* feat: add PBAC permission checks to insights
- Add layout-level protection for insights pages with session.user.org.id check
- Add API-level protection for insights tRPC endpoints using insightsPbacProcedure
- Enhance routing form insights with PBAC team filtering
- Use insights.read permission with OWNER/ADMIN fallback roles
- Replace all userBelongsToTeamProcedure with insightsPbacProcedure in insights router
- Fix lint issues: remove unused variables and functions, fix non-null assertion
Implements Permission-Based Access Control (PBAC) for insights functionality following the same patterns as event type PBAC implementation from PR #22618.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* fix: clean up unused imports in routing-forms
- Remove unused isFormCreateEditAllowed import
- Remove unused TRPCError import
- Change MembershipRole to type import for better tree-shaking
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* address feedback
* clean up permission check
* revert unnecessary changes
* fix procedure
* allow MEMBER for insights
* support teams not under orgs
* fix type error
* revert unnecessary changes
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>