Minor Changes
- fd54ac7: Persist alert evaluation errors (query errors, timeouts, webhook failures) as
ERROR-state AlertHistory records instead of only a latest-only snapshot,
upserted per evaluation window so retries collapse into a single row. Query
timeouts are classified separately (QUERY_TIMEOUT, including timeouts wrapped
by the ClickHouse query client) with an actionable message. ERROR rows are
excluded from scheduling/backfill computations so failed windows are still
retried and backfilled, and once a failed window recovers (via a same-window
retry or a later tick's backfill) its stale ERROR row is removed. Evaluation
analytics (query/webhook durations, backfilled buckets) are recorded on every
history row. - 05a3fd8: Add the AlertHistory evaluations read model and GET /alerts/:id/evaluations
endpoint: per-window evaluation history scoped to a time range (clamped to the
retention window) with per-group breakdown for group-by alerts, evaluation
analytics fields, deduped error surfacing for ERROR-state windows, and
cursor-based pagination that always advances across gaps. Adds read-side
schema/type support for ERROR-state AlertHistory rows and evaluation analytics. - 4fa4975: Add a
clickstack_query_tilesMCP tool that validates many dashboard tiles in
a single call. It accepts a dashboard ID and an optional list of tile IDs
(default: every non-markdown tile), runs the tile queries with bounded
concurrency, and returns a compact per-tile success/failure summary
(status, row count, errors, and raw-SQL macro warnings) plus an aggregate
count. A tile that fails to query is reported inline without failing the whole
call, so an agent can validate an entire dashboard in one or two calls instead
of oneclickstack_query_tilecall per tile. Theclickstack_save_dashboard
guidance now points at the batch tool for post-save validation. - d201b71: Add an optional
serviceVersionExpressionto log and trace sources, identifying
the running release of a service. Defaults to the OpenTelemetry
service.versionresource attribute; teams whose release identifier lives
elsewhere, such as a container image tag under GitOps, can point it there
instead of changing instrumentation.
Patch Changes
- b9430a6: feat: Add broadcast and variable settings to dashboard filters
- b619603: Treat a session whose user no longer exists as logged out instead of failing the
request. Deleting a team member left that person's browser holding a session
cookie pointing at a user document that was gone, anddeserializeUserreported
the missing user as an error rather than as an unauthenticated session. Because
passport.session()runs ahead of every router, each request carrying the
cookie came back500 Something went wrong :(regardless of path or method,
including public routes such asPOST /team/setup/:tokenandGET /logout, so
a removed person could neither accept a fresh invite nor clear their own
session. The stale id is now dropped from the session and the request continues
unauthenticated, so protected routes answer 401 and the browser is sent back to
the login page. - de78306: Clear the remaining small api ESLint warnings and enforce their rules. Merges
the duplicate Expressdeclare globalnamespace blocks in the auth middleware
(thenamespace+ empty-interface augmentation pattern is required, so it
carries a scoped disable with a comment), and scopesn/no-process-exitoff for
the process entry points (src/index.ts,src/tasks/index.ts) where exiting
with a status code is intended.@typescript-eslint/no-namespace,
no-empty-object-type, andn/no-process-exitare promoted toerrorand the
api--max-warningsceiling is lowered. Behavior is unchanged. - 018a648: Clean up ESLint warnings and tighten lint enforcement. Resolved all
no-unused-varsand@typescript-eslint/ban-ts-commentwarnings (removing dead
code and converting@ts-ignoreto described@ts-expect-error), then promoted
those rules toerrorin the api/app/common-utils/cli/hdx-eval configs, disabled
the noisy@typescript-eslint/no-empty-functionrule in app, and lowered each
package's--max-warningsceiling so the counts can't regress. Behavior is
unchanged. - 582f394: Show password requirements on the Join Team page and align the checklist with the server policy. When a user accepts a team invite and sets their password, the same live password policy checklist used on the auth/register page is now displayed, so users no longer have to guess the required length, casing, number, and special-character rules. The checklist previously diverged from the server in two ways that could show all-green checks for a password the server rejects: its special-character rule used a broader pattern than the backend (so a password whose only special character was e.g.
~, a backtick, or a space passed the checklist but failed on submit), and it never surfaced the 72-character maximum (so an over-long password passed the checklist but failed on submit). The length rule now enforces both the minimum and maximum, and the password policy checks (length bounds, casing, number, and the accepted special-character set) live in a single shared module in@hyperdx/common-utilsused by both the frontend checklist and the backendpasswordSchema, so they can no longer drift. Finally, when the server rejects a password the Join Team page now shows the specific reason(s) it failed (e.g. "Password must include at least one special character (!@#$%^&*(),.?":{}|<>;-+=)") instead of a generic "Password is invalid", so users are told exactly what to change — including which special characters are accepted. - f891eb1: fix(mcp): steer agents toward builder query tools instead of raw SQL (HDX-4892). Telemetry showed agents (notebook investigations) using
clickstack_sqlfor ~73% of data queries — usually for single-source aggregations, top-N, and time-series that the builder tools express more reliably (raw SQL also had ~2x the error rate). Reworded theclickstack_sqldescription to mark it a last resort, added a reciprocal "prefer me over SQL" nudge toclickstack_table,clickstack_timeseries, andclickstack_search, and added a server-levelinstructionstool-selection policy so the guidance is surfaced oninitializerather than only via the opt-inquery_guideprompt. - 4c5ccfc: Add MCP tool annotations (readOnlyHint, destructiveHint) to every MCP tool so
clients can distinguish read-only query tools from mutating ones. Read/query
tools are marked read-only; save/patch and delete tools are marked destructive
since they can overwrite or remove existing resources. Hints that would be
redundant against the MCP spec defaults are omitted (e.g. destructiveHint is
left off read-only tools, where it has no meaning). - 6662379: feat: expose summary metrics through the mcp
- f34cfae: Remove the non-functional
GET /ext/silence-alert/:tokenendpoint and its dead code path. - 711b905: Guide dashboard MCP agents to filter builder tiles (table, line, stacked_bar,
number, pie, bar) with the per-serieswhereon each select item, which the
chart editor surfaces as the tile's visible "Where" box. The dashboard prompt
and the select-itemwheretool description now steer toward it, and the save
and patch tools reject a tile-config-levelwhere/whereLanguageon these
types with an actionable message (the editor does not render a tile-level filter
for them, so it would be invisible and uneditable). Search, heatmap, and
event_patterns tiles keep their tile-levelwhere. - 908b27e: Reject source writes that reference malformed, missing, or another team's
connection. - Updated dependencies [fd54ac7]
- Updated dependencies [05a3fd8]
- Updated dependencies [b9430a6]
- Updated dependencies [546dd44]
- Updated dependencies [cab98c7]
- Updated dependencies [018a648]
- Updated dependencies [8508b6c]
- Updated dependencies [2d33b83]
- Updated dependencies [0ed72dd]
- Updated dependencies [aedb514]
- @hyperdx/common-utils@0.26.0