████████████░░░ 86.3% 524 / 607
warehouse_suggestions █████████████████░░░ 87.1% 2,192 / 2,518
posthog_ai ██████████████████░░ 87.7% 4,226 / 4,817
cdp ██████████████████░░ 88.0% 4,656 / 5,290
notebooks ██████████████████░░ 88.4% 15,201 / 17,196
today ██████████████████░░ 88.6% 2,866 / 3,233
mcp_registry ██████████████████░░ 89.0% 1,596 / 1,794
product_tours ██████████████████░░ 89.1% 1,337 / 1,500
signals ██████████████████░░ 89.5% 66,012 / 73,747
dashboards ██████████████████░░ 89.5% 6,957 / 7,769
webmcp ██████████████████░░ 89.6% 240 / 268
cohorts ██████████████████░░ 89.6% 8,458 / 9,438
data_modeling ██████████████████░░ 90.1% 10,831 / 12,021
ai_training ██████████████████░░ 90.4% 349 / 386
tasks ██████████████████░░ 90.5% 80,660 / 89,086
visual_review ██████████████████░░ 90.7% 9,842 / 10,856
data_warehouse ██████████████████░░ 90.7% 14,656 / 16,155
canvas ██████████████████░░ 90.9% 7,760 / 8,535
exports ██████████████████░░ 91.0% 9,698 / 10,663
business_knowledge ██████████████████░░ 91.0% 8,613 / 9,468
autoresearch ██████████████████░░ 91.2% 10,009 / 10,971
managed_warehouse ██████████████████░░ 91.2% 11,053 / 12,114
error_tracking ██████████████████░░ 91.6% 16,797 / 18,328
wizard ██████████████████░░ 91.8% 6,008 / 6,548
streamlit_apps ██████████████████░░ 91.8% 3,087 / 3,362
stamphog ██████████████████░░ 92.0% 8,242 / 8,963
conversations ██████████████████░░ 92.1% 29,145 / 31,640
managed_migrations ██████████████████░░ 92.5% 1,600 / 1,730
early_access_features ███████████████████░ 92.6% 1,339 / 1,446
alerts ███████████████████░ 92.8% 7,126 / 7,683
web_analytics ███████████████████░ 93.1% 23,971 / 25,751
surveys ███████████████████░ 93.1% 6,626 / 7,118
notifications ███████████████████░ 93.2% 1,152 / 1,236
approvals ███████████████████░ 93.3% 4,323 / 4,633
cross_project_dashboards ███████████████████░ 93.4% 880 / 942
review_hog ███████████████████░ 93.4% 13,200 / 14,129
slack_app ███████████████████░ 93.5% 14,869 / 15,897
context_layer ███████████████████░ 93.7% 3,409 / 3,640
marketing_analytics ███████████████████░ 93.8% 19,836 / 21,158
workflows ███████████████████░ 93.8% 16,372 / 17,460
billing_alerts ███████████████████░ 93.9% 2,090 / 2,226
customer_analytics ███████████████████░ 93.9% 26,079 / 27,773
mcp_store ███████████████████░ 93.9% 9,008 / 9,593
experiments ███████████████████░ 94.2% 33,527 / 35,603
ai_observability ███████████████████░ 94.2% 26,434 / 28,069
replay_vision ███████████████████░ 94.3% 28,956 / 30,711
legal_documents ███████████████████░ 94.3% 2,289 / 2,427
logs ███████████████████░ 94.4% 15,782 / 16,710
actions ███████████████████░ 94.6% 973 / 1,029
endpoints ███████████████████░ 94.8% 9,298 / 9,812
reminders ███████████████████░ 94.8% 760 / 802
growth ███████████████████░ 94.8% 11,268 / 11,880
skills ███████████████████░ 94.9% 7,024 / 7,403
annotations ███████████████████░ 95.0% 816 / 859
tracing ███████████████████░ 95.2% 3,617 / 3,801
data_catalog ███████████████████░ 95.5% 4,420 / 4,628
access_control ███████████████████░ 95.6% 7,693 / 8,048
alerts_platform ███████████████████░ 95.7% 4,639 / 4,848
product_analytics ███████████████████░ 95.7% 28,602 / 29,879
messaging ███████████████████░ 95.8% 3,833 / 4,003
revenue_analytics ███████████████████░ 95.9% 1,878 / 1,959
data_quality ███████████████████░ 95.9% 8,569 / 8,933
feature_flags ███████████████████░ 96.2% 27,109 / 28,175
warehouse_sources ███████████████████░ 96.4% 451,071 / 467,965
security ███████████████████░ 96.7% 1,452 / 1,501
pulse ███████████████████░ 97.4% 2,023 / 2,078
metrics ████████████████████ 97.8% 3,980 / 4,068
analytics_platform ████████████████████ 98.0% 2,775 / 2,833
field_notes ████████████████████ 99.4% 172 / 173

Report-only. Patch coverage = changed backend lines covered vs origin/master. Sorted lowest first.
Known gaps: lines covered only by Temporal tests show as uncovered; core line numbers may drift if master changed the same file.

✅ Hogbox preview — ready, open the preview

▶ Open the preview

🔑 Login test@posthog.com / 12345678 (demo data)
🧩 Running this PR's backend and frontend, on the PostHog :master base
🔗 Link stable across rebuilds: a re-push swaps the box underneath, the URL stays
🔒 Access tailnet only (PostHog VPN)
🛠️ Admin inspect & debug state in hogland
💤 Idle sleeps after ~30 min idle (snapshot to S3, zero node cost) and wakes on your next visit in ~30s, behind a brief "waking up" screen

commit 36b59a5 · box box-9303a201e092 · ready in 1199s (push → usable) · build log · rebuilds on every push, torn down on close

@haacked
haacked marked this pull request as ready for review October 8, 2026 16:32
@haacked
haacked requested a review from a team as a code owner October 8, 2026 16:32
@haacked haacked added the stamphog Request AI approval (no full review) label Oct 8, 2026
@parameterai

parameterai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Risk: No findings

This increment removes the announcement "Learn more" link from the flag-called SQL warning: the url field is dropped from HogQLNotice, the payload-based URL validation is deleted, and the flag-called-move-notices gate now uses the standard feature_enabled_or_false helper, evaluated inside the advisory try block. The removal eliminates the only link-rendering surface the PR had (Monaco handling of a flag-payload URL), and no new security-relevant surface is introduced.

Sentinel reviewed 36b59a5 · Review settings

@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested a review from a team October 8, 2026 16:33
stamphog[bot]

This comment was marked as outdated.

@posthog

posthog Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

PostHog Review alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏

Comment thread posthog/hogql/flag_called_warnings.py
Comment thread posthog/hogql/flag_called_warnings.py
@posthog posthog Bot removed the reviewhog ($$$) Reviews pull requests before humans do label Oct 8, 2026
@trunk-io

trunk-io Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Static Badge   Static Badge   Static Badge

View Full Report ↗︎ ⋅ Docs

@haacked
haacked marked this pull request as draft October 8, 2026 16:56
… warning

- posthog/hogql/flag_called_warnings.py: the finder skips hidden aliases, so a saved expression body no longer yields a warning at offsets from its own text
- posthog/hogql/flag_called_warnings.py: the finder stops at each field instead of following its type into shared CTE types

Claude-Session: https://claude.ai/code/session_0182H46NbivitrX4jyFFg61N
@stamphog
stamphog Bot dismissed their stale review October 8, 2026 17:08

New commits were pushed — dismissing the stamphog approval from an earlier head. This PR no longer qualifies for automatic review.

…yload

- posthog/hogql/metadata.py: reads the https URL in the flag-called-move-notices payload and evaluates the flag inside the advisory try block
- posthog/hogql/flag_called_warnings.py: puts that URL on each warning
- frontend/src/queries/schema/schema-general.ts: HogQLNotice has an optional url
- frontend/src/lib/monaco/codeEditorLogic.tsx: a notice with a url shows a "Learn more" link in its hover

Claude-Session: https://claude.ai/code/session_0182H46NbivitrX4jyFFg61N
@posthog

posthog Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🕓 This approval covered an earlier revision. There are new visual changes to review in the newer comment below.

✅ Visual changes approved by @haacked — baseline updated in ac75cf4.

View this run in PostHog

2 changed.

Install the Visual Review Chrome extension to see visual review results at the top of your pull requests.

2 updated
Run: 4b37d9d6-60d5-433e-99aa-126993b62a18

Co-authored-by: haacked <19977+haacked@users.noreply.github.com>
@haacked
haacked marked this pull request as ready for review October 8, 2026 21:03

@stamphog stamphog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not approved — escalated to a human reviewer.

Re-add the stamphog label to request another review once you have addressed this.

The API contract and editor-link changes need independent assurance; the supplied reviews are on older commits, and MODERATE familiarity does not supply that assurance. Request a current-head review from @PostHog/team-data-tools covering the response field and URL handling before re-requesting.

  • Author wrote 0% of the modified lines and has 67 merged PRs in these paths (familiarity MODERATE).
  • Risky territory without independent assurance: Public API contracts — posthog/schema.py adds an optional URL to HogQLNotice responses, with corresponding frontend and generated API schemas.; Auth or security-sensitive surface — frontend/src/lib/monaco/codeEditorLogic.tsx turns notice URLs into clickable editor links; posthog/hogql/metadata.py validates the new payload URL as HTTPS with a host before returning it.
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✓ no deny categories matched
size ✓ 171L, 6F substantive, 286L/11F incl. docs/generated/snapshots — within ceiling
tier ✓ T1-agent / T1d-complex (286L, 11F, cross-cutting, feat)
stamphog 2.4.1 .stamphog/policy.yml @ ac75cf4 · reviewed head ac75cf4

@posthog

posthog Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Visual changes approved by @haacked — baseline updated in 9dede36.

View this run in PostHog

2 changed.

Install the Visual Review Chrome extension to see visual review results at the top of your pull requests.

2 updated
Run: 1fb99b25-788e-4b23-8156-30f65fdaf7ff

Co-authored-by: haacked <19977+haacked@users.noreply.github.com>
@haacked haacked added the stamphog Request AI approval (no full review) label Oct 8, 2026
@stamphog stamphog Bot removed the stamphog Request AI approval (no full review) label Oct 8, 2026

@stamphog stamphog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not approved — escalated to a human reviewer.

Re-add the stamphog label to request another review once you have addressed this.

The API contract and editor-link security surface lack independent assurance on the current head; older reviews and discussion-only summaries do not supply it. Request current-head review from @PostHog/team-data-tools covering both areas before re-requesting; Rory Shanks and Andy Zhao are suggested reviewers.

  • Author wrote 0% of the modified lines and has 67 merged PRs in these paths (familiarity MODERATE).
  • Risky territory without independent assurance: Public API contracts — posthog/schema.py adds an optional URL to HogQLNotice, changing query metadata responses and the generated client schemas.; Security-sensitive surface — frontend/src/lib/monaco/codeEditorLogic.tsx turns notice URLs into clickable Monaco links; posthog/hogql/metadata.py validates the feature-flag payload to allow only HTTPS URLs with a host.
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✓ no deny categories matched
size ✓ 169L, 6F substantive, 1905L/23F incl. docs/generated/snapshots — within ceiling
tier ✓ T1-agent / T1d-complex (1905L, 23F, cross-cutting, feat)
stamphog 2.4.1 .stamphog/policy.yml @ 9dede36 · reviewed head 9dede36

The warning keeps the flag-called-move-notices gate and evaluates the flag
inside the advisory try block. A stacked follow-up adds the link.

Claude-Session: https://claude.ai/code/session_0182H46NbivitrX4jyFFg61N

@stamphog stamphog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

Contained, feature-gated editor advisory with targeted tests; no substantive unresolved concerns are evidenced in the supplied review context. The change does not alter ingestion, data models, query execution contracts, or security controls, so independent assurance is not required.

  • Author wrote 0% of the modified lines and has 27 merged PRs in these paths (familiarity MODERATE).
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✓ no deny categories matched
size ✓ 132L, 3F substantive, 1788L/16F incl. docs/generated/snapshots — within ceiling
tier ✓ T1-agent / T1d-complex (1788L, 16F, cross-cutting, feat)
stamphog 2.4.1 .stamphog/policy.yml @ 36b59a5 · reviewed head 36b59a5

@mariusandra mariusandra left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed by Codex, an AI agent, at 36b59a5. No blocking findings.

Checked the feature gate, advisory failure handling, resolved events-column detection, and source-span handling. In-memory probes using this commit's warning implementation and the local HogQL parser/resolver passed for equality, IN, reversed equality, table/column aliases, namespaced events, property/literal exclusions, saved-view and saved-expression exclusions, and a 12-level shared-CTE query. The CTE probe produced one correctly positioned warning without the earlier traversal blowup.

GitHub checks are passing. I did not run the full database-backed suite or browser validation locally. The documented Go language-service coverage gap remains outside this PR's scope.

@haacked

haacked commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

/trunk merge

@trunk-io
trunk-io Bot merged commit 274373b into master Oct 9, 2026
288 checks passed
@trunk-io
trunk-io Bot deleted the haacked/flag-called-sql-warning branch October 9, 2026 16:25
@deployment-status-posthog

deployment-status-posthog Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Deploy status

Environment Status Deployed At Workflow
dev ✅ Deployed 2026-10-09 17:01 UTC Run
prod-us ✅ Deployed 2026-10-09 17:14 UTC Run
prod-eu ✅ Deployed 2026-10-09 17:16 UTC Run

This branch was successfully deployed

1 active deployment
preview-pr-114059 — 36b59a57 Deployed Oct 8, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature/feature-flags Feature Tag: Feature flags stamphog Request AI approval (no full review) team/feature-flags

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants